攻防技战术动态一周更新–20260330

admin 2026-04-07 01:01:22 网络安全文章 来源:ZONE.CI 全球网 0 阅读模式

文章总结: 文档汇总了2026年3月30日当周的红蓝对抗技术动态,涵盖红队技巧(如免杀、权限提升、凭证转储)、蓝队检测方案(如KslKatz框架识别、Rootkit检测)及实用工具(InfraGuard、WinDefenderKiller等),提供攻防实战参考与技术演进洞察。 综合评分: 82 文章分类: 红队,蓝队,安全工具,漏洞分析,威胁情报


cover_image

攻防技战术动态一周更新 – 20260330

原创

红蓝对抗技术 红蓝对抗技术

红蓝对抗技战术

2026年4月5日 10:49 北京

漏洞相关

1、

红队技术

1、Unwind Data Can’t Sleep – Introducing InsomniacUnwinding

https://lorenzomeacci.com/unwind-data-cant-sleep-introducing-insomniacunwinding

2、An Operators Guide to Beacon Object Files

https://maldev.nl/posts/operator-guide-bof/

3、AI免杀 – 利用Trae+Skills流程化免杀主流杀软

https://mp.weixin.qq.com/s/jhcnPTJNiAMPZHP86Qj2cw

4、Credential Dumping: Local Security Authority (LSA|LSASS.EXE)

https://www.hackingarticles.in/credential-dumping-local-security-authority-lsalsass-exe/

5、Local Privilege Escalation through BYOVD with Kernel R/W Primitives

https://medium.com/@s12deff/local-privilege-escalation-through-byovd-with-kernel-r-w-primitives-2e27878725a2

6、Debugging a PyInstaller EXE file with Windbg

https://v1k1ngfr.github.io/debugging-PyInstaller-EXE-file-with-windbg/

7、Mythic C2 with EarlyBird Injection and Defender Evasion

https://xbz0n.sh/blog/mythic-c2-early-bird-defender-evasion

8、Weaponizing BYOVD to Kill and Evade Windows Defender

https://medium.com/@s12deff/weaponizing-byovd-to-kill-and-evade-windows-defender-535ad94652b0

9、How to build .NET obfuscator – Part I

https://kant2002.github.io/en/obfuscators/2026/04/02/how-to-build-obfuscator-part-i.html

10、ghostsurf: From NTLM Relay to Browser Session Hijacking

https://specterops.io/blog/2026/04/02/ghostsurf-from-ntlm-relay-to-browser-session-hijacking/?utm_source=twitter&utm_medium=social&utm_campaign=soc-blog-260402-ghostsurf

11、Gaining Initial Access and Outsmarting SmartScreen

https://g3tsyst3m.com/initial%20access/Gaining-Initial-Access-and-Outsmarting-SmartScreen/

蓝队技术

1、Ghost in LSASS: Detecting KslKatz Credential Dumping Framework

https://detect.fyi/ghost-in-lsass-detecting-kslkatz-credential-dumping-framework-8645f246aec9

2、Qilin EDR killer infection chain

https://blog.talosintelligence.com/qilin-edr-killer/

3、Hooked on Linux: Rootkit Detection Engineering

https://www.elastic.co/security-labs/linux-rootkits-2-caught-in-the-act

工具类

1、InfraGuard

https://github.com/Whispergate/InfraGuardInfraGuard is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution

2、WebRelayX

https://github.com/SecCoreGmbH/WebRelayX

NTLM Relaying to generic web services with NTLM authentication

3、WinDefenderKiller

https://github.com/S12cybersecurity/WinDefenderKiller

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

4、3LayersPersistenc

https://github.com/Maldev-Academy/3LayersPersistence

Demonstrating 3 persistence layers from a single EXE, that converts itself into proxy DLLs at runtime

5、NOFILTER-NFEXEC

https://github.com/y637F9QQ2x/NOFILTER-NFEXEC

Havoc C2 BOF — WFP kernel-space SYSTEM escalation + command execution with indirect syscalls, patchless AMSI/ETW bypass, and return address spoofing

6、Brutus

https://github.com/praetorian-inc/brutus

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native nerva/naabu pipeline integration.

7、WinDefenderKiller

https://github.com/S12cybersecurity/WinDefenderKiller

Windows Defender Killer | Registry-Based Disablement + BYOVD Process Termination (C++)

8、KslKatzBOF

https://github.com/PrincipleCheck/KslKatzBof

9、KslKatz

https://github.com/yenick514/KslKatz

其他类

1、


免责声明:

本文所载程序、技术方法仅面向合法合规的安全研究与教学场景,旨在提升网络安全防护能力,具有明确的技术研究属性。

任何单位或个人未经授权,将本文内容用于攻击、破坏等非法用途的,由此引发的全部法律责任、民事赔偿及连带责任,均由行为人独立承担,本站不承担任何连带责任。

本站内容均为技术交流与知识分享目的发布,若存在版权侵权或其他异议,请通过邮件联系处理,具体联系方式可点击页面上方的联系我

本文转载自:红蓝对抗技战术 红蓝对抗技术 红蓝对抗技术《攻防技战术动态一周更新 – 20260330》

评论:0   参与:  0