{"id":73747,"date":"2026-02-08T10:09:40","date_gmt":"2026-02-08T02:09:40","guid":{"rendered":"https:\/\/www.wsisp.com\/helps\/73747.html"},"modified":"2026-02-08T10:09:40","modified_gmt":"2026-02-08T02:09:40","slug":"%e2%93%ab%e2%81%84%e2%82%81%e2%82%82-%e2%9f%a6-oscp-%e2%ac%96-%e7%a0%94%e8%ae%b0-%e2%9f%a7-windows%e6%9d%83%e9%99%90%e6%8f%90%e5%8d%87-%e2%9e%b1-%e6%9c%aa%e5%8a%a0%e5%bc%95%e5%8f%b7%e6%9c%8d%e5%8a%a1","status":"publish","type":"post","link":"https:\/\/www.wsisp.com\/helps\/73747.html","title":{"rendered":"\u24eb\u2044\u2081\u2082 \u27e6 OSCP \u2b16 \u7814\u8bb0 \u27e7 Windows\u6743\u9650\u63d0\u5347 \u27b1 \u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u5229\u7528\uff08\u4e0b\uff09"},"content":{"rendered":"<p>\u00a0\u00a0\u00a0\u00a0 \u00a0 \u00a0 \u00a0\u90d1\u91cd\u58f0\u660e&#xff1a;\u672c\u6587\u6240\u6d89\u5b89\u5168\u6280\u672f\u4ec5\u9650\u7528\u4e8e\u5408\u6cd5\u7814\u7a76\u4e0e\u5b66\u4e60\u76ee\u7684&#xff0c;\u4e25\u7981\u4efb\u4f55\u5f62\u5f0f\u7684\u975e\u6cd5\u5229\u7528\u3002\u56e0\u4e0d\u5f53\u4f7f\u7528\u6240\u5bfc\u81f4\u7684\u4e00\u5207\u6cd5\u5f8b\u4e0e\u7ecf\u6d4e\u8d23\u4efb&#xff0c;\u672c\u4eba\u6982\u4e0d\u8d1f\u8d23\u3002\u4efb\u4f55\u5f62\u5f0f\u7684\u8f6c\u8f7d\u5747\u987b\u660e\u786e\u6807\u6ce8\u539f\u6587\u51fa\u5904&#xff0c;\u4e14\u4e0d\u5f97\u7528\u4e8e\u5546\u4e1a\u76ee\u7684\u3002<\/p>\n<p>&#x1f50b; \u70b9\u8d5e | \u80fd\u91cf\u6ce8\u5165 \u2764\ufe0f\u00a0\u5173\u6ce8 | \u4fe1\u53f7\u9501\u5b9a &#x1f514;\u00a0\u6536\u85cf | \u6570\u636e\u5f52\u6863\u00a0\u2b50\ufe0f\u00a0\u8bc4\u8bba | \u4fdd\u6301\u8fde\u63a5&#x1f4ac;<\/p>\n<p>&#x1f30c;\u00a0\u7acb\u5373\u524d\u5f80\u00a0&#x1f449;<span>\u6656\u5ea6\u4e28\u5b89\u5168\u89c6\u754c<\/span>&#x1f680;\u200b<\/p>\n<p><span><img decoding=\"async\" alt=\"\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020934-6987f05ebfcdf.png\" \/><span title=\"\u70b9\u51fb\u5e76\u62d6\u62fd\u4ee5\u6539\u53d8\u5c3a\u5bf8\">\u200b<\/span><\/span>\u200b\u200b\u200b\u200b\u200b<\/p>\n<p>\u25b6 \u4fe1\u606f\u6536\u96c6\u00a0  \u25b6 \u6f0f\u6d1e\u68c0\u6d4b \u25b6 \u521d\u59cb\u7acb\u8db3\u70b9\u00a0 \u25b6 \u6743\u9650\u63d0\u5347\u00a0\u27a2 Windows\u6743\u9650\u63d0\u5347\u00a0\u27a2\u00a0\u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u5229\u7528&#xff08;\u4e0b&#xff09;&#x1f525;&#x1f525;&#x1f525; \u25b6 \u6a2a\u5411\u79fb\u52a8 \u25b6 \u62a5\u544a\/\u5206\u6790 \u25b6 \u6559\u8bad\/\u4fee\u590d<\/p>\n<p id=\"main-toc\">\u76ee\u5f55<\/p>\n<p id=\"1.Windows%E6%9D%83%E9%99%90%E6%8F%90%E5%8D%87-toc\" style=\"margin-left:0px\">1.Windows\u6743\u9650\u63d0\u5347<\/p>\n<p id=\"1.1%20Windows%E6%9C%AA%E5%8A%A0%E5%BC%95%E5%8F%B7%E6%9C%8D%E5%8A%A1%E8%B7%AF%E5%BE%84%E6%BC%8F%E6%B4%9E%E5%88%A9%E7%94%A8-toc\" style=\"margin-left:40px\">1.1 Windows\u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u5229\u7528<\/p>\n<p id=\"1.1.2%20%E6%9C%AA%E5%8A%A0%E5%BC%95%E5%8F%B7%E6%9C%8D%E5%8A%A1%E8%B7%AF%E5%BE%84%E6%BC%8F%E6%B4%9E%E5%AE%9E%E8%B7%B5-toc\" style=\"margin-left:80px\">1.1.2 \u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u5b9e\u8df5<\/p>\n<p id=\"1.1.2.1%20%E6%9E%9A%E4%B8%BE%E6%BC%8F%E6%B4%9E%E6%9C%8D%E5%8A%A1-toc\" style=\"margin-left:120px\">1.1.2.1 \u679a\u4e3e\u6f0f\u6d1e\u670d\u52a1<\/p>\n<p id=\"1.%20%E6%9C%8D%E5%8A%A1%E6%9E%9A%E4%B8%BE-toc\" style=\"margin-left:160px\">1. \u670d\u52a1\u679a\u4e3e<\/p>\n<p id=\"2.%E9%AA%8C%E8%AF%81%E5%90%AF%E5%8A%A8%2F%E5%81%9C%E6%AD%A2%E8%AF%A5%E6%9C%8D%E5%8A%A1%E7%9A%84%E6%9D%83%E9%99%90-toc\" style=\"margin-left:160px\">2.\u9a8c\u8bc1\u542f\u52a8\/\u505c\u6b62\u8be5\u670d\u52a1\u7684\u6743\u9650<\/p>\n<p id=\"1.1.2.2%20%E8%B7%AF%E5%BE%84%E6%9D%83%E9%99%90%E6%A3%80%E6%9F%A5-toc\" style=\"margin-left:120px\">1.1.2.2 \u8def\u5f84\u6743\u9650\u68c0\u67e5<\/p>\n<p id=\"1.1.2.3%C2%A0%E6%9E%84%E5%BB%BA%E4%B8%8E%E9%83%A8%E7%BD%B2%E6%81%B6%E6%84%8F%E7%A8%8B%E5%BA%8F-toc\" style=\"margin-left:120px\">1.1.2.3\u00a0\u6784\u5efa\u4e0e\u90e8\u7f72\u6076\u610f\u7a0b\u5e8f<\/p>\n<p id=\"1.1.2.4%C2%A0%E6%9C%8D%E5%8A%A1%E5%90%AF%E5%8A%A8%E4%B8%8E%E6%94%BB%E5%87%BB%E9%AA%8C%E8%AF%81-toc\" style=\"margin-left:120px\">1.1.2.4\u00a0\u670d\u52a1\u542f\u52a8\u4e0e\u653b\u51fb\u9a8c\u8bc1<\/p>\n<p id=\"1.1.3%C2%A0%E4%BD%BF%E7%94%A8%E8%87%AA%E5%8A%A8%E5%8C%96%E5%B7%A5%E5%85%B7PowerUp.ps1%E5%88%A9%E7%94%A8%E6%BC%8F%E6%B4%9E-toc\" style=\"margin-left:80px\">1.1.3\u00a0\u4f7f\u7528\u81ea\u52a8\u5316\u5de5\u5177PowerUp.ps1\u5229\u7528\u6f0f\u6d1e<\/p>\n<p id=\"1.1.3.1%20%E6%81%A2%E5%A4%8D%E5%8E%9F%E5%A7%8B%E6%9C%8D%E5%8A%A1%E5%8A%9F%E8%83%BD-toc\" style=\"margin-left:120px\">1.1.3.1 \u6062\u590d\u539f\u59cb\u670d\u52a1\u529f\u80fd<\/p>\n<p id=\"1.1.3.2%20%E4%BD%BF%E7%94%A8%E8%87%AA%E5%8A%A8%E5%8C%96%E5%B7%A5%E5%85%B7%20PowerUp.ps1%20%E8%AF%86%E5%88%AB%E4%B8%8E%E5%88%A9%E7%94%A8%E6%BC%8F%E6%B4%9E-toc\" style=\"margin-left:120px\">1.1.3.2 \u4f7f\u7528\u81ea\u52a8\u5316\u5de5\u5177 PowerUp.ps1 \u8bc6\u522b\u4e0e\u5229\u7528\u6f0f\u6d1e<\/p>\n<p id=\"1.1.4%20%E6%9C%AA%E5%8A%A0%E5%BC%95%E5%8F%B7%E6%9C%8D%E5%8A%A1%E8%B7%AF%E5%BE%84%E6%BC%8F%E6%B4%9E%E5%88%A9%E7%94%A8%E5%85%A8%E6%B5%81%E7%A8%8B%E6%80%BB%E7%BB%93-toc\" style=\"margin-left:80px\">1.1.4 \u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u5229\u7528\u5168\u6d41\u7a0b\u603b\u7ed3<\/p>\n<p id=\"%E6%AC%A2%E8%BF%8E%E2%9D%A4%EF%B8%8F%20%E7%82%B9%E8%B5%9E%20%7C%20%F0%9F%94%94%20%E5%85%B3%E6%B3%A8%20%7C%20%E2%AD%90%EF%B8%8F%20%E6%94%B6%E8%97%8F%20%7C%20%F0%9F%92%AC%20%E8%AF%84%E8%AE%BA-toc\" style=\"margin-left:0px\">\u6b22\u8fce\u2764\ufe0f \u70b9\u8d5e | &#x1f514; \u5173\u6ce8 | \u2b50\ufe0f \u6536\u85cf | &#x1f4ac; \u8bc4\u8bba<\/p>\n<hr id=\"hr-toc\" \/>\n<h2 style=\"background-color:transparent\">1.Windows\u6743\u9650\u63d0\u5347<\/h2>\n<p>\u00a0 \u00a0 \u00a0 \u5728\u6e17\u900f\u6d4b\u8bd5\u4e2d&#xff0c;\u6211\u4eec\u901a\u5e38\u4ee5\u975e\u7279\u6743\u7528\u6237\u8eab\u4efd\u83b7\u5f97\u521d\u59cb\u7acb\u8db3\u70b9\u3002\u4f46\u4e3a\u4e86\u6df1\u5165\u63a2\u6d4b&#xff08;\u5982\u641c\u7d22\u654f\u611f\u4fe1\u606f\u3001\u63d0\u53d6\u5bc6\u7801\u54c8\u5e0c\u7b49&#xff09;&#xff0c;\u5f80\u5f80\u9700\u8981\u63d0\u5347\u81f3\u7ba1\u7406\u5458\u6743\u9650&#xff08;\u6bd4\u5982&#xff1a;\u4f7f\u7528Mimikatz\u63d0\u53d6\u5bc6\u7801\u54c8\u5e0c&#xff09;&#xff0c;\u8fd9\u4e2a\u8fc7\u7a0b\u5c31\u662f\u7279\u6743\u63d0\u5347\u3002<\/p>\n<p>&#x1f4ca; \u6743\u9650\u63d0\u5347\u4e09\u5927\u8def\u5f84&#xff1a;\u672c\u6587\u5f00\u59cb\u4ecb\u7ecd&#xff1a;Windows\u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u5229\u7528\u3002<\/p>\n<table>\n<tr>\u9636\u6bb5\u76ee\u6807\u5173\u952e\u65b9\u6cd5<\/tr>\n<tbody>\n<tr>\n<td>1. \u679a\u4e3eWindows<\/td>\n<td>\u83b7\u53d6\u7cfb\u7edf\u60c5\u62a5<\/td>\n<td>\u624b\u52a8\u641c\u7d22 &#043; \u81ea\u52a8\u5316\u5de5\u5177<\/td>\n<\/tr>\n<tr>\n<td>2. \u6ee5\u7528Windows\u670d\u52a1<\/td>\n<td>\u653b\u51fb\u670d\u52a1\u6f0f\u6d1e<\/td>\n<td>\u670d\u52a1\u914d\u7f6e\u7f3a\u9677\u3001\u6743\u9650\u6ee5\u7528<\/td>\n<\/tr>\n<tr>\n<td>3. \u5229\u7528\u5176\u4ed6\u7ec4\u4ef6<\/td>\n<td>\u6269\u5927\u653b\u51fb\u9762<\/td>\n<td>\u8ba1\u5212\u4efb\u52a1\u3001\u7cfb\u7edf\u6f0f\u6d1e\u5229\u7528<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr \/>\n<h3 id=\"1.1%20Windows%E6%9C%AA%E5%8A%A0%E5%BC%95%E5%8F%B7%E6%9C%8D%E5%8A%A1%E8%B7%AF%E5%BE%84%E6%BC%8F%E6%B4%9E%E5%88%A9%E7%94%A8\">1.1 Windows\u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u5229\u7528<\/h3>\n<h4 id=\"1.1.2%20%E6%9C%AA%E5%8A%A0%E5%BC%95%E5%8F%B7%E6%9C%8D%E5%8A%A1%E8%B7%AF%E5%BE%84%E6%BC%8F%E6%B4%9E%E5%AE%9E%E8%B7%B5\" style=\"background-color:transparent\">1.1.2 \u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u5b9e\u8df5<\/h4>\n<h5 id=\"1.1.2.1%20%E6%9E%9A%E4%B8%BE%E6%BC%8F%E6%B4%9E%E6%9C%8D%E5%8A%A1\">1.1.2.1 \u679a\u4e3e\u6f0f\u6d1e\u670d\u52a1<\/h5>\n<p>\u00a0 \u00a0 \u00a0 \u73b0\u5728\u5bf9\u8fd9\u4e2a\u6f0f\u6d1e\u539f\u7406\u6709\u57fa\u672c\u4e86\u89e3&#xff0c;\u8ba9\u6211\u4eec\u5b9e\u8df5\u4e00\u4e0b\u3002\u4ee5RDP\u8fde\u63a5\u5230CLIENTWK220&#xff08;\u7528\u6237\u540dsteve &#xff1b;\u5bc6\u7801securityIsNotAnOption&#043;&#043;&#043;&#043;&#043;&#043;&#xff09;&#xff0c;\u7136\u540e\u5f00\u59cb\u679a\u4e3e\u6b63\u5728\u8fd0\u884c\u548c\u505c\u6b62\u7684\u670d\u52a1\u3002<\/p>\n<h6 id=\"1.%20%E6%9C%8D%E5%8A%A1%E6%9E%9A%E4%B8%BE\">1. \u670d\u52a1\u679a\u4e3e<\/h6>\n<p>\u00a0 \u00a0 \u00a0 \u4f7f\u7528PowerShell\u6216WMIC\u5de5\u5177\u5217\u4e3e\u7cfb\u7edf\u670d\u52a1&#xff0c;\u91cd\u70b9\u5173\u6ce8&#xff1a;<\/p>\n<ul>\n<li>\u975eWindows\u76ee\u5f55&#xff08;\u56e0\u4e3a\u666e\u901a\u7528\u6237\u6ca1\u6709\u6743\u9650\u5199\u5165&#xff09;<\/li>\n<li>\u8def\u5f84\u5305\u542b\u7a7a\u683c\u672a\u52a0\u5f15\u53f7\u7684\u670d\u52a1&#xff08;\u53ef\u505a\u6f0f\u6d1e\u5229\u7528&#xff09;<\/li>\n<\/ul>\n<p>\u2460PowerShell&#xff1a;<\/p>\n<p><span><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"188\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020935-6987f05f1f1e7.png\" width=\"830\" \/><span title=\"\u70b9\u51fb\u5e76\u62d6\u62fd\u4ee5\u6539\u53d8\u5c3a\u5bf8\">\u200b<\/span><\/span><\/p>\n<p>\u00a0 \u00a0 \u00a0 \u4e0a\u56fe\u663e\u793a&#xff1a;\u4e00\u4e2a\u540d\u4e3aGammaService\u7684\u505c\u6b62\u670d\u52a1\u3002\u5b83\u672a\u52a0\u5f15\u53f7\u7684\u670d\u52a1\u4e8c\u8fdb\u5236\u8def\u5f84\u5305\u542b\u591a\u4e2a\u7a7a\u683c&#xff0c;\u56e0\u6b64\u53ef\u80fd\u5bb9\u6613\u53d7\u5230\u6b64\u653b\u51fb\u5411\u91cf\u7684\u5f71\u54cd\u3002<\/p>\n<p>\u6216\u2461WMIC\u5de5\u5177&#xff1a;&#xff08;cmd\u73af\u5883&#xff09;<\/p>\n<p> wmic service get name,pathname | findstr \/i \/v <span class=\"hljs-string\">&#034;C:\\\\Windows\\\\\\\\&#034;<\/span> | findstr \/i \/v <span class=\"hljs-string\">&#034;&#034;<\/span><span class=\"hljs-string\">&#034;<\/span> <\/p>\n<p><span><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"130\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020935-6987f05f361b1.png\" width=\"831\" \/><span title=\"\u70b9\u51fb\u5e76\u62d6\u62fd\u4ee5\u6539\u53d8\u5c3a\u5bf8\">\u200b<\/span><\/span><\/p>\n<table>\n<tr>\u547d\u4ee4\u90e8\u5206\u529f\u80fd\u8bf4\u660e<\/tr>\n<tbody>\n<tr>\n<td>wmic service get name,pathname<\/td>\n<td>\u67e5\u8be2\u6240\u6709Windows\u670d\u52a1\u7684\u540d\u79f0\u548c\u53ef\u6267\u884c\u6587\u4ef6\u8def\u5f84<\/td>\n<\/tr>\n<tr>\n<td>findstr \/i \/v &#034;C:\\\\Windows\\\\&#034;<\/td>\n<td>\n<p>\u7b2c\u4e00\u6b21\u8fc7\u6ee4&#xff1a;\u6392\u9664\u7cfb\u7edf\u76ee\u5f55&#xff08;C:\\\\Windows\\\\&#xff09;\u4e0b\u7684\u670d\u52a1&#xff0c;\u805a\u7126\u4e8e\u7b2c\u4e09\u65b9\u670d\u52a1<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td>findstr \/i \/v &#034;&#034;&#034;<\/td>\n<td>\u7b2c\u4e8c\u6b21\u8fc7\u6ee4&#xff1a;\u7b5b\u9009\u51fa\u8def\u5f84\u672a\u52a0\u5f15\u53f7\u5305\u88f9\u7684\u670d\u52a1&#xff08;&#034;&#034;&#034;\u5339\u914d\u5e26\u5f15\u53f7\u7684\u8def\u5f84&#xff09;<\/td>\n<\/tr>\n<tr>\n<td>\/i<\/td>\n<td>\u5ffd\u7565\u5927\u5c0f\u5199<\/td>\n<\/tr>\n<tr>\n<td>\/v<\/td>\n<td>\u53cd\u5411\u5339\u914d&#xff08;\u663e\u793a\u4e0d\u5305\u542b\u6307\u5b9a\u5b57\u7b26\u4e32\u7684\u884c&#xff09;<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>\u00a0 \u00a0 \u00a0 \u6b64\u547d\u4ee4\u4ec5\u5217\u51fa\u53ef\u80fd\u53d7\u5230\u653b\u51fb\u5411\u91cf\u5f71\u54cd\u7684\u670d\u52a1&#xff1a;GammaService&#xff0c;\u53ca\u5176\u8def\u5f84\u3002<\/p>\n<\/p>\n<p>\u6ce8\u610f&#xff1a;wmic\u5de5\u5177&#xff08;Windows Management Instrumentation Command-line&#xff09;\u5728\u67d0\u4e9b\u8f83\u65b0\u7684Windows\u7248\u672c\u4e2d\u5df2\u7ecf\u4e0d\u518d\u9ed8\u8ba4\u5b89\u88c5\u6216\u88ab\u5f03\u7528\u3002\u5982\u679c\u9700\u4f7f\u7528\u5b83&#xff0c;\u9700\u8981\u989d\u5916\u5b89\u88c5\u5b83\u3002<\/p>\n<h6 id=\"2.%E9%AA%8C%E8%AF%81%E5%90%AF%E5%8A%A8%2F%E5%81%9C%E6%AD%A2%E8%AF%A5%E6%9C%8D%E5%8A%A1%E7%9A%84%E6%9D%83%E9%99%90\">2.\u9a8c\u8bc1\u542f\u52a8\/\u505c\u6b62\u8be5\u670d\u52a1\u7684\u6743\u9650<\/h6>\n<p>\u00a0 \u00a0 \u00a0 \u76ee\u524d&#xff0c;\u662f\u4ee5\u7528\u6237steve\u7684\u8eab\u4efd\u767b\u5f55\u7684\u3002\u5728\u7ee7\u7eed\u4e4b\u524d&#xff0c;\u68c0\u67e5\u662f\u5426\u53ef\u4ee5\u4ee5steve\u7684\u8eab\u4efd\u4f7f\u7528Start-Service\u548cStop-Service\u542f\u52a8\u548c\u505c\u6b62\u5df2\u8bc6\u522b\u7684\u670d\u52a1GammaService&#xff0c;\u4ee5\u786e\u8ba4\u653b\u51fb\u53ef\u884c\u6027\u3002<\/p>\n<p><span><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"88\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020935-6987f05f486d2.png\" width=\"831\" \/><span title=\"\u70b9\u51fb\u5e76\u62d6\u62fd\u4ee5\u6539\u53d8\u5c3a\u5bf8\">\u200b<\/span><\/span><\/p>\n<p>\u00a0 \u00a0 \u00a0 \u4ece\u4ee5\u4e0a\u7684\u8f93\u51fa\u53ef\u770b\u51fa&#xff0c;\u7528\u6237steve\u5177\u6709\u542f\u52a8\u548c\u505c\u6b62GammaService\u7684\u6743\u9650\u3002\u7531\u4e8e\u53ef\u4ee5\u81ea\u5df1\u91cd\u65b0\u542f\u52a8\u8fd9\u4e2a\u670d\u52a1&#xff0c;\u6240\u4ee5\u4e0d\u9700\u8981\u53d1\u51fa\u91cd\u542f\u547d\u4ee4\u6765\u91cd\u65b0\u542f\u52a8\u670d\u52a1\u3002<\/p>\n<hr \/>\n<h5 id=\"1.1.2.2%20%E8%B7%AF%E5%BE%84%E6%9D%83%E9%99%90%E6%A3%80%E6%9F%A5\">1.1.2.2 \u8def\u5f84\u6743\u9650\u68c0\u67e5<\/h5>\n<p><span><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"102\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020935-6987f05f5870f.png\" width=\"1059\" \/><span title=\"\u70b9\u51fb\u5e76\u62d6\u62fd\u4ee5\u6539\u53d8\u5c3a\u5bf8\">\u200b<\/span><\/span><\/p>\n<p>\u00a0 \u00a0 \u00a0 \u63a5\u4e0b\u6765&#xff0c;\u5217\u51faWindows\u7528\u4e8e\u5c1d\u8bd5\u5b9a\u4f4d\u670d\u52a1\u53ef\u6267\u884c\u6587\u4ef6\u7684\u8def\u5f84&#xff08;\u7ea2\u6846\u90e8\u5206&#xff09;\u3002<\/p>\n<p><span><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"88\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020935-6987f05f6e042.png\" width=\"830\" \/><span title=\"\u70b9\u51fb\u5e76\u62d6\u62fd\u4ee5\u6539\u53d8\u5c3a\u5bf8\">\u200b<\/span><\/span><\/p>\n<p>\u00a0 \u00a0 \u00a0 \u4f7f\u7528icacls\u5206\u522b\u68c0\u67e5\u8fd9\u4e9b\u8def\u5f84\u7684\u8bbf\u95ee\u6743\u9650&#xff0c;\u4ece\u524d\u4e24\u4e2a\u8def\u5f84\u5f00\u59cb&#xff1a;<\/p>\n<p><span><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"618\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020935-6987f05f82dc4.png\" width=\"1062\" \/><span title=\"\u70b9\u51fb\u5e76\u62d6\u62fd\u4ee5\u6539\u53d8\u5c3a\u5bf8\">\u200b<\/span><\/span><\/p>\n<p>\u6743\u9650\u68c0\u67e5&#xff1a;\u7528\u6237\u00a0steve&#xff08;\u5c5e\u4e8e\u00a0BUILTIN\\\\Users\u3001NT AUTHORITY\\\\AUTHENTICATED Users\u7ec4&#xff09;\u65e0\u5199\u5165&#xff08;W&#xff09;\u6743\u9650\u3002\u63a5\u4e0b\u6765&#xff0c;\u5f00\u59cb\u68c0\u67e5\u7b2c\u4e09\u4e2a\u9009\u9879\u7684\u8def\u5f84&#xff08;C:\\\\Program Files\\\\Enterprise Apps&#xff09;&#xff1a;<\/p>\n<p><span><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"318\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020935-6987f05fcacdc.png\" width=\"1062\" \/><span title=\"\u70b9\u51fb\u5e76\u62d6\u62fd\u4ee5\u6539\u53d8\u5c3a\u5bf8\">\u200b<\/span><\/span>\u6743\u9650\u68c0\u67e5&#xff1a;\u7528\u6237\u00a0steve \u5bf9\u8be5\u8def\u5f84\u62e5\u6709\u5199\u5165&#xff08;W&#xff09;\u6743\u9650&#xff01;<\/p>\n<p>\u7b2c\u56db\u4e2a\u8def\u5f84\u4e0d\u7528\u68c0\u67e5&#xff0c;\u56e0\u4e3a\u5b83\u4ee3\u8868\u4e86\u670d\u52a1\u4e8c\u8fdb\u5236\u6587\u4ef6\u672c\u8eab\u3002<\/p>\n<p>\u653b\u51fb\u90e8\u7f72&#xff1a;<\/p>\n<ul>\n<li>\u5c06\u6076\u610f\u53ef\u6267\u884c\u6587\u4ef6\u547d\u540d\u4e3a\u00a0Current.exe<\/li>\n<li>\u653e\u7f6e\u4e8e\u5177\u6709\u5199\u5165\u6743\u9650\u7684\u76ee\u5f55&#xff1a;C:\\\\Program Files\\\\Enterprise Apps\\\\<\/li>\n<li>\u5f53\u670d\u52a1\u542f\u52a8\u65f6&#xff0c;\u7cfb\u7edf\u4f1a\u4f18\u5148\u6267\u884c\u6b64\u6076\u610f\u6587\u4ef6&#xff08;\u56e0\u8def\u5f84\u89e3\u6790\u987a\u5e8f&#xff09;&#xff0c;\u4ece\u800c\u89e6\u53d1\u6743\u9650\u63d0\u5347\u3002<\/li>\n<\/ul>\n<hr \/>\n<h5 id=\"1.1.2.3%C2%A0%E6%9E%84%E5%BB%BA%E4%B8%8E%E9%83%A8%E7%BD%B2%E6%81%B6%E6%84%8F%E7%A8%8B%E5%BA%8F\">1.1.2.3\u00a0\u6784\u5efa\u4e0e\u90e8\u7f72\u6076\u610f\u7a0b\u5e8f<\/h5>\n<p>\u00a0 \u00a0 \u00a0 \u6211\u4eec\u53ef\u901a\u8fc7\u524d\u6587\u4e2d\u7f16\u8bd1\u201c\u670d\u52a1\u4e8c\u8fdb\u5236\u52ab\u6301\u201d\u90e8\u5206\u7684C\u4ee3\u7801\u7f16\u8bd1\u7684adduser.exe\u6587\u4ef6\u4f5c\u4e3a\u6076\u610f\u7a0b\u5e8f\u3002<\/p>\n<p>\u7b80\u8981\u56de\u987e\u4e0b&#xff0c;adduser.c\u6e90\u4ee3\u7801&#xff1a;<\/p>\n<p><span><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"229\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020936-6987f06006833.png\" width=\"830\" \/><span title=\"\u70b9\u51fb\u5e76\u62d6\u62fd\u4ee5\u6539\u53d8\u5c3a\u5bf8\">\u200b<\/span><\/span><\/p>\n<p>\u7f16\u8bd1\u540e\u53d8\u6210adduser.exe&#xff1a;<\/p>\n<p><span><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"30\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020936-6987f06027f7e.png\" width=\"831\" \/><span title=\"\u70b9\u51fb\u5e76\u62d6\u62fd\u4ee5\u6539\u53d8\u5c3a\u5bf8\">\u200b<\/span><\/span><\/p>\n<p>\u5728Kali\u4e0a&#xff0c;\u5728\u53ef\u6267\u884c\u6587\u4ef6\u7684\u76ee\u5f55\u4e2d\u542f\u52a8Python3 Web\u670d\u52a1\u5668\u4ee5\u4fbf\u63d0\u4f9b\u5b83\u3002<\/p>\n<p>\u8be6\u7ec6\u6b65\u9aa4\u5982\u4e0b&#xff1a;<\/p>\n<p>\u2460\u67b6\u8bbe\u4f20\u8f93\u670d\u52a1\u5668<\/p>\n<ul>\n<li>\n<p>\u5728Kali\u653b\u51fb\u673a\u4e0a\u542f\u52a8\u00a0Python3 HTTP\u670d\u52a1\u5668&#xff0c;\u4e3a\u6076\u610f\u7a0b\u5e8f\u63d0\u4f9b\u4e0b\u8f7d\u3002<\/p>\n<\/li>\n<\/ul>\n<p>\u2461\u4e0b\u8f7d\u81f3\u76ee\u6807\u673a<\/p>\n<ul>\n<li>\n<p>\u5728\u76ee\u6807Windows\u673a\u5668\u4e0a&#xff0c;\u4ee5steve\u7528\u6237\u8eab\u4efd\u4f7f\u7528\u7c7b\u4f3c\u4ee5\u4e0b\u547d\u4ee4\u4e0b\u8f7d\u6587\u4ef6&#xff0c;\u5e76\u76f4\u63a5\u4fdd\u5b58\u4e3a\u653b\u51fb\u6240\u9700\u7684\u540d\u79f0\u00a0Current.exe&#xff1a;<\/p>\n<\/li>\n<\/ul>\n<p>\u2462\u653e\u7f6e\u5230\u6f0f\u6d1e\u8def\u5f84<\/p>\n<ul>\n<li>\n<p>\u5c06Current.exe\u590d\u5236\u5230\u5df2\u786e\u8ba4\u5177\u6709\u5199\u5165\u6743\u9650\u7684\u76ee\u5f55&#xff1a;C:\\\\Program Files\\\\Enterprise Apps\\\\\u3002<\/p>\n<\/li>\n<\/ul>\n<p><span><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"69\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020936-6987f060366d4.png\" width=\"831\" \/><span title=\"\u70b9\u51fb\u5e76\u62d6\u62fd\u4ee5\u6539\u53d8\u5c3a\u5bf8\">\u200b<\/span><\/span><\/p>\n<p>\u81f3\u6b64&#xff0c;\u5f53\u76ee\u6807\u670d\u52a1\u91cd\u542f\u65f6&#xff0c;\u7cfb\u7edf\u5c06\u4f18\u5148\u6267\u884c\u6076\u610fCurrent.exe&#xff0c;\u4ece\u800c\u5b8c\u6210\u6743\u9650\u63d0\u5347\u653b\u51fb\u3002<\/p>\n<\/p>\n<hr \/>\n<h5 id=\"1.1.2.4%C2%A0%E6%9C%8D%E5%8A%A1%E5%90%AF%E5%8A%A8%E4%B8%8E%E6%94%BB%E5%87%BB%E9%AA%8C%E8%AF%81\">1.1.2.4\u00a0\u670d\u52a1\u542f\u52a8\u4e0e\u653b\u51fb\u9a8c\u8bc1<\/h5>\n<p>\u542f\u52a8\u670d\u52a1\u89e6\u53d1\u653b\u51fb&#xff1a;<\/p>\n<ul>\n<li>\n<p>\u4f7f\u7528\u547d\u4ee4\u542f\u52a8\u76ee\u6807\u670d\u52a1&#xff1a;<\/p>\n<p>   &gt; Start-Service GammaService\n   <\/li>\n<li>\n<p>\u7cfb\u7edf\u6309\u89e3\u6790\u987a\u5e8f\u4f18\u5148\u6267\u884c\u6076\u610f\u7a0b\u5e8f\u00a0C:\\\\Program Files\\\\Enterprise Apps\\\\Current.exe&#xff0c;\u5e76\u5c06\u5269\u4f59\u8def\u5f84\u90e8\u5206\u00a0Version\\\\GammaServ.exe\u00a0\u4f5c\u4e3a\u53c2\u6570\u4f20\u9012\u3002<\/p>\n<\/li>\n<li>\n<p>\u518d\u6b21\u5f3a\u8c03&#xff1a;\u4e00\u65e6\u670d\u52a1\u542f\u52a8&#xff0c;\u6211\u4eec\u7684\u6587\u4ef6Current.exe\u5c06\u4ee5\u4e0e\u670d\u52a1\u542f\u52a8\u76f8\u540c\u7684\u6743\u9650\u6267\u884c\u3002\u901a\u5e38&#xff0c;\u4ee5LocalSystem\u670d\u52a1\u8d26\u6237\u6743\u9650\u6765\u6267\u884cCurrent.exe\u3002<\/p>\n<\/li>\n<\/ul>\n<p><span><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"822\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020936-6987f06045b2f.png\" width=\"1056\" \/><span title=\"\u70b9\u51fb\u5e76\u62d6\u62fd\u4ee5\u6539\u53d8\u5c3a\u5bf8\">\u200b<\/span><\/span><\/p>\n<p>\u7ed3\u679c\u5206\u6790&#xff1a;<\/p>\n<ul>\n<li>\n<p>\u670d\u52a1\u542f\u52a8\u62a5\u9519<\/p>\n<p>\u7531\u4e8e\u6076\u610f\u7a0b\u5e8f\u00a0Current.exe\u00a0\u65e0\u6cd5\u6b63\u786e\u5904\u7406\u539f\u59cb\u670d\u52a1\u7684\u53c2\u6570&#xff1a;Version\\\\GammaServ.exe\u662f\u5269\u4f59\u53c2\u6570\u3002\u8fd9\u4e2a\u9519\u8bef\u6e90\u4e8e\u4ea4\u53c9\u7f16\u8bd1\u7684C\u4ee3\u7801\u4e0d\u63a5\u53d7\u539f\u59cb\u670d\u52a1\u4e8c\u8fdb\u5236\u8def\u5f84\u7684\u5269\u4f59\u53c2\u6570&#xff0c;\u5bfc\u81f4Windows\u62a5\u544a\u670d\u52a1\u542f\u52a8\u5931\u8d25\u3002<\/p>\n<\/li>\n<li>\n<p>\u653b\u51fb\u6210\u529f\u6267\u884c<\/p>\n<p>\u5c3d\u7ba1\u670d\u52a1\u72b6\u6001\u5f02\u5e38&#xff0c;\u4f46\u6076\u610f\u7a0b\u5e8f\u5df2\u4ee5LocalSystem\u6743\u9650\u5b8c\u6210\u6267\u884c&#xff0c;\u6210\u529f\u521b\u5efa\u4e86\u7ba1\u7406\u5458\u8d26\u6237\u00a0dave2&#xff0c;\u5e76\u52a0\u5165\u4e86\u7ba1\u7406\u5458\u7ec4administrators&#xff0c;\u5b9e\u73b0\u63d0\u6743&#xff01;&#xff01;&#xff01;<\/p>\n<\/li>\n<\/ul>\n<hr \/>\n<h4 id=\"1.1.3%C2%A0%E4%BD%BF%E7%94%A8%E8%87%AA%E5%8A%A8%E5%8C%96%E5%B7%A5%E5%85%B7PowerUp.ps1%E5%88%A9%E7%94%A8%E6%BC%8F%E6%B4%9E\">1.1.3\u00a0\u4f7f\u7528\u81ea\u52a8\u5316\u5de5\u5177PowerUp.ps1\u5229\u7528\u6f0f\u6d1e<\/h4>\n<p>\u00a0 \u00a0 \u00a0 \u4ee5\u4e0a\u662f\u624b\u52a8\u5229\u7528\u7684\u65b9\u5f0f\u3002\u63a5\u4e0b\u6765&#xff0c;\u5c1d\u8bd5\u4f7f\u7528\u81ea\u52a8\u5316\u5de5\u5177PowerUp.ps1\u8bc6\u522b\u672a\u52a0\u5f15\u53f7\u670d\u52a1\u542f\u52a8\u8def\u5f84\u6f0f\u6d1e\u5b9e\u73b0\u63d0\u53d6\u3002<\/p>\n<h5 id=\"1.1.3.1%20%E6%81%A2%E5%A4%8D%E5%8E%9F%E5%A7%8B%E6%9C%8D%E5%8A%A1%E5%8A%9F%E8%83%BD\">1.1.3.1 \u6062\u590d\u539f\u59cb\u670d\u52a1\u529f\u80fd<\/h5>\n<p>\u6062\u590d\u6b65\u9aa4&#xff1a;<\/p>\n<ul>\n<li>\n<p>\u505c\u6b62\u670d\u52a1&#xff1a;\u4f7f\u7528\u00a0Stop-Service\u00a0\u547d\u4ee4\u505c\u6b62\u76ee\u6807\u670d\u52a1\u3002<\/p>\n<\/li>\n<li>\n<p>\u5220\u9664\u6076\u610f\u6587\u4ef6&#xff1a;\u79fb\u9664\u653e\u7f6e\u5728\u6f0f\u6d1e\u8def\u5f84\u4e0b\u7684\u6076\u610f\u7a0b\u5e8f\u00a0Current.exe\u3002<\/p>\n<\/li>\n<li>\n<p>\u670d\u52a1\u6062\u590d&#xff1a;\u6b64\u540e\u542f\u52a8\u670d\u52a1\u65f6&#xff0c;\u7cfb\u7edf\u5c06\u91cd\u65b0\u6b63\u5e38\u6267\u884c\u539f\u59cb\u670d\u52a1\u4e8c\u8fdb\u5236\u6587\u4ef6\u00a0GammaServ.exe&#xff0c;\u6062\u590d\u539f\u6709\u529f\u80fd\u3002<\/p>\n<\/li>\n<\/ul>\n<hr \/>\n<h5 id=\"1.1.3.2%20%E4%BD%BF%E7%94%A8%E8%87%AA%E5%8A%A8%E5%8C%96%E5%B7%A5%E5%85%B7%20PowerUp.ps1%20%E8%AF%86%E5%88%AB%E4%B8%8E%E5%88%A9%E7%94%A8%E6%BC%8F%E6%B4%9E\">1.1.3.2 \u4f7f\u7528\u81ea\u52a8\u5316\u5de5\u5177 PowerUp.ps1 \u8bc6\u522b\u4e0e\u5229\u7528\u6f0f\u6d1e<\/h5>\n<p>\u5229\u7528\u6b65\u9aa4&#xff1a;<\/p>\n<li>\n<p>\u4e0b\u8f7d\u5e76\u5bfc\u5165\u00a0PowerUp.ps1 \u811a\u672c\u3002&#xff08;\u4f7f\u7528iwr\u4e0b\u8f7dPowerUp.ps1&#xff0c;\u5c06\u5176\u5bfc\u5165\u5230PowerShell\u4f1a\u8bdd\u4e2d\u3002\u7136\u540e&#xff0c;\u5c06ExecutionPolicy\u8bbe\u7f6e\u4e3aBypass&#xff0c;\u6267\u884c\u8be5\u5de5\u5177\u3002&#xff09; <span><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"168\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020936-6987f060a1b95.png\" width=\"1055\" \/><span title=\"\u70b9\u51fb\u5e76\u62d6\u62fd\u4ee5\u6539\u53d8\u5c3a\u5bf8\">\u200b<\/span><\/span><\/p>\n<\/li>\n<li>\n<p>\u68c0\u6d4b\u6f0f\u6d1e&#xff1a;\u8fd0\u884c\u00a0Get-UnquotedService\u00a0\u547d\u4ee4&#xff0c;\u81ea\u52a8\u8bc6\u522b\u7cfb\u7edf\u4e2d\u5b58\u5728\u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u7684\u670d\u52a1&#xff08;\u5982 GammaService&#xff09;\u3002 <span><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"459\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020936-6987f060bf915.png\" width=\"1056\" \/><span title=\"\u70b9\u51fb\u5e76\u62d6\u62fd\u4ee5\u6539\u53d8\u5c3a\u5bf8\">\u200b<\/span><\/span><\/p>\n<\/li>\n<li>\n<p>\u81ea\u52a8\u5316\u5229\u7528&#xff1a;\u4f7f\u7528\u00a0Write-ServiceBinary\u00a0\u547d\u4ee4\u81ea\u52a8\u521b\u5efa\u5e76\u653e\u7f6e\u6076\u610f\u4e8c\u8fdb\u5236\u6587\u4ef6\u5230\u76f8\u5e94\u76ee\u5f55&#xff0c;\u9ed8\u8ba4\u6dfb\u52a0\u672c\u5730\u7ba1\u7406\u5458\u7528\u6237&#xff08;\u5982 john&#xff09;\u3002\u7136\u540e\u91cd\u542f\u670d\u52a1GammaService&#xff0c;\u5b8c\u6210\u6743\u9650\u63d0\u5347\u3002<\/p>\n<p>   &gt; Write-ServiceBinary -Name <span class=\"hljs-string\">&#039;GammaService&#039;<\/span> -Path <span class=\"hljs-string\">&#034;C:\\\\Program Files\\\\Enterprise Apps\\\\Current.exe&#034;<\/span> <\/p>\n<p><span><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"486\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020937-6987f06107208.png\" width=\"1053\" \/><span title=\"\u70b9\u51fb\u5e76\u62d6\u62fd\u4ee5\u6539\u53d8\u5c3a\u5bf8\">\u200b<\/span><\/span><\/p>\n<\/li>\n<li>\n<p>\u9a8c\u8bc1\u653b\u51fb\u7ed3\u679c&#xff1a;PowerUp.ps1\u81ea\u52a8\u5316\u5de5\u5177\u7684\u9ed8\u8ba4\u884c\u4e3a\u662f\u521b\u5efa\u540d\u4e3ajohn\u7684\u65b0\u672c\u5730\u7528\u6237&#xff0c;\u5bc6\u7801\u4e3aPassword123&#xff01;\u3002\u6b64\u5916&#xff0c;\u8be5\u7528\u6237\u88ab\u6dfb\u52a0\u5230\u672c\u5730Administrators\u7ec4\u3002 <span><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"340\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020937-6987f0614a294.png\" width=\"831\" \/><span title=\"\u70b9\u51fb\u5e76\u62d6\u62fd\u4ee5\u6539\u53d8\u5c3a\u5bf8\">\u200b<\/span><\/span><\/p>\n<\/li>\n<hr \/>\n<h4 id=\"1.1.4%20%E6%9C%AA%E5%8A%A0%E5%BC%95%E5%8F%B7%E6%9C%8D%E5%8A%A1%E8%B7%AF%E5%BE%84%E6%BC%8F%E6%B4%9E%E5%88%A9%E7%94%A8%E5%85%A8%E6%B5%81%E7%A8%8B%E6%80%BB%E7%BB%93\">1.1.4 \u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u5229\u7528\u5168\u6d41\u7a0b\u603b\u7ed3<\/h4>\n<p>1. \u6f0f\u6d1e\u8bc6\u522b<\/p>\n<ul>\n<li>\n<p>\u53d1\u73b0\u670d\u52a1\u53ef\u6267\u884c\u6587\u4ef6\u7684\u00a0\u8def\u5f84\u5305\u542b\u7a7a\u683c\u4e14\u672a\u7528\u5f15\u53f7\u5305\u88f9\u3002<\/p>\n<\/li>\n<li>\n<p>\u7406\u89e3 Windows \u4f1a\u6309\u7a7a\u683c\u5206\u6bb5\u3001\u4ece\u5de6\u81f3\u53f3\u5c1d\u8bd5\u6267\u884c\u7684\u89e3\u6790\u903b\u8f91\u3002<\/p>\n<\/li>\n<\/ul>\n<p>2. \u6761\u4ef6\u5206\u6790\u4e0e\u51c6\u5907<\/p>\n<ul>\n<li>\n<p>\u68c0\u67e5\u8def\u5f84\u4e2d\u5404\u524d\u7f6e\u76ee\u5f55\u7684\u5199\u5165\u6743\u9650&#xff0c;\u627e\u5230\u53ef\u653e\u7f6e\u6076\u610f\u6587\u4ef6\u7684\u4f4d\u7f6e\u3002<\/p>\n<\/li>\n<li>\n<p>\u786e\u8ba4\u5f53\u524d\u7528\u6237\u5177\u6709\u91cd\u542f\u76ee\u6807\u670d\u52a1\u7684\u6743\u9650\u3002<\/p>\n<\/li>\n<\/ul>\n<p>3. \u653b\u51fb\u5b9e\u65bd<\/p>\n<ul>\n<li>\n<p>\u5c06\u6076\u610f\u53ef\u6267\u884c\u6587\u4ef6\u547d\u540d\u5e76\u653e\u7f6e\u5230\u6743\u9650\u5141\u8bb8\u7684\u5bf9\u5e94\u76ee\u5f55\u4e2d\u3002<\/p>\n<\/li>\n<li>\n<p>\u91cd\u542f\u670d\u52a1&#xff0c;\u89e6\u53d1\u6076\u610f\u7a0b\u5e8f\u4ee5\u00a0LocalSystem\u00a0\u7b49\u9ad8\u6743\u9650\u8eab\u4efd\u6267\u884c\u3002<\/p>\n<\/li>\n<\/ul>\n<p>4. \u81ea\u52a8\u5316\u5229\u7528&#xff08;PowerUp.ps1&#xff09;<\/p>\n<ul>\n<li>\n<p>Get-UnquotedService&#xff1a;\u81ea\u52a8\u626b\u63cf\u5e76\u5217\u51fa\u5b58\u5728\u6f0f\u6d1e\u7684\u670d\u52a1\u3002<\/p>\n<\/li>\n<li>\n<p>Write-ServiceBinary&#xff1a;\u81ea\u52a8\u751f\u6210\u5e76\u90e8\u7f72\u6076\u610f\u7a0b\u5e8f&#xff0c;\u5b8c\u6210\u6743\u9650\u63d0\u5347\u3002<\/p>\n<\/li>\n<\/ul>\n<p>5. \u6062\u590d\u4e0e\u6e05\u7406<\/p>\n<ul>\n<li>\n<p>\u505c\u6b62\u670d\u52a1\u3001\u5220\u9664\u6076\u610f\u6587\u4ef6&#xff0c;\u5373\u53ef\u6062\u590d\u670d\u52a1\u7684\u539f\u59cb\u529f\u80fd\u3002<\/p>\n<\/li>\n<\/ul>\n<p>\u6838\u5fc3\u8981\u70b9&#xff1a;\u8be5\u6f0f\u6d1e\u5229\u7528\u4f9d\u8d56\u4e8e\u00a0\u8def\u5f84\u89e3\u6790\u7f3a\u9677\u00a0\u4e0e\u00a0\u4e0d\u5f53\u7684\u76ee\u5f55\u6743\u9650\u914d\u7f6e\u00a0\u5171\u540c\u4f5c\u7528&#xff0c;\u901a\u8fc7\u201c\u8def\u5f84\u52ab\u6301\u201d\u5b9e\u73b0\u6743\u9650\u63d0\u5347\u3002<\/p>\n<hr \/>\n<h2 id=\"%E6%AC%A2%E8%BF%8E%E2%9D%A4%EF%B8%8F%20%E7%82%B9%E8%B5%9E%20%7C%20%F0%9F%94%94%20%E5%85%B3%E6%B3%A8%20%7C%20%E2%AD%90%EF%B8%8F%20%E6%94%B6%E8%97%8F%20%7C%20%F0%9F%92%AC%20%E8%AF%84%E8%AE%BA\" style=\"background-color:transparent\">\u6b22\u8fce\u2764\ufe0f \u70b9\u8d5e | &#x1f514; \u5173\u6ce8 | \u2b50\ufe0f \u6536\u85cf | &#x1f4ac; \u8bc4\u8bba<\/h2>\n<p>\u6bcf\u4e00\u4efd\u652f\u6301&#xff0c;\u90fd\u662f\u6211\u6301\u7eed\u8f93\u51fa\u7684\u5149\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"1050\" src=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020937-6987f06168010.png\" width=\"1644\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u90d1\u91cd\u58f0\u660e&#xff1a;\u672c\u6587\u6240\u6d89\u5b89\u5168\u6280\u672f\u4ec5\u9650\u7528\u4e8e\u5408\u6cd5\u7814\u7a76\u4e0e\u5b66\u4e60\u76ee\u7684&#xff0c;\u4e25\u7981\u4efb\u4f55\u5f62\u5f0f\u7684\u975e\u6cd5\u5229\u7528\u3002\u56e0\u4e0d\u5f53\u4f7f\u7528\u6240\u5bfc\u81f4\u7684\u4e00\u5207\u6cd5\u5f8b\u4e0e\u7ecf\u6d4e\u8d23\u4efb&#xff0c;\u672c\u4eba\u6982\u4e0d\u8d1f\u8d23\u3002\u4efb\u4f55\u5f62\u5f0f\u7684\u8f6c\u8f7d\u5747\u987b\u660e\u786e\u6807\u6ce8\u539f\u6587\u51fa\u5904&#xff0c;\u4e14\u4e0d\u5f97\u7528\u4e8e\u5546\u4e1a\u76ee\u7684\u3002 &#x1f50b; \u70b9\u8d5e | \u80fd\u91cf\u6ce8\u5165 \u2764\ufe0f\u00a0\u5173\u6ce8 | \u4fe1\u53f7\u9501\u5b9a &#x1f514;\u00a0\u6536\u85cf | \u6570\u636e\u5f52\u6863\u00a0\u2b50\ufe0f\u00a0\u8bc4\u8bba | \u4fdd\u6301\u8fde\u63a5&#x1f4ac; &#x1f30c;\u00a0\u7acb\u5373\u524d\u5f80\u00a0&#x1f449;\u6656\u5ea6\u4e28\u5b89\u5168\u89c6\u754c&#x1f680;\u200b \u200b<\/p>\n","protected":false},"author":2,"featured_media":73730,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[7762,7763,1870,122],"topic":[],"class_list":["post-73747","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-server","tag-windows","tag-7763","tag-1870","tag-122"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u24eb\u2044\u2081\u2082 \u27e6 OSCP \u2b16 \u7814\u8bb0 \u27e7 Windows\u6743\u9650\u63d0\u5347 \u27b1 \u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u5229\u7528\uff08\u4e0b\uff09 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.wsisp.com\/helps\/73747.html\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u24eb\u2044\u2081\u2082 \u27e6 OSCP \u2b16 \u7814\u8bb0 \u27e7 Windows\u6743\u9650\u63d0\u5347 \u27b1 \u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u5229\u7528\uff08\u4e0b\uff09 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"og:description\" content=\"\u90d1\u91cd\u58f0\u660e&#xff1a;\u672c\u6587\u6240\u6d89\u5b89\u5168\u6280\u672f\u4ec5\u9650\u7528\u4e8e\u5408\u6cd5\u7814\u7a76\u4e0e\u5b66\u4e60\u76ee\u7684&#xff0c;\u4e25\u7981\u4efb\u4f55\u5f62\u5f0f\u7684\u975e\u6cd5\u5229\u7528\u3002\u56e0\u4e0d\u5f53\u4f7f\u7528\u6240\u5bfc\u81f4\u7684\u4e00\u5207\u6cd5\u5f8b\u4e0e\u7ecf\u6d4e\u8d23\u4efb&#xff0c;\u672c\u4eba\u6982\u4e0d\u8d1f\u8d23\u3002\u4efb\u4f55\u5f62\u5f0f\u7684\u8f6c\u8f7d\u5747\u987b\u660e\u786e\u6807\u6ce8\u539f\u6587\u51fa\u5904&#xff0c;\u4e14\u4e0d\u5f97\u7528\u4e8e\u5546\u4e1a\u76ee\u7684\u3002 &#x1f50b; \u70b9\u8d5e | \u80fd\u91cf\u6ce8\u5165 \u2764\ufe0f\u00a0\u5173\u6ce8 | \u4fe1\u53f7\u9501\u5b9a &#x1f514;\u00a0\u6536\u85cf | \u6570\u636e\u5f52\u6863\u00a0\u2b50\ufe0f\u00a0\u8bc4\u8bba | \u4fdd\u6301\u8fde\u63a5&#x1f4ac; &#x1f30c;\u00a0\u7acb\u5373\u524d\u5f80\u00a0&#x1f449;\u6656\u5ea6\u4e28\u5b89\u5168\u89c6\u754c&#x1f680;\u200b \u200b\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.wsisp.com\/helps\/73747.html\" \/>\n<meta property=\"og:site_name\" content=\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"article:published_time\" content=\"2026-02-08T02:09:40+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020934-6987f05ebfcdf.png\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/73747.html\",\"url\":\"https:\/\/www.wsisp.com\/helps\/73747.html\",\"name\":\"\u24eb\u2044\u2081\u2082 \u27e6 OSCP \u2b16 \u7814\u8bb0 \u27e7 Windows\u6743\u9650\u63d0\u5347 \u27b1 \u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u5229\u7528\uff08\u4e0b\uff09 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"isPartOf\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\"},\"datePublished\":\"2026-02-08T02:09:40+00:00\",\"dateModified\":\"2026-02-08T02:09:40+00:00\",\"author\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/73747.html#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.wsisp.com\/helps\/73747.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/73747.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.wsisp.com\/helps\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u24eb\u2044\u2081\u2082 \u27e6 OSCP \u2b16 \u7814\u8bb0 \u27e7 Windows\u6743\u9650\u63d0\u5347 \u27b1 \u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u5229\u7528\uff08\u4e0b\uff09\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\",\"url\":\"https:\/\/www.wsisp.com\/helps\/\",\"name\":\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"description\":\"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"contentUrl\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"caption\":\"admin\"},\"sameAs\":[\"http:\/\/wp.wsisp.com\"],\"url\":\"https:\/\/www.wsisp.com\/helps\/author\/admin\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\u24eb\u2044\u2081\u2082 \u27e6 OSCP \u2b16 \u7814\u8bb0 \u27e7 Windows\u6743\u9650\u63d0\u5347 \u27b1 \u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u5229\u7528\uff08\u4e0b\uff09 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.wsisp.com\/helps\/73747.html","og_locale":"zh_CN","og_type":"article","og_title":"\u24eb\u2044\u2081\u2082 \u27e6 OSCP \u2b16 \u7814\u8bb0 \u27e7 Windows\u6743\u9650\u63d0\u5347 \u27b1 \u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u5229\u7528\uff08\u4e0b\uff09 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","og_description":"\u90d1\u91cd\u58f0\u660e&#xff1a;\u672c\u6587\u6240\u6d89\u5b89\u5168\u6280\u672f\u4ec5\u9650\u7528\u4e8e\u5408\u6cd5\u7814\u7a76\u4e0e\u5b66\u4e60\u76ee\u7684&#xff0c;\u4e25\u7981\u4efb\u4f55\u5f62\u5f0f\u7684\u975e\u6cd5\u5229\u7528\u3002\u56e0\u4e0d\u5f53\u4f7f\u7528\u6240\u5bfc\u81f4\u7684\u4e00\u5207\u6cd5\u5f8b\u4e0e\u7ecf\u6d4e\u8d23\u4efb&#xff0c;\u672c\u4eba\u6982\u4e0d\u8d1f\u8d23\u3002\u4efb\u4f55\u5f62\u5f0f\u7684\u8f6c\u8f7d\u5747\u987b\u660e\u786e\u6807\u6ce8\u539f\u6587\u51fa\u5904&#xff0c;\u4e14\u4e0d\u5f97\u7528\u4e8e\u5546\u4e1a\u76ee\u7684\u3002 &#x1f50b; \u70b9\u8d5e | \u80fd\u91cf\u6ce8\u5165 \u2764\ufe0f\u00a0\u5173\u6ce8 | \u4fe1\u53f7\u9501\u5b9a &#x1f514;\u00a0\u6536\u85cf | \u6570\u636e\u5f52\u6863\u00a0\u2b50\ufe0f\u00a0\u8bc4\u8bba | \u4fdd\u6301\u8fde\u63a5&#x1f4ac; &#x1f30c;\u00a0\u7acb\u5373\u524d\u5f80\u00a0&#x1f449;\u6656\u5ea6\u4e28\u5b89\u5168\u89c6\u754c&#x1f680;\u200b \u200b","og_url":"https:\/\/www.wsisp.com\/helps\/73747.html","og_site_name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","article_published_time":"2026-02-08T02:09:40+00:00","og_image":[{"url":"https:\/\/www.wsisp.com\/helps\/wp-content\/uploads\/2026\/02\/20260208020934-6987f05ebfcdf.png"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"admin","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"2 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.wsisp.com\/helps\/73747.html","url":"https:\/\/www.wsisp.com\/helps\/73747.html","name":"\u24eb\u2044\u2081\u2082 \u27e6 OSCP \u2b16 \u7814\u8bb0 \u27e7 Windows\u6743\u9650\u63d0\u5347 \u27b1 \u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u5229\u7528\uff08\u4e0b\uff09 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","isPartOf":{"@id":"https:\/\/www.wsisp.com\/helps\/#website"},"datePublished":"2026-02-08T02:09:40+00:00","dateModified":"2026-02-08T02:09:40+00:00","author":{"@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41"},"breadcrumb":{"@id":"https:\/\/www.wsisp.com\/helps\/73747.html#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.wsisp.com\/helps\/73747.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.wsisp.com\/helps\/73747.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.wsisp.com\/helps"},{"@type":"ListItem","position":2,"name":"\u24eb\u2044\u2081\u2082 \u27e6 OSCP \u2b16 \u7814\u8bb0 \u27e7 Windows\u6743\u9650\u63d0\u5347 \u27b1 \u672a\u52a0\u5f15\u53f7\u670d\u52a1\u8def\u5f84\u6f0f\u6d1e\u5229\u7528\uff08\u4e0b\uff09"}]},{"@type":"WebSite","@id":"https:\/\/www.wsisp.com\/helps\/#website","url":"https:\/\/www.wsisp.com\/helps\/","name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","description":"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41","name":"admin","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/","url":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","contentUrl":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","caption":"admin"},"sameAs":["http:\/\/wp.wsisp.com"],"url":"https:\/\/www.wsisp.com\/helps\/author\/admin"}]}},"_links":{"self":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/73747","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/comments?post=73747"}],"version-history":[{"count":0,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/73747\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media\/73730"}],"wp:attachment":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media?parent=73747"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/categories?post=73747"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/tags?post=73747"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/topic?post=73747"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}