SUMMARY History End of life CLI Services Security Considerations - - PowerPoint PPT Presentation

summary
SMART_READER_LITE
LIVE PREVIEW

SUMMARY History End of life CLI Services Security Considerations - - PowerPoint PPT Presentation

SUMMARY History End of life CLI Services Security Considerations Powershell Server Setup BRIEF HISTORY (WINDOWS CLIENT) MSDOS (1980) WINDOWS (1985) WINDOWS 3.1 (1992) Windows 95 (1995) Windows ME


slide-1
SLIDE 1
slide-2
SLIDE 2

SUMMARY

▶ History ▶ End of life ▶ CLI ▶ Services ▶ Security Considerations ▶ Powershell ▶ Server Setup

slide-3
SLIDE 3

BRIEF HISTORY (WINDOWS CLIENT)

MSDOS (1980)

WINDOWS (1985)

WINDOWS 3.1 (1992)

Windows 95 (1995)

Windows ME (2000)

Windows XP (2001)

Windows Vista (2006)

Windows 7 (2009)

Windows 8 (2012)

Windows 10 (2015)

slide-4
SLIDE 4

BRIEF HISTORY (WINDOWS SERVER)

▶ Windows NT 4.0 (1993) ▶ Windows NT 4.0 (1996) ▶ Windows Server 2003 ▶ Windows Server 2008 ▶ Server 2012 ▶ Server 2016 ▶ Server 2019 (2018)

slide-5
SLIDE 5
slide-6
SLIDE 6

MARKET SHARE

slide-7
SLIDE 7

END OF LIFE

▶ Windows 7 (2020) ▶ Windows 8.1 (2023)

slide-8
SLIDE 8

END OF LIFE

slide-9
SLIDE 9

KERNEL TYPES

slide-10
SLIDE 10

KERNEL

slide-11
SLIDE 11

COMMAND LINE INTERFACE (CLI)

slide-12
SLIDE 12

COMMAND LINE INTERFACE (CLI)

slide-13
SLIDE 13

SERVICES

*Fixes 99% of printer problems

slide-14
SLIDE 14

WINDOWS SERVER

slide-15
SLIDE 15

SERVER CORE

slide-16
SLIDE 16

ACTIVE DIRECTORY (AD)

slide-17
SLIDE 17

DYNAMIC HOST CONFIGURATION PROTOCOL(DHCP)

slide-18
SLIDE 18

FILE TRANSFER PROTOCOL (FTP)

slide-19
SLIDE 19

INTERNET INFORMATION SERVICES (IIS)

slide-20
SLIDE 20

SERVER MESSAGE BLOCK (SMB)

slide-21
SLIDE 21

DOMAIN NAME SERVICE (DNS)

slide-22
SLIDE 22

GROUP POLICY OBJECTS (GPO)

slide-23
SLIDE 23

SECURITY CONSIDERATIONS

slide-24
SLIDE 24

WINDOWS DEFENDER

▶ Built into Windows ▶ Behavior based/Signature based

slide-25
SLIDE 25

WINDOWS DEFENDER

slide-26
SLIDE 26

POWERSHELL BASED EXPLOITATION

▶ “Living off the land” ▶ Open Source Tools

Bloodhound

Empire (BC-Security Branch)

Powerup

PoshC2

Death Star

And more…

slide-27
SLIDE 27

WHEN SIGNATURE DETECTION FAILS

slide-28
SLIDE 28

BEHAVIOR DETECTION SUCCEEDS

slide-29
SLIDE 29

WINDOWS DEFENDER + GROUP POLICIES

slide-30
SLIDE 30

WINDOWS DEFENDER + GROUP POLICIES

slide-31
SLIDE 31
slide-32
SLIDE 32

POWERSHELL COMMANDS

▶ Get-Service

Lists services running or stopped

slide-33
SLIDE 33

POWERSHELL COMMANDS

▶ Get-Childitem (-hidden)

Lists directories and files

slide-34
SLIDE 34

POWERSHELL COMMANDS

▶ Start-Service <servicename> ▶ Stop-Service <servicename>

Start/Stop service

  • Ex. Start-Service DNS
slide-35
SLIDE 35

POWERSHELL COMMANDS

▶ sc.exe start <servicename> ▶ sc.exe stop <servicename>

Start/Stop service

slide-36
SLIDE 36

POWERSHELL COMMANDS

▶ Set-Service –Name <serviceName> -StartupType <startupType>

Automatic (Delayed)

Automatic

Manual

Disabled

slide-37
SLIDE 37

POWERSHELL COMMANDS

▶ Get-MpComputerStatus

Gets the status of antimalware software on system

slide-38
SLIDE 38

POWERSHELL COMMANDS

▶ Start-MpScan

[-ScanPath <String>]

[-ScanType <ScanType>]

[-CimSession <CimSession[]>]

[-ThrottleLimit <Int32>]

[-AsJob]

slide-39
SLIDE 39

POWERSHELL COMMANDS

▶ Get-Process

List Processes

slide-40
SLIDE 40

POWERSHELL COMMANDS

▶ Get-ComputerInfo

Display system information

slide-41
SLIDE 41

POWERSHELL COMMANDS

▶ Clear

Clear Screen

slide-42
SLIDE 42

POWERSHELL COMMANDS

▶ More info https://docs.microsoft.com/en-us/powershell/

slide-43
SLIDE 43

SERVER SETUP