发表评论
BlueChecker将帮助您审核powershell并检查任何可疑活动,如审核Powershell并从历史记录中的已知关键字中搜索#Blueteam蓝队,也可当做取证的一部分来使用。
只需下载脚本或使用以下命令远程运行:
powershell –nop –c “iex(New-Object Net.WebClient).DownloadString(‘https://raw.githubusercontent.com/securethelogs/Bluechecker/master/Bluechecker.ps1’)”
BlueChecker将检查:
Powershell status
Evidence of downgrading
Registry and GP set for PowerShell auditing
Malicious scripts using keywords
Event logs for Module logging and script block logging.