Defending against malware with robust and practical application whitelisting

Join us for the fourth edition of the popular Sysinternals Primer series with Aaron Margosis, Mark Russinovich’s co-author of The Windows Sysinternals Administrator’s Reference. The Sysinternals utilities are vital tools for any computer professional on the Windows platform. Mark Russinovich's popular "Case Of The Unexplained" demonstrates some of their capabilities in advanced troubleshooting scenarios. This complementary tutorial series focuses primarily on the utilities themselves, deep-diving into as many features as time will allow. This year’s session describes everything that’s new and improved in the Sysinternals tool set since the book was published two years ago. It’s like an early draft of Sysinternals, Second Edition.
This is always a great session and I go to it every year I go to TechEd. There is always something new, or something that I forgot or missed previously.
Will have to catch the plane so cannot attend this in person. Hope to view the recording of this session to learn more.
A must go! Looking forward to this very much!
Always packed so come early.
I've missed this in the past so I'm making plans to line up early!
Looking forward for this Primer.
One of the best sessions every year. Hoping to dig into some of the more obscure tools this year.
Please do not tell anyone else about this session. I would love to get a seat this time
I'm hoping to make this session -- looks interesting!
I'll be at this one... Another great sysinternals session.
Very much looking forward to this session as there always seems to be something new to learn. Love the tools.
Which tools will be covered first?
I'm looking forward to this - haven't been to this session in a couple of years now.
I still miss good old FileMon
Yes, I know about Process Monitor, but it always takes that annoying extra moment to set it all up and exclude all the extraneous (to the case only needing FileMon) content.
Is there perhaps a way to have a feature in Process Monitor (a command line switch) to allow it to _immediately_ start-up in the FileMon-analogous mode straight away?
Check out Kenny Kerr's "SyncTools for Synsinternals" to always keep your Sysinternals tools up to date.
http://kennykerr.ca/2013/01/04/synctools-for-sysinternals/
Works great for me!
This conversation has been locked by the site admins. No new comments can be made.