MSTIC has observed an increasing number of Linux attackers encoding their scripts into Base64 both for ease of use and to avoid detection. Because the commands are encoded, it can be time-intensive and inefficient to hone in on malicious Base64-encoded commands by looking at raw log data. To solve this problem, we have created a Jupyter notebook that makes this process easier by scoring and ranking Base64 commands found in your Sentinel data. We walk through the notebook and how to use it in this video.
Learn more https://techcommunity.microsoft.com/t....
#MicrosoftSecurity
Watch video Detect Malicious Base64-Encoded Commands on Linux Hosts online without registration, duration hours minute second in high quality. This video was added by user Microsoft Security 27 August 2021, don't forget to share it with your friends and acquaintances, it has been viewed on our site 1,221 once and liked it 15 people.