攻防技战术动态一周更新–20260921

admin 2026-09-28 04:53:22 网络安全文章 来源:ZONE.CI 全球网 0 阅读模式

文章总结: 红蓝对抗技术动态更新,包含红队和蓝队技术文章、工具类资源和其他类内容,涉及恶意软件动态分析、EDR绕过、内存保护、权限提升等技术。 综合评分: 75 文章分类: 渗透测试,红队,内网渗透,恶意软件,安全工具


攻防技战术动态一周更新 – 20260921

原创

红蓝对抗技术 红蓝对抗技术

红蓝对抗技战术

2026年9月27日 11:23 北京

在小说阅读器读本章

去阅读

在公众号小说中沉浸阅读

漏洞相关

1、

红队技术

1、Malware Dynamic Analysis Evasion Techniques: A Survey

https://dl.acm.org/doi/fullHtml/10.1145/3365001

2、Bypassing EDR with Local AI

https://projectblack.io/blog/bypassing-edr-with-local-ai/

3、OBJECT_ATTRIBUTES Explained: How the Native API Opens Kernel Objects

https://trainsec.net/library/windows-internals/object-attributes-explained-how-the-native-api-opens-kernel-objects/

4、Windows Privilege Escalation: SeManageVolumePrivilege

https://www.hackingarticles.in/windows-privilege-escalation-semanagevolumeprivilege/

5、Even more privileged ADCS ESC_CES

https://adhdmurky.github.io/posts/post4/

蓝队技术

1、🛡️ MemGuard — Zero-Dependency LSASS Memory Shield & EDR Hook Detector

https://github.com/prox0959/MemGuard

2、MuddyWater’s Rented Arsenal and Its Traces in the Russian MaaS Market

https://medium.com/@Root0ne/muddywaters-rented-arsenal-and-its-traces-in-the-russian-maas-market-d58965401f15

工具类

1、LocalStranger

https://github.com/nbs32k/LocalStranger

PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation.

2、HimitsuShell

https://github.com/HimitsuShell/HimitsuShell

shell script protector (obfuscation, embedded interpreter, DRM) – invisible to kernel tracing

3、Linux LPE Toolkit

https://github.com/portbuster1337/lpe-toolkit

Multi-architecture Linux privilege escalation toolkit with 29 pre-built and runtime-compilable exploits. Auto-detects kernel version, filters patched exploits, tries each until root.

4、CnaEmulator – Cobalt Strike Aggressor Script Emulator & Mock Harness

https://github.com/iterat0r/CnaEmulator

5、DPAPI-toolkit

https://github.com/crypt0p3g/dpapi-toolkit

Drop any Windows DPAPI artifact and it identifies the format and the exact master key it needs, then decrypts once you supply the key. Offline, CLI + web UI.

6、learning_ai_pentesting

https://github.com/mr-r3b00t/learning_ai_pentesting/7、Snaffler (Python)

7、Snaffler (Python)

https://github.com/S3cur3Th1sSh1t/SnafflePy/tree/main

A feature-for-feature Python port of SnaffCon/Snaffler, using impacket for SMB share enumeration, file access and authentication, and ldap3/impacket LDAP for Active Directory discovery.

8、AKCA

https://github.com/akha-security/akca

AKCA Advanced Web Security Scanner

9、Situational Awareness BOF – Cross-platform BOFs

https://github.com/sliverarmory/CS-Situational-Awareness-BOF

10、File Notification Attacks – Artifacts

https://github.com/isec-tugraz/file-notification-attacks、

11、Ultimate WDAC Bypass List

https://github.com/bohops/UltimateWDACBypassList

其他类

1、


免责声明:

本文所载程序、技术方法仅面向合法合规的安全研究与教学场景,旨在提升网络安全防护能力,具有明确的技术研究属性。

任何单位或个人未经授权,将本文内容用于攻击、破坏等非法用途的,由此引发的全部法律责任、民事赔偿及连带责任,均由行为人独立承担,本站不承担任何连带责任。

本站内容均为技术交流与知识分享目的发布,若存在版权侵权或其他异议,请通过邮件联系处理,具体联系方式可点击页面上方的联系我。

本文转载自:红蓝对抗技战术 红蓝对抗技术 红蓝对抗技术《攻防技战术动态一周更新 – 20260921》

评论:0   参与:  0