Invoke-Obfuscation: PowerShell obFUsk8tion Techniques & How To (Try To) D""e`Tec`T 'Th'+'em'
Slides: https://www.slideshare.net/DanielBohannon2/invokeobfuscation-derbycon-2016
Conferences:
DerbyCon 6 (2016-09-25 :: Louisville, Kentucky USA)
https://www.youtube.com/watch?v=P1lkflnWb0ISANS DFIR Summit (2016-10-09 :: Prague, Czech Republic)
No public recordingCODE BLUE (2016-10-20 :: Tokyo, Japan)
https://www.youtube.com/watch?v=Z_fdf_BpzLUHacktivity (2016-10-22 :: Budapest, Hungary)
https://www.youtube.com/watch?v=uE8IAxM_BhEBruCON (2016-10-28 :: Gent, Belgium)
https://www.youtube.com/watch?v=DLtJTxMWZ2oMicrosoft BlueHat (2016-11-04 :: Redmond, Washington USA)
No public recordingMicrosoft BlueHat IL (2017-01-24 :: Tel Aviv, Israel)
https://www.youtube.com/watch?v=6J8pw_bM-i4nullcon (2017-03-03 :: Goa, India)
https://www.youtube.com/watch?v=PMh0_59jD2U
PS I Love You: Detection, Evasion & the State of PowerShell Security
Co-presented with Mandiant's Matthew Dunwoody (@matthewdunwoody).
Slides: N/A
Conference:
FireEye Cyber Defense Summit (2016-11-30 :: Washington DC, USA)
No public recording
Invoke-CradleCrafter: Moar PowerShell obFUsk8tion & Detection (@('Tech','niques') -Join '')
Conferences:
x33fcon (2017-04-28 :: Gdynia, Poland)
https://www.youtube.com/watch?v=Nn9yJjFGXU0NOPcon (2017-05-11 :: Istanbul, Turkey)
https://www.youtube.com/watch?v=sIUh4CkgUCA (Interview)RVAsec (2017-06-07 :: Richmond, Virginia USA)
https://www.youtube.com/watch?v=Nn9yJjFGXU0SEC-T 0x0A (2017-09-13 :: Stockholm, Sweden)
https://www.youtube.com/watch?v=J0r03wG8ossDerbyCon 7 (2017-09-22 :: Louisville, Kentucky USA)
https://www.youtube.com/watch?v=5jlzF_hFQkg
Co-presented with Microsoft's Lee Holmes (@Lee_Holmes).
Slides: https://www.slideshare.net/DanielBohannon2/revokeobfuscation
Conferences:
Black Hat USA (2017-07-27 :: Las Vegas, Nevada USA)
https://www.youtube.com/watch?v=x97ejtv56xwDEF CON 25 (2017-07-30 :: Las Vegas, USA)
https://www.youtube.com/watch?v=k5ToL0J7uL0SEC-T 0x0A (2017-09-15 :: Stockholm, Sweden)
https://www.youtube.com/watch?v=cPml1XQ4BdkDerbyCon 7 (2017-09-23 :: Louisville, Kentucky USA)
https://www.youtube.com/watch?v=7XnkDsOZM3YBSides DC (2017-10-08 :: Washington DC, USA)
https://www.youtube.com/watch?v=yusq49wEijIPSConfEU (2018-04-18 :: Hanover, Germany)
Video Link TBD
Revoke-Obfuscation: PowerShell Obfuscation Detection (And Evasion) Using Science
Slides: https://www.slideshare.net/DanielBohannon2/invokedosfuscation
Conferences:
Black Hat Asia (2018-03-23 :: Singapore)
[Received "Best of Briefings" award]
https://www.youtube.com/watch?v=mej5L9PE1fsHITBSecConf (2018-04-12 :: Amsterdam, Netherlands) https://www.youtube.com/watch?v=Gu1AXglrW80
NorthSec (2018-05-18 :: Montreal, Québec, Canada)
https://www.youtube.com/watch?v=StmzEvO3H-QCONFidence (2018-06-04 :: Kraków, Poland)
https://www.youtube.com/watch?v=_twSYQj9K0IHack In Paris (2018-06-28 :: Paris, France)
https://www.youtube.com/watch?v=3cwtCfa3FukDerbyCon 8 (2018-10-07 :: Louisville, Kentucky USA)
https://www.youtube.com/watch?v=Moo2Skig8iU
Invoke-DOSfuscation: Techniques FOR %F IN (-style) DO (S-level CMD Obfuscation)
Slides: https://www.slideshare.net/DanielBohannon2/devsec-defense
Conferences:
PSConfEU (2018-04-19 :: Hanover, Germany)
https://www.youtube.com/watch?v=91BOEtdrPTgx33fcon (2018-05-08 :: Gdynia, Poland)
https://www.youtube.com/watch?v=QJe8xikf-iE
DevSec Defense: How DevOps Practices Can Drive Detection Development For Defenders
Co-presented with Mandiant's Matthew Dunwoody (@matthewdunwoody).
Slides: https://www.slideshare.net/DanielBohannon2/signaturesaredead-long-live-resilient-signatures
Conferences:
SANS DFIR Summit (2018-06-08 :: Austin, Texas USA)
https://www.youtube.com/watch?v=Oh4pLsCvBlwBruCON (2018-10-04 :: Gent, Belgium)
https://www.youtube.com/watch?v=YGJaj6_3dGA
$SignaturesAreDead = "Long Live RESILIENT Signatures" wide ascii nocase
Slides: N/A
Venues:
UGAHacks Hackathon [University of Georgia] (2019-02-09 :: Athens, Georgia USA)
GreyHat Cyber Security Club [Georgia Institute of Technology] (2019-03-14 :: Atlanta, Georgia USA)
CU Cyber Security Club [Clemson University] (2019-10-10 :: Clemson, South Carolina USA)
University of Tirana (Faculty of Economics) (2020-01-20 :: Tirana, Albania)
Cyber Academy (2020-01-23 :: Prishtina, Kosovo)
University of Prishtina (2020-01-24 :: Prishtina, Kosovo)
Prishtina Hackerspace (2020-01-25 :: Prishtina, Kosovo)
Obfuscation, Evasion & Detection
Slides: N/A
Venues:
Open Labs Hackerspace (2019-03-02 :: Tirana, Albania)
Prishtina Hackerspace (2019-03-06 :: Prishtina, Kosovo)
Getting Into InfoSec via Open Source
Slides: N/A
Venues (University Guest Lectures):
Albanian University (2019-04-23 :: Tirana, Albania)
University of Tirana (Faculty of Economics) (2019-04-23 :: Tirana, Albania)
University for Business & Technology - UBT [Ferizaj campus] (2019-04-25 :: Ferizaj, Kosovo)
University for Business & Technology - UBT [Prishtina campus] (2019-04-25 :: Prishtina, Kosovo)
Universiteti Metropolitan Tirana - UMT (2020-01-20 :: Tirana, Albania)
Polis University (2020-01-20 :: Tirana, Albania)
Albanian University (2020-01-21 :: Tirana, Albania)
University of Tirana (Faculty of Natural Sciences) (2020-01-21 :: Tirana, Albania)
Canadian Institute of Technology (2020-01-21 :: Tirana, Albania)
University for Business & Technology - UBT [Ferizaj campus] (2020-01-22 :: Ferizaj, Kosovo)
University for Business & Technology - UBT [Prizren campus] (2020-01-23 :: Prizren, Kosovo)
AAB University (2020-01-24 :: Prishtina, Kosovo)
Getting Into InfoSec - Real World Overview + Q&A
Malicious Payloads vs Deep Visibility: A PowerShell Story
Slides: https://www.slideshare.net/DanielBohannon2/malicious-payloads-vs-deep-visibility-a-powershell-story
Conferences:
PowerShell + DevOps Global Summit (2019-04-30 :: Bellevue, Washington USA)
https://www.youtube.com/watch?v=OGhqGqBEaMkSp4rkCon (2019-05-04 :: Bentonville, Arkansas USA)
https://www.youtube.com/watch?v=RxIXUauz02EPSConfEU (2019-06-05 :: Hanover, Germany)
https://www.youtube.com/watch?v=h1Sbb-1wRKw
Slides: https://www.slideshare.net/DanielBohannon2/pestersec-using-pester-scriptanalyzer-to-detect-obfuscated-powershell
Conferences:
PowerShell + DevOps Global Summit (2019-05-01 :: Bellevue, Washington USA)
https://www.youtube.com/watch?v=xHqj7Icc3LMPSConfEU (2019-06-06 :: Hanover, Germany)
https://www.youtube.com/watch?v=qYgCLzBaVaw
PesterSec: Using Pester & ScriptAnalyzer for Detecting Obfuscated PowerShell
Slides: N/A
Venues:
University of Prizren (2022-04-22 :: Prizren, Kosovo)
University of Prishtina (2022-04-25 :: Prishtina, Kosovo)
Cyber Academy (2022-04-25 :: Prishtina, Kosovo)