×ðÁú¿­Ê±

֤ȯ¼ò³Æ£º×ðÁú¿­Ê± ֤ȯ´úÂ룺002212
È«Ììºò7x24Сʱ·þÎñ£º 400-777-0777

windowsÐÅÏ¢ÍøÂ繤¾ß

winlogÒ»¿î»ùÓÚgoµÄwindowsÐÅÏ¢ÍøÂ繤¾ß£¬Ö÷ÒªÍøÂçÄ¿µÄ×°±¸rdp¶Ë¿ÚµÇ¼¡¢mstscÔ¶³ÌÅþÁ¬¼Í¼¡¢mstscÃÜÂëºÍÇå¾²ÊÂÎñÖС£

windowsÐÅÏ¢ÍøÂ繤¾ß

Ðû²¼Ê±¼ä£º2022-08-16
ä¯ÀÀ´ÎÊý£º3276
·ÖÏí£º

ÏîÄ¿×÷Õߣºi11us0ry

ÏîÄ¿µØµã£ºhttps://github.com/i11us0ry/winlog

Ò»¡¢¹¤¾ßÏÈÈÝ

winlogÒ»¿î»ùÓÚgoµÄwindowsÐÅÏ¢ÍøÂ繤¾ß£¬Ö÷ÒªÍøÂçÄ¿µÄ×°±¸rdp¶Ë¿ÚµÇ¼¡¢mstscÔ¶³ÌÅþÁ¬¼Í¼¡¢mstscÃÜÂëºÍÇå¾²ÊÂÎñÖС£

¶þ¡¢×°ÖÃÓëʹÓÃ

1¡¢»ñÈ¡ÍâµØRDP¶Ë¿Ú£º

\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp

2¡¢»ñȡĿ½ñÓû§mstscÔ¶³ÌÅþÁ¬¼Í¼£¬°üÀ¨host¡¢port¡¢loginName

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Terminal Server Client\DefaultHKEY_CURRENT_USER\SOFTWARE\Microsoft\Terminal Server Client\Servers

3¡¢»ñȡĿ½ñ·þÎñÆ÷Çå¾²ÈÕÖ¾4624¡¢4625ÊÂÎñ

Advapi32.dll --> ReadEventLogW --> Security --> 4624¡¢4625

4¡¢×¥È¡ÃÜÂë

ÈôÊÇÓû§Ê¹ÓÃmstsc¾ÙÐÐÔ¶³ÌÅþÁ¬Ê±Ñ¡ÔñÁ˱£´æÆ¾Ö¤£¬Ôò¿ÉÒÔŲÓÃmimikatzץȡÓû§±£´æµÄÃÜÂë

5¡¢Ê¹ÓÃʱִÐÐexe£¬ÈôÊÇÐèÒª»ñÈ¡ÃÜÂëÐèÒªÒ»ÆðÉÏ´«mimikatz£¬²¢Ê¹ÓÃ-pÖ¸¶¨mimikatz£¬Â·¾¶ÈçÏ£º

Èý¡¢ÏÂÔØµØµã£º

ͨ¹ýÏîÄ¿µØµãÏÂÔØ

¿Í»§·þÎñÈÈÏß

400-777-0777
7*24Сʱ·þÎñ

ÁªÏµÓÊÏä

servicing@topsec.com.cn

ɨÂë¹Ø×¢
ÍøÕ¾µØÍ¼