ISC StormCast for Wednesday, June 20th 2018
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 19 June 2018
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, June 20th, 2018 edition of the Sands and Storm Center's Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:12.8 | Xavier came across an interesting PowerShell script that disables logging. One of the standard techniques, how you defend against Militius' |
| 0:20.8 | PowerShell scripts is to log all PowerShell |
| 0:24.6 | and then to check and review PowerShell commands executed for malicious payloads. |
| 0:31.6 | In this particular case, a trick is used that allows an attacker to disable the script block logging without actually |
| 0:41.8 | being administrator. Now, one annoying problem with antivirus that we have talked about a number |
| 0:49.9 | of times in the past is false positives. Now, you would hope that Anavirus vendors have procedures |
| 0:56.7 | in place to avoid them, but of course it's very difficult for them to test every single piece |
| 1:02.9 | of software that's not malicious. Virus Total now offers a new paid service to help with that. |
| 1:10.2 | If you are a software publisher, you may upload |
| 1:14.4 | your software collection to Virus Total and have Virus Total automatically alert you whenever |
| 1:21.0 | your software triggers false positive. Now of course it could also happen that your software actually uses a malicious component. |
| 1:29.9 | We have seen this quite often with Bitcoin miners and the like and you probably still want |
| 1:34.7 | to know that. |
| 1:35.9 | So it's nice to have Virus Total alert you in this case as well. |
| 1:41.2 | Now you say okay I can already do this for free with Virus Total. |
| 1:44.1 | I just upload my software and then keep checking for updated scan results. |
| 1:50.0 | The real nice thing of this paid version is that it actually provides an API that you can |
| 1:56.9 | then integrate in your development pipeline. |
| 2:00.0 | Which then allows you to recognize any false |
| 2:02.9 | positives before you even publish your software. |
| 2:06.1 | The next news item, again, no big surprise, turns out a lot of systems used to manage cloud |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

