文章总结: 该文档为2026年9月7日攻防技战术动态周报,涵盖漏洞相关、红队技术、蓝队技术及安全工具等板块。红队技术涉及DLL侧加载、凭据转储、组策略渗透、无文件ELF执行、AD服务模拟及华硕内核驱动0day漏洞等;蓝队技术介绍Token分析与追踪系统;工具类收录LinuxLPE工具包、PassTheCert-rs、NTLMRain、HashSiphon、TornadoRevC2等10款安全工具,为安全研究人员提供最新攻防技术参考。 综合评分: 85 文章分类: 红队,蓝队,安全工具,漏洞分析
攻防技战术动态一周更新 – 20260907
原创
红蓝对抗技术 红蓝对抗技术
红蓝对抗技战术
2026年9月12日 15:52 北京
在小说阅读器读本章
去阅读
在公众号小说中沉浸阅读
漏洞相关
1、
红队技术
1、From Intrusion Analysis to HijackLibs: DLL Sideloading Research
https://www.infosecharry.co.uk/blog/dll-sideloading
2、Credential Dumping via File Handle Redirection
https://medium.com/@s12deff/credential-dumping-via-file-handle-redirection-b2fe15b61181
3、Pentesting: Group Policy for Hackers – Basics
https://hackers-arise.com/pentesting-group-policy-for-hackers-basics/
4、Fileless ELF Execution via Kernel Keyring
https://matheuzsecurity.github.io/hacking/linux-kernel-keyring-fileless-exec/
5、Simulating legitimate Active Directory services on the network: the case of GPO exploitation
https://www.synacktiv.com/en/publications/simulating-legitimate-active-directory-services-on-the-network-the-case-of-gpo
6、Windows Active Directory(AD) Penetration Testing: Account Takeover leading to full compromise
https://medium.com/@pture/windows-active-directory-ad-penetration-testing-account-takeover-leading-to-full-compromise-d87c34b10988
7、Asustek Kernel Driver Asio3.sys 0-day vulnerability
https://www.exploitpack.com/blogs/research/asustek-kernel-driver-asio3-sys-0-day-vulnerability
蓝队技术
1、Token Analysis and Tracking System (TATS)
https://specterops.io/blog/2026/09/08/token-analysis-and-tracking-system-tats/#
工具类
1、Linux LPE Toolkit
https://github.com/portbuster1337/lpe-toolkit
2、PassTheCert-rs
https://github.com/g0h4n/PassTheCert-rs
Tool to authenticate to an LDAP/S server with a certificate through Schannel written in Rust. 🦀
3、NTLMRain
https://github.com/outflanknl/ntlmrain
Recover NT hashes from NetNTLMv1 responses using local WebGPU computation and local/remote table lookup
4、HashSiphon
https://github.com/ivancabrera02/HashSiphon
NTLM hash extraction through HTTP-layer authentication proxying, zero SSPI calls from the attacker process.
5、TornadoRevC2
https://github.com/kamalx06/TornadoRevC2
A lightweight, modular post-exploitation framework for Linux and Windows that provides reverse shell session management, cross-platform plugins, SOCKS5 pivoting, in-memory payload execution, resumable file transfers with SHA-256 verification, and structured per-session logging for authorized security research and penetration testing.
6、TitanHide
https://github.com/mrexodia/TitanHide
Hiding kernel-driver for x86/x64.
7、RustHound-CE
https://github.com/g0h4n/RustHound-CE
Active Directory data ingestor for BloodHound Community Edition written in Rust. 🦀
8、adexsnap
https://github.com/crypt0p3g/adexsnap
Active Directory snapshots from Linux and macOS in the AD Explorer .dat format. Opens in AD Explorer, works with ADExplorerSnapshot.py and BOFHound.
9、SpecterOps Skills
https://github.com/SpecterOps/skills
A marketplace for LLM skills
10、adexview
https://github.com/crypt0p3g/adexview?1
Browse, search and audit AD Explorer snapshots offline in your browser: decoded attributes, LDAP filters, and reports for what BloodHound doesn’t show (DNS, subnets, DFS, GPO links, LAPS, AD CS).
其他类
1、
免责声明:
本文所载程序、技术方法仅面向合法合规的安全研究与教学场景,旨在提升网络安全防护能力,具有明确的技术研究属性。
任何单位或个人未经授权,将本文内容用于攻击、破坏等非法用途的,由此引发的全部法律责任、民事赔偿及连带责任,均由行为人独立承担,本站不承担任何连带责任。
本站内容均为技术交流与知识分享目的发布,若存在版权侵权或其他异议,请通过邮件联系处理,具体联系方式可点击页面上方的联系我。
本文转载自:红蓝对抗技战术 红蓝对抗技术 红蓝对抗技术《攻防技战术动态一周更新 – 20260907》
版权声明
本站仅做备份收录,仅供研究与教学参考之用。
读者将信息用于其他用途的,全部法律及连带责任由读者自行承担,本站不承担任何责任。









![[更新]红队DLL劫持工具v1.3.1:MCP支持,AI对话即可生成](/images/random/titlepic/6.jpg)
评论