ISC StormCast for Friday, September 25th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 25 September 2020
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Friday, September 25th, 2020 edition of the Sandtonet Storm Center's Stormcast. |
| 0:07.7 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:13.9 | If I ran into some obfuscated PowerShell script and had a real hard time analyzing it, well, you are in it for a treat if you are following Xavier's diary from today. |
| 0:28.6 | Xavier is going over PowerShell ISE, the integration scripting environment that is installed by default on all current versions of Windows, just like the default |
| 0:41.3 | PowerShell interpreter. |
| 0:43.3 | But what's really different about PowerShe ise is the fact that it's a full interactive |
| 0:50.3 | debugger. |
| 0:51.3 | What you have to do is you have to load the PowerShe script into PowerShe |
| 0:55.9 | ISE and then you can step through it and essentially decode or let the script decode itself |
| 1:03.8 | until you can actually read or extract whatever shell code is in it. Now, Xavier has a big warning here. |
| 1:12.3 | Be careful when you do this. |
| 1:13.9 | And best, of course, to do this on a separate environment, |
| 1:19.6 | a separate system. |
| 1:21.0 | Because, of course, you don't want any malicious PowerShell script |
| 1:25.1 | to execute on a production system that you also have corporate data on. |
| 1:31.7 | And if you would like to know more details, Xavier is walking you through a sample script step by step. |
| 1:38.9 | So real nice little post here to follow along and do the analysis yourself with Xavier as your guide. |
| 1:50.9 | And yes, it is happening. Microsoft announced via its Microsoft Security Intelligence Twitter account |
| 1:59.9 | that they are seeing active exploitation of the |
| 2:04.5 | Zero Logon vulnerability. So again, this was CVE 2020, 1472 against the net logon |
| 2:13.3 | EOP vulnerability. Of course, I mentioned it already a couple times, so everybody here should be |
| 2:18.9 | aware of it and hopefully is patched. Let me got a couple smaller updates from Apple. First we got |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

