溯源

windows排查

系统日志

windows系统日志包含系统日志,安全日志、应用日志等
敏感事件id:
4624 登录成功
4625 登录失败
4720 创建用户
4634 注销成功
4647 用户启动的注销
4672 使用超级用户/管理员用户进行登录
比如说利用文件上传,上传了一句话木马,此时使用中国蚁剑连接。创建一个隐藏用户。
net user test$ 123456 /add
image-20241024194917534
image-20241024195124861
image-20241024195214919
image-20241024195307083
image-20241024200909240
image-20241024195500193
image-20241024195543869
image-20241024195645513
image-20241024195710007
image-20241024200130055
image-20241024200405300
image-20241024200501763
image-20241024200543574
image-20241024201447389
image-20241024201558107
image-20241024201716399
image-20241024201831928

web日志排查

image-20241024202910675
image-20241024202949585
image-20241024203105351
image-20241024204111317
image-20241024204249094
image-20241024204347704
image-20241024204801306
image-20241024204911896
image-20241024205007625
image-20241025002140553

Linux排查

web日志分析

image-20241025145807000
image-20241025150021811
image-20241025150125705
image-20241025150406858
image-20241025150542120
image-20241025150816130
image-20241025150933354

文件日志分析

image-20241025151416269
image-20241025151555973
image-20241025151733317
image-20241025151813753
image-20241025151907471
image-20241025152027724

系统日志分析

image-20241025152526007
image-20241025153114930
image-20241025153135935
image-20241025153555983
image-20241025153641276
image-20241025154052598
image-20241025154146033

进程分析

image-20241025154301319
image-20241025154738815
image-20241025155226342

溯源真实身份

攻击源的获取

image-20241025200330978

溯源的方法

image-20241025201458655
image-20241025202236482
image-20241025202248455
image-20241025202921066
image-20241025203430661

利用AntSword RCE进行溯源反制黑客

image-20241025205811352
image-20241025210252197
image-20241025210450187
image-20241025210526138
image-20241025230336501
image-20241025230614389
image-20241025230738821
image-20241025230806634
image-20241025230856049
image-20241025231141900
image-20241025231205944
image-20241025232014650
image-20241025232046411
image-20241025231719454
image-20241025232404943

利用GoBy RCE进行溯源反制

image-20241026003907058
image-20241026003932934
image-20241026004140130
image-20241026003807615
image-20241026004500493
image-20241026004602776
image-20241026004700059
image-20241026004735460

image-20241026005023603

image-20241026005051605
image-20241026005130481
image-20241026010726325
image-20241026010642511

如何防止被溯源

Last updated