12 Days of Defense - Day 1: PDF and Office Doc Malware IOC Extraction

In this video I show how to extract a malicious URL from a PDF without opening it, how to spot a weaponized Office document, and a method to quickly de-obfuscate PowerShell. Enjoy! Links: REMnux: https://www.remnux.org PDF: https://app.any.run/tasks/0bf96bc2-04... Macro-enabled doc: https://hybrid-analysis.com/sample/0a... === My SANS Courses: SEC450 - Blue Team Fundamentals: https://sans.org/sec450 MGT551 - Building and Leading Security Operations Centers: https://sans.org/mgt551 PDF Guide to Security Operations: https://www.sans.org/security-resourc... Blueprint Podcast: https://sans.org/blueprint-podcast Twitter:   / sechubb