About:
Monitor WMI Persistence
Instructions about ExportsToC++
My test of using DiskCleanup on Windows 10 using DiskCleanup
目录:
介绍如何在系统日志中记录WMI Persistence,测试并分析如何绕过
dll劫持中会用到的一个
About:
DynamicWrapperX
Generate shellcode
Write JS and SCT script
How to use
Detection
目录:
介绍如何配置使用脚本附加库DynamicWrapperX
通过JS/VBS实现对win32 API的调用
如何在js脚本中加载shellcode
结合
About:
Common commands of netsh
Matthew Demaske’s way of using netshell to execute evil dlls and persist on a host
Write a dll with the InitHelperDll function
How to use
Detection
About:
Use odbcconf to load dll
Use powershell to get dll exports
Use Event Tracing for Windows to log keystrokes from USB keyboards
目录:
介绍为什么通过odbcconf加载dll可以绕过在命令行下对regsvr32的拦截
About:
use tracker to load dll
use csi to bypass Application Whitelisting
execute C# from XSLT file
目录:
介绍利用tracker.exe加载dll的方法
如何利用csi.exe绕过Windows Device Guard
在XSLT文件转换过程中执