Slides and demo content from our BSidesTO 2017 presentation by Lee Kagan (@InvokeThreatGuy) and Anton Ovrutsky (@antonlovesdnb)
Please be aware that this script was created to demonstrate various detections that were tailored for the demo. The script is not meant to be used in any sort of production environment, has some buggy issues still but we will update it over time.