Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal
Is Microsoft Defender enough to protect your PC? Malware researcher Leo joins me at Black Hat to discuss antivirus, Windows security and how hackers steal your accounts.
We explore how infostealers target saved passwords and session tokens, why two-factor authentication cannot prevent every account takeover, and how a message from a compromised friend’s account can lead to an infection.
Leo shares practical starting points for investigating your computer, including Autoruns for startup entries, TCPView for linking connections to applications, and Wireshark for examining network traffic. We also discuss password managers, account recovery planning, Windows telemetry and why switching operating systems does not eliminate security risks.
In this interview:
• Microsoft Defender’s strengths and limitations
• Free tools for investigating suspicious Windows activity
• How infostealers and initial access brokers operate
• Stolen session tokens and the limits of 2FA
• Fake download sites, malicious ads and targeted phishing
• Preparing recovery options before your accounts are compromised
• Security and privacy trade-offs across Windows, Linux and macOS
// Leo’s SOCIAL //
YouTube: @pcsecuritychannel
X: https://x.com/leotday
Discord: Discord: discord
// David's SOCIAL //
Discord: Discord: discord
X: Twitter: davidbombal
Instagram: Instagram: davidbombal
LinkedIn: LinkedIn: davidbombal
Facebook: Facebook: davidbombal.co
TikTok: TikTok: davidbombal
YouTube: @davidbombal
Spotify: https://open.spotify.com/show/3f6k6gE...
SoundCloud: SoundCloud: davidbombal
Apple Podcast: https://podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
0:00 - Coming Up
0:35 - Intro
0:48 - Leo's Background & How Malware Has Evolved
03:27 - How to Detect Malware on Your Computer
05:21 - Best Sysinternals Tools for Malware Analysis
08:21 - Windows Device Tracking & Privacy Concerns
10:42 - Would you Recommend Windows in 2026?
11:59 - Privacy Laws & the Future of Tracking
12:50 - How Telemetry Helps Catch Cybercriminals
14:02 - ThreatLocker Sponsor
15:18 - How Hackers Actually Get Into Systems
16:42 - How to Protect Yourself From Getting Hacked
19:12 - Do You Really Need Antivirus?
21:35 - Security Advice for Home Users
25:59 - Why Smart People Still Get Hacked
26:59 - What Happens After Your Credentials Are Stolen
28:06 - Linux vs Mac vs Windows
29:40 - Is Windows Really Targeted More by Malware?
31:18 - Conclusion & Outro
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
#malware #bhusa2026 #microsoftdefender
Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal
Is Microsoft Defender enough to protect your PC? Malware researcher Leo joins me at Black Hat to discuss antivirus, Windows security and how hackers steal your accounts.
We explore how infostealers target saved passwords and session tokens, why two-factor authentication cannot prevent every account takeover, and how a message from a compromised friend’s account can lead to an infection.
Leo shares practical starting points for investigating your computer, including Autoruns for startup entries, TCPView for linking connections to applications, and Wireshark for examining network traffic. We also discuss password managers, account recovery planning, Windows telemetry and why switching operating systems does not eliminate security risks.
In this interview:
• Microsoft Defender’s strengths and limitations
• Free tools for investigating suspicious Windows activity
• How infostealers and initial access brokers operate
• Stolen session tokens and the limits of 2FA
• Fake download sites, malicious ads and targeted phishing
• Preparing recovery options before your accounts are compromised
• Security and privacy trade-offs across Windows, Linux and macOS
// Leo’s SOCIAL //
YouTube: @pcsecuritychannel
X: https://x.com/leotday
Discord: Discord: discord
// David's SOCIAL //
Discord: Discord: discord
X: Twitter: davidbombal
Instagram: Instagram: davidbombal
LinkedIn: LinkedIn: davidbombal
Facebook: Facebook: davidbombal.co
TikTok: TikTok: davidbombal
YouTube: @davidbombal
Spotify: https://open.spotify.com/show/3f6k6gE...
SoundCloud: SoundCloud: davidbombal
Apple Podcast: https://podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
0:00 - Coming Up
0:35 - Intro
0:48 - Leo's Background & How Malware Has Evolved
03:27 - How to Detect Malware on Your Computer
05:21 - Best Sysinternals Tools for Malware Analysis
08:21 - Windows Device Tracking & Privacy Concerns
10:42 - Would you Recommend Windows in 2026?
11:59 - Privacy Laws & the Future of Tracking
12:50 - How Telemetry Helps Catch Cybercriminals
14:02 - ThreatLocker Sponsor
15:18 - How Hackers Actually Get Into Systems
16:42 - How to Protect Yourself From Getting Hacked
19:12 - Do You Really Need Antivirus?
21:35 - Security Advice for Home Users
25:59 - Why Smart People Still Get Hacked
26:59 - What Happens After Your Credentials Are Stolen
28:06 - Linux vs Mac vs Windows
29:40 - Is Windows Really Targeted More by Malware?
31:18 - Conclusion & Outro
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
#malware #bhusa2026 #microsoftdefender
2. ALWAYS backup your critical data to a secondary storage device, and if possible a NAS that keeps multiple historical file copies which will allow you to restore maliciously encrypted files.
3. Never use an Admin account for your everyday activities - have a separate root/admin account for installing software, and ONLY use it when you MUST install software manually - do NOT leave it logged in, login using a non-Admin account for everyday browsing, emailing, application use etc.
4. Learn how to control your own DNS traffic - this is a huge lever which when understood and properly controlled can save you from a lot of grief.