Friday, October 28, 2016

SANS Cyber Defense Challenge: What did the other Powershell Command do?

I was wondering what the other powershell command did in day four.  Looks like a file.  It's probably just random bits, but  I was wondering if it was like that shift cipher.  Sometimes they hide Easter Eggs in the challenges.  So far I haven't found anything.  I'll have to look at that powershell command in the evtx log again.  I know that it was base64 encoded, so I decoded it.  Wonder if the command did anything else?

No comments:

Post a Comment