倾旋的博客 - 现阶段在进行有效性验证/攻击模拟相关的安全研究工作,我的博客会记录一些我的学习过程和部分安全技术研究成果。
倾旋的博客

倾旋的博客

现阶段在进行有效性验证/攻击模拟相关的安全研究工作,我的博客会记录一些我的学习过程和部分安全技术研究成果。

20 Dec 2018

最近学习Windows编程总结

1,961 words, ~7 min read

总结一下最近学习Windows编程的知识点。
19 Dec 2018

Intranet Space - Linux Privilege

116 words, ~0 min read

Linux Privilege -> Exploit
19 Dec 2018

Intranet Space - nishang <ReadTeam/Powershell/Penetration-testing>

1,406 words, ~5 min read

Nishang is a framework and collection of scripts and payloads which enables usage of PowerShell for offensive security, penetration testing and red teaming. Nishang is useful during all phases of penetration testing.
18 Dec 2018

Intranet Space - Dns Tunneling

904 words, ~3 min read

DNS Tunneling,是隐蔽信道的一种,通过将其他协议封装在DNS协议中传输建立通信。因为在我们的网络世界中DNS是一个必不可少的服务,所以大部分防火墙和入侵检测设备很少会过滤DNS流量,这就给DNS作为一种隐蔽信道提供了条件,从而可以利用它实现诸如远程控制,文件传输等操作,现在越来越多的研究证明DNS Tunneling也经常在僵尸网络和APT攻击中扮演着重要的角色。
18 Dec 2018

Intranet Space - p0wnedShell

365 words, ~1 min read

p0wnedShell is an offensive PowerShell Runspace Post Exploitation host application written in C# that does not rely on powershell.exe but runs PowerShell commands and functions within a PowerShell run space environment (.NET). It has a lot of offensive PowerShell modules and binaries included making the process of Post Exploitation easier.
15 Dec 2018

Intranet Space - Empire

765 words, ~3 min read

Empire is a PowerShell and Python post-exploitation agent.
05 Dec 2018

应急响应 近期总结

1,662 words, ~6 min read

总结一下近期做的一些应急响应心得
30 Nov 2018

彻底理解Windows认证 - 议题解读

7,934 words, ~31 min read

在内部分享的《彻底理解Windows认证》议题解读
26 Nov 2018

内网渗透心得

1,101 words, ~4 min read

内网渗透心得
04 Nov 2018