Skip to main content
0 Results Found
              Back To Results

                The PowerShell Risk

                Understanding and avoiding PowerShell attacks

                Speaker: Lee Lawson, Special Operation Resercher, Secureworks Counter Threat Unit
                Recorded: June 20, 2017
                Duration: 60 Mins

                What you will learn:

                • What PowerShell is and how it is used in “living off the land” attacks
                • Why built-in tools like PowerShell are so attractive to threat actors
                • Examples of malicious PowerShell use
                • How to defend your organization against common methods to evade prevention and detection

                In a recent Secureworks engagement, 98.5% of the 3,477 commands executed by threat actors were native to the Windows operating system.

                PowerShell is a popular tool that Microsoft has been including with the Windows OS since 2009, but malicious PowerShell use is rivaling ransomware in popularity with threat actors. Security products focused on preventing endpoint threats are often not enough to differentiate legitimate from malicious PowerShell use. Join us for a discussion of why PowerShell is so risky, how Secureworks researchers identify PowerShell threats, and how you can defend your organization.

                View Your On-Demand Webcast

                All fields are required.

                We generate around 2 billion events each month. With Secureworks, we are able to crunch down that number to 20-30 high fidelity alerts — and that makes my team's job much easier.
                Sunil Saale, Head of Cyber and Information Security, Minter Ellison
                With Secureworks Taegis ManagedXDR, I have the peace of mind that my environment is being monitored 24x7 and if a threat actor tries to attack Secureworks will alert me, quickly investigate, and collaborate to fully resolve before damage can be done.
                Jerry Ryan, VP of IT, We Florida Financial

                Why Secureworks?

                Secureworks (NASDAQ: SCWX) is a global cybersecurity leader that protects customer progress with Secureworks® Taegis™, a cloud-native security analytics platform built on 20+ years of real-world threat intelligence and research, improving customers’ ability to detect advanced threats, streamline and collaborate on investigations, and automate the right actions.

                Close Modal
                Close Modal