文章预览
内网渗透 remotechrome:借助atexec与CDP远程转储Chrome Cookies https://github.com/zimnyaa/remotechrome 终端对抗 Windows平台ARM64/AArch64架构Shellcode编写 https://modexp.wordpress.com/2024/09/16/windows_arm64/ 延迟导入表phantomDLL的机会探究 https://www.hexacorn.com/blog/2024/09/14/the-delayed-import-table-phantomdll-opportunities/ NyxInvoke:基于Rust的.NET程序集、Powershell命令与BOF加载器,集成AMSI/ETW修补 https://github.com/BlackSnufkin/NyxInvoke BYOSI:借助自带PHP脚本解释器绕过EDR执行恶意代码 https://github.com/oldkingcone/BYOSI PolyDrop:BYOSI快速载荷部署工具箱 https://github.com/MalwareSupportGroup/PolyDrop PPLrevenant:借助BYODLL技术绕过LSA保护 https://github.com/itm4n/PPLrevenant DLL代理攻击技术介绍 https://www.blackhillsinfosec.com/a-different-take-on-dll-hijacking/ 借助恶意软件虚拟化规避终端检测 https://blog.fox-it.com/2024/09/25/red-teaming-in-the-age-of-edr-evasion-of-e
………………………………