全部安全开发新闻数码摄影汽车北京AIIT其他
  • 文章封面

    AdaptixC2:大规模指纹识别开源 C2 框架

    作者:securitainment发布日期:2026-07-08 17:30:00

    原文链接作者https://censys.com/blog/adaptixc2-open-source-c2-framework/Aidan Holland执行摘要AdaptixC2 是一个开源的后渗

    阅读全文
  • 文章封面

    WinPE:作为 Windows 驱动测试与模糊测试的无状态测试框架

    作者:securitainment发布日期:2026-07-06 12:50:00

    原文链接作者https://bednars.me/blog/winpe-harnessbednars.me最近,我分析了低层自动化领域中的两个具体工程问题。第一个是 Windows 系统 CI/CD

    阅读全文
  • 文章封面

    给黑客的 jq 指南

    作者:securitainment发布日期:2026-07-06 12:50:00

    原文链接作者https://trustedsec.com/blog/jq-for-hackersJustin Bollinger当我第一次接触 jq时,它让人感到既不知所措又困惑。我试过直接硬上,没意

    阅读全文
  • 文章封面

    用 LLM 驱动的分析加速 EDR 绕过

    作者:securitainment发布日期:2026-07-03 12:20:00

    原文链接作者https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/Adam Chester这些年来,我一直非常热衷于拆解和调试终

    阅读全文
  • 文章封面

    Sleeping Beauty II:CFG、CET 与栈欺骗

    作者:securitainment发布日期:2026-07-01 16:50:00

    一个关于 CFG 位图、影子栈,以及教会植入体在它本不该存活的地方沉睡的故事。原文链接作者https://maorsabag.github.io/posts/adaptix-stealthpalace

    阅读全文
  • 文章封面

    Windows 恶意软件中的 COM 利用方式入门

    作者:securitainment发布日期:2026-06-30 10:24:00

    原文链接作者https://blog.talosintelligence.com/introduction-to-com-usage-by-windows-threats/Vanja Svajcer组

    阅读全文
  • 文章封面

    heavener:当你买不起 EDR 授权时会发生什么

    作者:securitainment发布日期:2026-06-29 11:50:00

    原文链接作者https://blog.otterpwn.com/projects/heavenerotterpwnheavener 是我过去 6 个月一直在开发的项目,大概也是我做过的最具雄心的事情。

    阅读全文
  • 文章封面

    Rootkit 检测防守指南:第一集——内核驱动

    作者:securitainment发布日期:2026-06-26 10:50:00

    原文链接作者https://labs.jumpsec.com/a-defenders-guide-for-rootkit-detection-episode-1-kernel-drivers/Thom

    阅读全文
  • 文章封面

    据说 Claude Code 能全自动完成 SOC 业务

    作者:securitainment发布日期:2026-06-25 11:50:00

    前言你好,我是信息安全部的兵藤。本文将介绍我们利用 Claude Code 构建自动化告警分诊 Agent(以下简称 SOC Agent)的实践案例,以提升 SOC 业务效率。目录前言目录背景与概述S

    阅读全文
  • 文章封面

    当 EPA 不起作用时:Certify、Certipy 和 checkMSSQLStatus.py 究竟漏掉了什么

    作者:securitainment发布日期:2026-06-24 21:39:00

    原文链接作者https://www.abdulmhsblog.com/posts/pitfallswithepa/Abduls Blog最近在项目交付中,我开始反复遇到两种情况。第一种是 certip

    阅读全文
  • 文章封面

    哎呀,我把数据库武器化了:滥用 SQL Server 2025 中的 AI 功能

    作者:securitainment发布日期:2026-06-11 16:04:00

    原文链接作者https://specterops.io/blog/2026/06/10/oops-i-weaponized-the-database-abusing-ai-features-in-ms

    阅读全文
  • 文章封面

    用 Malcat 对 LLM 进行恶意软件分流与静态脱壳基准测试

    作者:securitainment发布日期:2026-06-10 10:24:00

    原文链接作者https://malcat.fr/blog/benchmarking-llms-for-malware-triage-and-static-unpacking-with-malcat/R

    阅读全文
  • 文章封面

    将 LLM 当作逆向工程的得力助手

    作者:securitainment发布日期:2026-06-09 21:13:00

    本研究探讨了大型语言模型 ( LLMs ) 如何在逆向工程这一复杂领域中辅助而非取代恶意软件分析人员的工作。在恶意软件分析过程中,LLMs 可以作为强大的助手,简化工作流程、提升效率,并提供切实可行的

    阅读全文
  • 文章封面

    构建一条智能体化的恶意软件分析流水线

    作者:securitainment发布日期:2026-06-05 10:24:00

    原文链接作者https://synthesis.to/2026/03/18/agentic_malware_analysis.htmlBlazytko大语言模型已经成为逆向工程中颇为得力的助手:它们能

    阅读全文
  • 文章封面

    构建检测基础:第五部分 - 关联分析的实战应用

    作者:securitainment发布日期:2026-05-31 10:24:00

    原文链接作者https://trustedsec.com/blog/building-a-detection-foundation-part-5-correlation-in-practiceCarl

    阅读全文
  • 文章封面

    构建检测基础:第三部分 - PowerShell 与脚本日志的三大支柱

    作者:securitainment发布日期:2026-05-30 10:24:00

    原文链接作者https://trustedsec.com/blog/building-a-detection-foundation-part-3-powershell-and-script-loggi

    阅读全文
  • 文章封面

    构建检测基础:第四部分 - Sysmon

    作者:securitainment发布日期:2026-05-30 10:24:00

    原文链接作者https://trustedsec.com/blog/building-a-detection-foundation-part-4-sysmonCarlos Perez填补原生日志的盲区

    阅读全文
  • 文章封面

    构建检测基础:第一部分 - 单一数据源之困

    作者:securitainment发布日期:2026-05-29 14:38:00

    原文链接作者https://trustedsec.com/blog/building-a-detection-foundation-part-1-the-single-source-problemCa

    阅读全文
  • 文章封面

    构建检测基础:第二部分 - Windows 安全事件的取证骨架

    作者:securitainment发布日期:2026-05-29 14:38:00

    原文链接作者https://trustedsec.com/blog/building-a-detection-foundation-part-2-windows-security-eventsCarl

    阅读全文
  • 文章封面

    意外的 C2:借道 VS Code Dev Tunnels 实现远程访问

    作者:securitainment发布日期:2026-05-23 10:24:00

    原文链接作者https://blog.xpnsec.com/accidental-c2/XPN / Adam Chester我是在从曼彻斯特飞往 JFK 的航班上开始写这篇博客文章的。每当我出行时,我

    阅读全文
  • 文章封面

    新型 Evilginx 前端:降低 token 窃取与复用的门槛

    作者:securitainment发布日期:2026-05-23 10:24:00

    原文链接作者https://newtonpaul.com/blog/evilginx-m365-aitm-panel-research/Newton Paul最近我在威胁狩猎方面收获颇丰,在 C2 狩

    阅读全文
  • 文章封面

    当文件名成为攻击面:武器化 NASA 的 CFITSIO 扩展文件名语法

    作者:securitainment发布日期:2026-05-22 11:06:00

    ​原文链接作者https://blog.doyensec.com/2026/05/19/cfitsio-weaponized-filenames.htmlAdrian Denkiewicz这项研究最近

    阅读全文
  • 文章封面

    隐藏威胁 - 利用组策略对象进行横向移动

    作者:securitainment发布日期:2026-05-22 11:06:00

    攻击性安全 – 核心要点:使用 GPO 执行横向移动在近期的红队评估中已变得越来越普遍。此过程的一个关键方面是目标定位。作为红队成员/渗透测试人员,您不希望在缺乏控制的情况下将配置部署到大量资产上。存

    阅读全文
  • 文章封面

    三个 CVE 与 2026 年 5 月那条被无视的利用链

    作者:securitainment发布日期:2026-05-21 16:08:00

    原文链接作者https://rud.is/b/2026/05/14/three-cves-and-the-may-2026-exploit-chain-nobodys-taking-seriously

    阅读全文
  • 文章封面

    重新审视"两发"内核 Shellcode 执行:从控制流劫持到绕过 CR Pinning

    作者:securitainment发布日期:2026-05-21 16:08:00

    原文链接作者https://blog.zolutal.io/two-shot-kernel-shellcode/Jennifer Miller我撰写 System Register Hijacking

    阅读全文
  • 文章封面

    Microsoft MDASH 揭秘:100 多个 AI 智能体如何在网络安全战场击败 Anthropic 的 Mythos

    作者:securitainment发布日期:2026-05-20 10:22:00

    原文链接作者https://www.revolutioninai.com/2026/05/microsoft-mdash-multi-agent-ai-security-system-2026.htm

    阅读全文
  • 文章封面

    设计如此,却被攻击者滥用:深入剖析 Device Code Flow 攻击

    作者:securitainment发布日期:2026-05-20 10:22:00

    原文链接作者https://guardz.com/blog/approved-by-design-abused-by-attackers-inside-device-code-flow-exploit

    阅读全文
  • 文章封面

    红队金矿:从 MDT 部署共享中提取凭据

    作者:securitainment发布日期:2026-05-19 11:11:00

    原文链接作者https://trustedsec.com/blog/red-team-gold-extracting-credentials-from-mdt-sharesOddvar Moe在红队行

    阅读全文
  • 文章封面

    理解 Windows 内核漏洞利用中的整数溢出

    作者:securitainment发布日期:2026-05-19 11:11:00

    原文链接作者https://whiteknightlabs.com/2025/05/27/understanding-integer-overflow-in-windows-kernel-exploi

    阅读全文
  • 文章封面

    DoublePulsar:Crystal Palace 与 Tradecraft Garden 时代的用户自定义反射加载器

    作者:securitainment发布日期:2026-05-18 21:11:00

    原文链接作者https://memn0ps.github.io/doublepulsar-a-user-defined-reflective-loader-in-the-crystal-palace-

    阅读全文
下一页