DFSP # 427 - MOF Balls
Digital Forensic Survival Podcast - A podcast by Digital Forensic Survival Podcast - Martedì
Categorie:
Windows management instrumentation, also known as WMI, is an App on Windows that allows a user to query all sorts of things about a system. Being native to Windows, it is an attractive target for a attackers to leverage. This week I'll break down the artifact from a DFIR point of a few and talk about how to detect its misuse.