the_Grinch wrote: » As an example, they cover the writing of a PowerShell script that allows you to pull registry keys in areas malware is known to place them and then go on to compare them to those previously pulled.
alias454 wrote: » Not to hijack this thread but I have been looking at doing that with group policy and an internal git server. I setup a gitlab server and have been working on a powershell script to pull all group policies from AD and then push to the git server. This way you can track changes over time. What you are talking about is kinda cool too, very interesting. Good luck on netwars woot!