Splunk Tech Talks
Deep-dives for technical practitioners.

Hunting for Malicious PowerShell using Script Block Logging

melissap
Splunk Employee
Splunk Employee

View our Tech Talk: Security Edition, Hunting for Malicious PowerShell using Script Block Logging 

Hunting for Malicious PowerShell using Script Block Logging
Video Player is loading.
Current Time 0:00
Duration 29:51
Loaded: 0%
Stream Type LIVE
Remaining Time 29:51
 
1x
    • Chapters
    • descriptions off, selected
    • captions off, selected
    • en (Main), selected
    (view in My Videos)

    The Splunk Threat Research Team most recently began evaluating more ways to generate security content using native Windows event logging regarding PowerShell Script Block Logging. This method provides greater depth of visibility as it provides the raw (entire) PowerShell script output. There are three sources that may enhance any defender's perspective: module, script block and transcript logging. We focused our security content on script block logging (4104) as it provides the most granular visibility of PowerShell scripts that execute on an endpoint. However, we also provided a way to gather all three for testing validation, production or curiosity.

    Tune in to this Tech Talk to learn about:

    • What is a malicious powershell
    • How to detect malicious powershell with script block logging
    • How to implement threat hunting in your operations to prevent breaches
    An Unexpected Error has occurred.
    Get Updates on the Splunk Community!

    See just what you’ve been missing | Observability tracks at Splunk University

    Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

    Weezer at .conf25? Say it ain’t so!

    Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

    How SC4S Makes Suricata Logs Ingestion Simple

    Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...