文章总结: 文档汇总了2026年3月30日当周的红蓝对抗技术动态,涵盖红队技巧(如免杀、权限提升、凭证转储)、蓝队检测方案(如KslKatz框架识别、Rootkit检测)及实用工具(InfraGuard、WinDefenderKiller等),提供攻防实战参考与技术演进洞察。 综合评分: 82 文章分类: 红队,蓝队,安全工具,漏洞分析,威胁情报
攻防技战术动态一周更新 – 20260330
原创
红蓝对抗技术 红蓝对抗技术
红蓝对抗技战术
2026年4月5日 10:49 北京
漏洞相关
1、
红队技术
1、Unwind Data Can’t Sleep – Introducing InsomniacUnwinding
https://lorenzomeacci.com/unwind-data-cant-sleep-introducing-insomniacunwinding
2、An Operators Guide to Beacon Object Files
https://maldev.nl/posts/operator-guide-bof/
3、AI免杀 – 利用Trae+Skills流程化免杀主流杀软
https://mp.weixin.qq.com/s/jhcnPTJNiAMPZHP86Qj2cw
4、Credential Dumping: Local Security Authority (LSA|LSASS.EXE)
https://www.hackingarticles.in/credential-dumping-local-security-authority-lsalsass-exe/
5、Local Privilege Escalation through BYOVD with Kernel R/W Primitives
https://medium.com/@s12deff/local-privilege-escalation-through-byovd-with-kernel-r-w-primitives-2e27878725a2
6、Debugging a PyInstaller EXE file with Windbg
https://v1k1ngfr.github.io/debugging-PyInstaller-EXE-file-with-windbg/
7、Mythic C2 with EarlyBird Injection and Defender Evasion
https://xbz0n.sh/blog/mythic-c2-early-bird-defender-evasion
8、Weaponizing BYOVD to Kill and Evade Windows Defender
https://medium.com/@s12deff/weaponizing-byovd-to-kill-and-evade-windows-defender-535ad94652b0
9、How to build .NET obfuscator – Part I
https://kant2002.github.io/en/obfuscators/2026/04/02/how-to-build-obfuscator-part-i.html
10、ghostsurf: From NTLM Relay to Browser Session Hijacking
https://specterops.io/blog/2026/04/02/ghostsurf-from-ntlm-relay-to-browser-session-hijacking/?utm_source=twitter&utm_medium=social&utm_campaign=soc-blog-260402-ghostsurf
11、Gaining Initial Access and Outsmarting SmartScreen
https://g3tsyst3m.com/initial%20access/Gaining-Initial-Access-and-Outsmarting-SmartScreen/
蓝队技术
1、Ghost in LSASS: Detecting KslKatz Credential Dumping Framework
https://detect.fyi/ghost-in-lsass-detecting-kslkatz-credential-dumping-framework-8645f246aec9
2、Qilin EDR killer infection chain
https://blog.talosintelligence.com/qilin-edr-killer/
3、Hooked on Linux: Rootkit Detection Engineering
https://www.elastic.co/security-labs/linux-rootkits-2-caught-in-the-act
工具类
1、InfraGuard
https://github.com/Whispergate/InfraGuardInfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution
2、WebRelayX
https://github.com/SecCoreGmbH/WebRelayX
NTLM Relaying to generic web services with NTLM authentication
3、WinDefenderKiller
https://github.com/S12cybersecurity/WinDefenderKiller
Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)
4、3LayersPersistenc
https://github.com/Maldev-Academy/3LayersPersistence
Demonstrating 3 persistence layers from a single EXE, that converts itself into proxy DLLs at runtime
5、NOFILTER-NFEXEC
https://github.com/y637F9QQ2x/NOFILTER-NFEXEC
Havoc C2 BOF — WFP kernel-space SYSTEM escalation + command execution with indirect syscalls, patchless AMSI/ETW bypass, and return address spoofing
6、Brutus
https://github.com/praetorian-inc/brutus
Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native nerva/naabu pipeline integration.
7、WinDefenderKiller
https://github.com/S12cybersecurity/WinDefenderKiller
Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)
8、KslKatzBOF
https://github.com/PrincipleCheck/KslKatzBof
9、KslKatz
https://github.com/yenick514/KslKatz
其他类
1、
免责声明:
本文所载程序、技术方法仅面向合法合规的安全研究与教学场景,旨在提升网络安全防护能力,具有明确的技术研究属性。
任何单位或个人未经授权,将本文内容用于攻击、破坏等非法用途的,由此引发的全部法律责任、民事赔偿及连带责任,均由行为人独立承担,本站不承担任何连带责任。
本站内容均为技术交流与知识分享目的发布,若存在版权侵权或其他异议,请通过邮件联系处理,具体联系方式可点击页面上方的联系我。
本文转载自:红蓝对抗技战术 红蓝对抗技术 红蓝对抗技术《攻防技战术动态一周更新 – 20260330》
版权声明
本站仅做备份收录,仅供研究与教学参考之用。
读者将信息用于其他用途的,全部法律及连带责任由读者自行承担,本站不承担任何责任。









评论