文章总结: 红蓝对抗技术动态更新,包含红队和蓝队技术文章、工具类资源和其他类内容,涉及恶意软件动态分析、EDR绕过、内存保护、权限提升等技术。 综合评分: 75 文章分类: 渗透测试,红队,内网渗透,恶意软件,安全工具
攻防技战术动态一周更新 – 20260921
原创
红蓝对抗技术 红蓝对抗技术
红蓝对抗技战术
2026年9月27日 11:23 北京
在小说阅读器读本章
去阅读
在公众号小说中沉浸阅读
漏洞相关
1、
红队技术
1、Malware Dynamic Analysis Evasion Techniques: A Survey
https://dl.acm.org/doi/fullHtml/10.1145/3365001
2、Bypassing EDR with Local AI
https://projectblack.io/blog/bypassing-edr-with-local-ai/
3、OBJECT_ATTRIBUTES Explained: How the Native API Opens Kernel Objects
https://trainsec.net/library/windows-internals/object-attributes-explained-how-the-native-api-opens-kernel-objects/
4、Windows Privilege Escalation: SeManageVolumePrivilege
https://www.hackingarticles.in/windows-privilege-escalation-semanagevolumeprivilege/
5、Even more privileged ADCS ESC_CES
https://adhdmurky.github.io/posts/post4/
蓝队技术
1、🛡️ MemGuard — Zero-Dependency LSASS Memory Shield & EDR Hook Detector
https://github.com/prox0959/MemGuard
2、MuddyWater’s Rented Arsenal and Its Traces in the Russian MaaS Market
https://medium.com/@Root0ne/muddywaters-rented-arsenal-and-its-traces-in-the-russian-maas-market-d58965401f15
工具类
1、LocalStranger
https://github.com/nbs32k/LocalStranger
PoC for WinNotify, demonstrated through a driver mapper, and local privilege escalation.
2、HimitsuShell
https://github.com/HimitsuShell/HimitsuShell
shell script protector (obfuscation, embedded interpreter, DRM) – invisible to kernel tracing
3、Linux LPE Toolkit
https://github.com/portbuster1337/lpe-toolkit
Multi-architecture Linux privilege escalation toolkit with 29 pre-built and runtime-compilable exploits. Auto-detects kernel version, filters patched exploits, tries each until root.
4、CnaEmulator – Cobalt Strike Aggressor Script Emulator & Mock Harness
https://github.com/iterat0r/CnaEmulator
5、DPAPI-toolkit
https://github.com/crypt0p3g/dpapi-toolkit
Drop any Windows DPAPI artifact and it identifies the format and the exact master key it needs, then decrypts once you supply the key. Offline, CLI + web UI.
6、learning_ai_pentesting
https://github.com/mr-r3b00t/learning_ai_pentesting/7、Snaffler (Python)
7、Snaffler (Python)
https://github.com/S3cur3Th1sSh1t/SnafflePy/tree/main
A feature-for-feature Python port of SnaffCon/Snaffler, using impacket for SMB share enumeration, file access and authentication, and ldap3/impacket LDAP for Active Directory discovery.
8、AKCA
https://github.com/akha-security/akca
AKCA Advanced Web Security Scanner
9、Situational Awareness BOF – Cross-platform BOFs
https://github.com/sliverarmory/CS-Situational-Awareness-BOF
10、File Notification Attacks – Artifacts
https://github.com/isec-tugraz/file-notification-attacks、
11、Ultimate WDAC Bypass List
https://github.com/bohops/UltimateWDACBypassList
其他类
1、
免责声明:
本文所载程序、技术方法仅面向合法合规的安全研究与教学场景,旨在提升网络安全防护能力,具有明确的技术研究属性。
任何单位或个人未经授权,将本文内容用于攻击、破坏等非法用途的,由此引发的全部法律责任、民事赔偿及连带责任,均由行为人独立承担,本站不承担任何连带责任。
本站内容均为技术交流与知识分享目的发布,若存在版权侵权或其他异议,请通过邮件联系处理,具体联系方式可点击页面上方的联系我。
本文转载自:红蓝对抗技战术 红蓝对抗技术 红蓝对抗技术《攻防技战术动态一周更新 – 20260921》
版权声明
本站仅做备份收录,仅供研究与教学参考之用。
读者将信息用于其他用途的,全部法律及连带责任由读者自行承担,本站不承担任何责任。








评论