<?xml version="1.0" encoding="utf-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><title>小迪渗透吧-提供最专业的渗透测试培训,web安全培训,网络安全培训,代码审计培训,安全服务培训,CTF比赛培训,SRC平台挖掘培训,红蓝对抗培训！</title><link>http://xiaodi8.com/</link><description>小迪安全,小迪渗透,小迪培训</description><item><title>AWVS V23.7 Cracked破解版</title><link>http://xiaodi8.com/?id=327</link><description>&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; text-wrap: wrap; background-color: rgb(255, 255, 255);&quot;&gt;当前版本：&lt;br style=&quot;box-sizing: inherit;&quot;/&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;mark class=&quot;has-inline-color&quot; style=&quot;box-sizing: inherit; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; color: rgb(249, 6, 6);&quot;&gt;23.7.230728157&lt;/mark&gt;&lt;/span&gt;&lt;/p&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; text-wrap: wrap; background-color: rgb(255, 255, 255);&quot;&gt;&lt;mark class=&quot;has-inline-color&quot; style=&quot;box-sizing: inherit; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; color: rgb(250, 4, 4);&quot;&gt;&lt;img src=&quot;http://xiaodi8.com/zb_users/upload/2023/10/202310181697637768136275.png&quot; alt=&quot;image.png&quot;/&gt;&lt;/mark&gt;&lt;/h2&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; text-wrap: wrap; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E9%87%8D%E8%A6%81%E7%9A%84%E6%8F%90%E7%A4%BA&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;mark class=&quot;has-inline-color&quot; style=&quot;box-sizing: inherit; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; color: rgb(250, 4, 4);&quot;&gt;重要的提示&lt;/mark&gt;&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; text-wrap: wrap; background-color: rgb(255, 255, 255);&quot;&gt;请注意，从版本 23.6.230626159 开始，我们已&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;mark class=&quot;has-inline-color&quot; style=&quot;box-sizing: inherit; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; color: rgb(246, 4, 4);&quot;&gt;不再支持 Windows 8、Server 2012 和 Server 2012 R2&lt;/mark&gt;&lt;/span&gt;。&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; text-wrap: wrap; background-color: rgb(255, 255, 255);&quot;&gt;请将您的 Windows 操作系统更新到 Windows 10（或更高版本）或 Windows Server 2016（或更高版本）以使用此版本和即将发布的版本。&lt;/p&gt;&lt;pre class=&quot;prism-highlight prism-language-markup&quot;&gt;Awvs更新日志:

新功能
[封闭测试功能]&amp;nbsp;Acunetix&amp;nbsp;现在包括运行时&amp;nbsp;SCA，它可以识别扫描端点上使用的技术，并突出显示具有已知漏洞的技术。
[封闭测试功能]&amp;nbsp;Acunetix&amp;nbsp;Online&amp;nbsp;中的内部扫描代理（在封闭测试版中可用）现在可以启动多个并发扫描。

新的安全检查
检查是否可以在无需身份验证的情况下访问包含&amp;nbsp;PII&amp;nbsp;的&amp;nbsp;API&amp;nbsp;响应
Joomla&amp;nbsp;未经授权访问漏洞测试(&amp;nbsp;CVE-2023-23752&amp;nbsp;)
由于不区分大小写的路径处理，测试&amp;nbsp;Express&amp;nbsp;javascript&amp;nbsp;框架中的身份验证绕过
测试&amp;nbsp;Citrix&amp;nbsp;Gateway&amp;nbsp;XSS&amp;nbsp;(&amp;nbsp;CVE-2023-24488&amp;nbsp;)
在&amp;nbsp;WooCommerce&amp;nbsp;中测试身份验证绕过和权限升级&amp;nbsp;(&amp;nbsp;CVE-2023-28121&amp;nbsp;)
检测&amp;nbsp;Rails&amp;nbsp;是否在调试模式下运行
检测&amp;nbsp;Adobe&amp;nbsp;ColdFusion&amp;nbsp;远程代码执行的访问控制绕过（CVE-2023-29298、CVE-2023-29300）

改进
将&amp;nbsp;CWE&amp;nbsp;Top&amp;nbsp;25&amp;nbsp;报告更新至最新的&amp;nbsp;2023&amp;nbsp;年版本
.NET&amp;nbsp;IAST&amp;nbsp;AcuSensor&amp;nbsp;的改进允许收集更多信息
改进了&amp;nbsp;LSR&amp;nbsp;中对&amp;nbsp;Shadow&amp;nbsp;DOM&amp;nbsp;的支持
NGINX&amp;nbsp;Alias&amp;nbsp;遍历安全检查的改进
WordPress&amp;nbsp;漏洞检测的改进
代码执行安全检查的改进&lt;/pre&gt;&lt;p&gt;下载地址：&lt;a href=&quot;https://ddosi-my.sharepoint.com/:u:/g/personal/netsparker_ddosi_onmicrosoft_com/EfdiP09eZEhBgGX3RegsrAABA1-KO4O9F-nD_KjTKsy6tg?e=USm6GN&quot; _src=&quot;https://ddosi-my.sharepoint.com/:u:/g/personal/netsparker_ddosi_onmicrosoft_com/EfdiP09eZEhBgGX3RegsrAABA1-KO4O9F-nD_KjTKsy6tg?e=USm6GN&quot;&gt;https://ddosi-my.sharepoint.com/:u:/g/personal/netsparker_ddosi_onmicrosoft_com/EfdiP09eZEhBgGX3RegsrAABA1-KO4O9F-nD_KjTKsy6tg?e=USm6GN&lt;/a&gt; &lt;/p&gt;&lt;p&gt;&lt;span style=&quot;color: #008000; font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; text-wrap: wrap; background-color: #FFFFFF;&quot;&gt;解压密码:&lt;/span&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700; color: #008000; font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; text-wrap: wrap; background-color: #FFFFFF;&quot;&gt;&lt;mark class=&quot;has-inline-color&quot; style=&quot;box-sizing: inherit; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; color: rgb(250, 2, 2);&quot;&gt;&lt;a href=&quot;http://www.ddosi.org&quot; _src=&quot;http://www.ddosi.org&quot;&gt;www.ddosi.org&lt;/a&gt; &lt;/mark&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;font color=&quot;#008000&quot; face=&quot;Oxygen, arial, helvetica, sans-serif&quot;&gt;&lt;span style=&quot;font-size: 16px; background-color: #FFFFFF;&quot;&gt;&lt;b&gt;破解参考：https://www.ddosi.org/awvs-23-7/&lt;/b&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;</description><pubDate>Wed, 18 Oct 2023 22:00:40 +0800</pubDate></item><item><title>云安全-AK/SK泄露利用工具CloudSec </title><link>http://xiaodi8.com/?id=326</link><description>&lt;h1 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 2.25rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;云安全-AK/SK泄露利用工具&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h1&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;注意：部分代码中由于时间关系未做权限控制，存在越权，建议本地搭建使用即可&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;前端采用vue3,基于buildadmin模板，后端springboot，原接口调用厂商的SDK&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E5%85%B3%E4%BA%8E%E4%BD%BF%E7%94%A8%E7%9B%AE%E5%89%8D%E6%8E%A5%E5%85%A5%E4%BA%86%E8%85%BE%E8%AE%AF%E4%BA%91%E7%9A%84%E6%89%80%E4%BB%A5%E4%B8%8B%E8%BF%B0%E5%8A%9F%E8%83%BD%E6%8E%A5%E5%8F%A3%EF%BC%8C%E9%98%BF%E9%87%8C%E4%BA%91%E5%B7%B2%E6%9B%B4%E6%96%B0%E5%8A%A0%E5%85%A5%EF%BC%8C%E5%85%B6%E4%BD%99%E5%8E%82%E5%95%86%E9%9C%80%E8%A6%81%E6%85%A2%E6%85%A2%E8%A1%A5%E5%85%85&quot; ez-toc-data-id=&quot;#关于使用目前接入了腾讯云的所以下述功能接口，阿里云已更新加入，其余厂商需要慢慢补充&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/libaibaia/cloudSec/tree/main#%E5%85%B3%E4%BA%8E%E4%BD%BF%E7%94%A8%E7%9B%AE%E5%89%8D%E6%8E%A5%E5%85%A5%E4%BA%86%E8%85%BE%E8%AE%AF%E4%BA%91%E7%9A%84%E6%89%80%E4%BB%A5%E4%B8%8B%E8%BF%B0%E5%8A%9F%E8%83%BD%E6%8E%A5%E5%8F%A3%E9%98%BF%E9%87%8C%E4%BA%91%E5%B7%B2%E6%9B%B4%E6%96%B0%E5%8A%A0%E5%85%A5%E5%85%B6%E4%BD%99%E5%8E%82%E5%95%86%E9%9C%80%E8%A6%81%E6%85%A2%E6%85%A2%E8%A1%A5%E5%85%85&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;关于使用(目前接入了腾讯云的所以下述功能接口，阿里云已更新加入，其余厂商需要慢慢补充)&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;&lt;img src=&quot;http://xiaodi8.com/zb_users/upload/2023/06/202306121686578364151479.png&quot; alt=&quot;image.png&quot;/&gt;&lt;/p&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E5%85%B3%E4%BA%8E%E5%90%8E%E7%BB%AD%E6%B7%BB%E5%8A%A0%E7%9A%84%E5%8E%82%E5%95%86&quot; ez-toc-data-id=&quot;#关于后续添加的厂商&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/libaibaia/cloudSec/tree/main#%E5%85%B3%E4%BA%8E%E5%90%8E%E7%BB%AD%E6%B7%BB%E5%8A%A0%E7%9A%84%E5%8E%82%E5%95%86&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;关于后续添加的厂商&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;亚马逊云&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;七牛云(已接入)&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;华为云（已更新存储桶）&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;微软云&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;谷歌&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;因为缺少好多资源，某些功能不能直接测试，如果有相关资源可以提供的师傅可以发给我测试一下 以上是后续的更详细方向，有点多，可能一时半会更新不完&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;如果有BUG请提交issue或者联系我&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;wechat：IHoshi&lt;/span&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E7%9B%AE%E5%89%8D%E6%94%AF%E6%8C%81%E7%9A%84%E5%8E%82%E5%95%86&quot; ez-toc-data-id=&quot;#目前支持的厂商&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/libaibaia/cloudSec/tree/main#%E7%9B%AE%E5%89%8D%E6%94%AF%E6%8C%81%E7%9A%84%E5%8E%82%E5%95%86&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;目前支持的厂商&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;腾讯云&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;阿里云&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;七牛&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;华为云（当前仅存储桶支持）&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;注：如果页面白屏刷新浏览器即可，因为热更新的原因导致，后期会解决。（已解决）&lt;/span&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;本地部署&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;数据库mysql5.7&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;jdk8&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;node 16.16 前端项目地址：&lt;a href=&quot;https://github.com/libaibaia/web-vue&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://github.com/libaibaia/vue-web&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;步骤：&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ol style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;编译后端项目（将application中的mysql改为本地mysql地址） mnv package&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;前端项目打包,打包前更改.env.production文件中的VITE_AXIOS_BASE_URL为本机IP，然后，npm install –&amp;gt; npm run build&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;将编译后的dist文件复制到nginx目录下&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;启动后端java -jar cloudSec.jar&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;访问nginx80端口登录，默认账号密码admin/admin123。&lt;/p&gt;&lt;/li&gt;&lt;/ol&gt;&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;h-cloudsec下载地址&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;cloudSec%E4%B8%8B%E8%BD%BD%E5%9C%B0%E5%9D%80&quot; ez-toc-data-id=&quot;#cloudSec下载地址&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;cloudSec下载地址:&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;a href=&quot;https://github.com/libaibaia/cloudSec/releases/download/v1.1/cloudSec-0.0.1-SNAPSHOT.jar&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;cloudSec-0.0.1-SNAPSHOT.jar&lt;/a&gt;&lt;/p&gt;&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;h-项目地址&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E9%A1%B9%E7%9B%AE%E5%9C%B0%E5%9D%80&quot; ez-toc-data-id=&quot;#项目地址&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;项目地址:&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;GitHub:&lt;br style=&quot;box-sizing: inherit;&quot;/&gt;&lt;a href=&quot;https://github.com/libaibaia/cloudSec/tree/main&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://github.com/libaibaia/cloudSec/tree/main&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;</description><pubDate>Mon, 12 Jun 2023 21:57:50 +0800</pubDate></item><item><title>Burpsuite_Pro_V2023.6破解版</title><link>http://xiaodi8.com/?id=325</link><description>&lt;p&gt;Burpsuite_Pro_V2023.6破解版&lt;/p&gt;&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;h-burpsuite-pro-2023-6更新日志&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;burpsuite pro 2023.6更新日志&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;更新日期：2023 年 6 月 7 日星期三&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;此版本引入了 BChecks，这是自定义扫描检查。它还改进了的实时爬网路径视图、GraphQL 扫描检查，以及一些额外的改进和错误修复。&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;想设置环境变量什么的最好是安装在默认位置).&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;②下载破解工具BurpLoaderKeygen.jar&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;下载地址:&lt;br style=&quot;box-sizing: inherit;&quot;/&gt;&lt;a href=&quot;https://github.com/h3110w0r1d-y/BurpLoaderKeygen/releases/download/1.15/BurpLoaderKeygen.jar&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;BurpLoaderKeygen.jar&lt;/a&gt;&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;当前版本:BurpLoaderKeygen.jar v1.15&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;该版本添加了命令行启动参数:&lt;/p&gt;&lt;pre class=&quot;wp-block-code&quot; style=&quot;box-sizing: border-box; font-size: 0.9375rem; font-family: &amp;quot;courier 10 pitch&amp;quot;, Courier, monospace; overflow: auto; margin-top: 1.5em; margin-bottom: 1.5em; padding: 1.5em; max-width: 100%; border: 1px solid rgb(229, 229, 229); background-color: rgb(245, 245, 245); line-height: 1.6; border-radius: 3px; color: rgb(0, 128, 0);&quot;&gt;&lt;code class=&quot;hljs language-css&quot; style=&quot;box-sizing: inherit; font-size: 0.9375rem; font-family: inherit; background: rgb(43, 43, 43); color: rgb(248, 248, 242); display: block; overflow-wrap: break-word; white-space: pre-wrap; padding: 1em; overflow-x: auto;&quot;&gt;java -jar Burploaderkeygen&lt;span class=&quot;hljs-selector-class&quot; style=&quot;box-sizing: inherit; color: #FFA07A;&quot;&gt;.jar&lt;/span&gt; &lt;span class=&quot;hljs-selector-attr&quot; style=&quot;box-sizing: inherit;&quot;&gt;[-a|-auto [0|1]&lt;/span&gt;] &lt;span class=&quot;hljs-selector-attr&quot; style=&quot;box-sizing: inherit;&quot;&gt;[-i|-ignore [0|1]&lt;/span&gt;] &lt;span class=&quot;hljs-selector-attr&quot; style=&quot;box-sizing: inherit;&quot;&gt;[-n|-name &amp;lt;UserName&amp;gt;]&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;pre class=&quot;prism-highlight prism-language-actionscript&quot;&gt;&lt;span style=&quot;background-color: #FFFFFF; color: #008000; font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal;&quot;&gt;③将如下两个文件放在同一目录下&lt;/span&gt;&lt;br/&gt;&lt;/pre&gt;&lt;pre class=&quot;wp-block-code&quot; style=&quot;box-sizing: border-box; font-size: 0.9375rem; font-family: &amp;quot;courier 10 pitch&amp;quot;, Courier, monospace; overflow: auto; margin-top: 1.5em; margin-bottom: 1.5em; padding: 1.5em; max-width: 100%; border: 1px solid rgb(229, 229, 229); background-color: rgb(245, 245, 245); line-height: 1.6; border-radius: 3px; color: rgb(0, 128, 0);&quot;&gt;BurpLoaderKeygen.jar
burpsuite_pro_v2023.6.jar&lt;/pre&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;a href=&quot;https://portswigger-cdn.net/burp/releases/download?product=pro&amp;type=Jar&amp;version=2023.6&quot; _src=&quot;https://portswigger-cdn.net/burp/releases/download?product=pro&amp;type=Jar&amp;version=2023.6&quot;&gt;&lt;/a&gt; &lt;span style=&quot;color: #008000; font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; background-color: #FFFFFF;&quot;&gt;④双击BurpLoaderKeygen.jar&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;img src=&quot;http://xiaodi8.com/zb_users/upload/2023/06/202306121686578211361562.png&quot; alt=&quot;image.png&quot;/&gt;&lt;span style=&quot;color: #008000; font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; background-color: #FFFFFF;&quot;&gt;⑤然后参考如下往期burp破解图片即可&lt;/span&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700; color: #008000; font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; background-color: #FFFFFF;&quot;&gt;&lt;mark class=&quot;has-inline-color&quot; style=&quot;box-sizing: inherit; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; color: rgb(247, 5, 5);&quot;&gt;(本质一样,就是复制粘贴)&lt;/mark&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span style=&quot;color: #5EDB0B; font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; background-color: #000000;&quot;&gt;加载器来源于GitHub,安全性自测.&lt;/span&gt;&lt;br style=&quot;box-sizing: inherit; color: rgb(94, 219, 11); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal;&quot;/&gt;&lt;span style=&quot;color: #5EDB0B; font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; background-color: #000000;&quot;&gt;burpsuite2023.6亲测可用&lt;/span&gt;&lt;br style=&quot;box-sizing: inherit; color: rgb(94, 219, 11); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal;&quot;/&gt;&lt;span style=&quot;color: #5EDB0B; font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; background-color: #000000;&quot;&gt;保险起见,请放虚拟机中运行&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;img src=&quot;http://xiaodi8.com/zb_users/upload/2023/06/202306121686578105178860.png&quot; alt=&quot;image.png&quot;/&gt;&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;br/&gt;&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;</description><pubDate>Mon, 12 Jun 2023 21:53:48 +0800</pubDate></item><item><title>云安全相关渗透文章及工具</title><link>http://xiaodi8.com/?id=324</link><description>&lt;h1 class=&quot;wp-block-heading&quot; id=&quot;h-云安全-攻击&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 2.25rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;云安全 – 攻击&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h1&gt;&lt;p&gt;&lt;img src=&quot;http://xiaodi8.com/zb_users/upload/2023/04/202304091681033244834076.png&quot; alt=&quot;image.png&quot;/&gt;&lt;/p&gt;&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;h-aws&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;AWS&quot; ez-toc-data-id=&quot;#AWS&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#aws&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;AWS&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-在-aws-vpn-客户端中将权限升级为-system&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E5%9C%A8_AWS_VPN_%E5%AE%A2%E6%88%B7%E7%AB%AF%E4%B8%AD%E5%B0%86%E6%9D%83%E9%99%90%E5%8D%87%E7%BA%A7%E4%B8%BA_SYSTEM&quot; ez-toc-data-id=&quot;#在_AWS_VPN_客户端中将权限升级为_SYSTEM&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#privilege-escalation-to-system-in-aws-vpn-client&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;在 AWS VPN 客户端中将权限升级为 SYSTEM&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/aws/cve-2022-25165-aws-vpn-client/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://rhinosecuritylabs.com/aws/cve-2022-25165-aws-vpn-client/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-aws-workspaces-远程代码执行&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;AWS_WorkSpaces_%E8%BF%9C%E7%A8%8B%E4%BB%A3%E7%A0%81%E6%89%A7%E8%A1%8C&quot; ez-toc-data-id=&quot;#AWS_WorkSpaces_远程代码执行&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#aws-workspaces-remote-code-execution&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;AWS WorkSpaces 远程代码执行&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/aws/cve-2021-38112-aws-workspaces-rce/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;aws/cve-2021-38112-aws-workspaces-rce/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-cloudformation-模板中的资源注入&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;CloudFormation_%E6%A8%A1%E6%9D%BF%E4%B8%AD%E7%9A%84%E8%B5%84%E6%BA%90%E6%B3%A8%E5%85%A5&quot; ez-toc-data-id=&quot;#CloudFormation_模板中的资源注入&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#resource-injection-in-cloudformation-templates&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;CloudFormation 模板中的资源注入&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/aws/cloud-malware-cloudformation-injection/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;rhinosecuritylabs.com/aws/cloud-malware-cloudformation-injection/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-下载和探索-aws-ebs-快照&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E4%B8%8B%E8%BD%BD%E5%92%8C%E6%8E%A2%E7%B4%A2_AWS_EBS_%E5%BF%AB%E7%85%A7&quot; ez-toc-data-id=&quot;#下载和探索_AWS_EBS_快照&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#downloading-and-exploring-aws-ebs-snapshots&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;下载和探索 AWS EBS 快照&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/aws/exploring-aws-ebs-snapshots/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://rhinosecuritylabs.com/aws/exploring-aws-ebs-snapshots/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-cloudgoat-ecs-efs-attack-演练&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;CloudGoat_ECS_EFS_Attack_%E6%BC%94%E7%BB%83&quot; ez-toc-data-id=&quot;#CloudGoat_ECS_EFS_Attack_演练&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#cloudgoat-ecs_efs_attack-walkthrough&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;CloudGoat ECS_EFS_Attack 演练&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/cloud-security/cloudgoat-aws-ecs_efs_attack/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;cloud-security/cloudgoat-aws-ecs_efs_attack/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-gke-kubelet-tls-bootstrap-提权&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;GKE_Kubelet_TLS_Bootstrap_%E6%8F%90%E6%9D%83&quot; ez-toc-data-id=&quot;#GKE_Kubelet_TLS_Bootstrap_提权&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#gke-kubelet-tls-bootstrap-privilege-escalation&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;GKE Kubelet TLS Bootstrap 提权&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/cloud-security/kubelet-tls-bootstrap-privilege-escalation/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;cloud-security/kubelet-tls-bootstrap-privilege-escalation/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-武器化-aws-ecs-任务定义以窃取正在运行的容器中的凭证&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;武器化 AWS ECS 任务定义以窃取正在运行的容器中的凭证&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/aws/weaponizing-ecs-task-definitions-steal-credentials-running-containers/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;weaponizing-ecs-task-definitions-steal-credentials-running-containers/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-cloudgoat-aws-场景演练-ec2-ssrf&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;CloudGoat_AWS_%E5%9C%BA%E6%99%AF%E6%BC%94%E7%BB%83%EF%BC%9AEC2_SSRF&quot; ez-toc-data-id=&quot;#CloudGoat_AWS_场景演练：EC2_SSRF&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#cloudgoat-aws-scenario-walkthrough-ec2_ssrf&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;CloudGoat AWS 场景演练：“EC2_SSRF”&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/cloud-security/cloudgoat-aws-scenario-ec2_ssrf/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;cloud-security/cloudgoat-aws-scenario-ec2_ssrf/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-掠夺硬编码机密的-aws-ecs-任务定义&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E6%8E%A0%E5%A4%BA%E7%A1%AC%E7%BC%96%E7%A0%81%E6%9C%BA%E5%AF%86%E7%9A%84_AWS_ECS_%E4%BB%BB%E5%8A%A1%E5%AE%9A%E4%B9%89&quot; ez-toc-data-id=&quot;#掠夺硬编码机密的_AWS_ECS_任务定义&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#pillaging-aws-ecs-task-definitions-for-hardcoded-secrets&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;掠夺硬编码机密的 AWS ECS 任务定义&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/aws/pillaging-ecs-task-definitions-two-new-pacu-modules/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;aws/pillaging-ecs-task-definitions-two-new-pacu-modules/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-在-aws-中滥用-vpc-流量镜像&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E5%9C%A8_AWS_%E4%B8%AD%E6%BB%A5%E7%94%A8_VPC_%E6%B5%81%E9%87%8F%E9%95%9C%E5%83%8F&quot; ez-toc-data-id=&quot;#在_AWS_中滥用_VPC_流量镜像&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#abusing-vpc-traffic-mirroring-in-aws&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;在 AWS 中滥用 VPC 流量镜像&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/aws/abusing-vpc-traffic-mirroring-in-aws/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://rhinosecuritylabs.com/aws/abusing-vpc-traffic-mirroring-in-aws/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-使用云容器攻击工具-ccat-利用-aws-ecr-和-ecs&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E4%BD%BF%E7%94%A8%E4%BA%91%E5%AE%B9%E5%99%A8%E6%94%BB%E5%87%BB%E5%B7%A5%E5%85%B7_CCAT_%E5%88%A9%E7%94%A8_AWS_ECR_%E5%92%8C_ECS&quot; ez-toc-data-id=&quot;#使用云容器攻击工具_CCAT_利用_AWS_ECR_和_ECS&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#exploiting-aws-ecr-and-ecs-with-the-cloud-container-attack-tool-ccat&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;使用云容器攻击工具 (CCAT) 利用 AWS ECR 和 ECS&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/aws/cloud-container-attack-tool/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://rhinosecuritylabs.com/aws/cloud-container-attack-tool/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-使用-aws-api-gateway-绕过基于-ip-的封锁&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E4%BD%BF%E7%94%A8_AWS_API_Gateway_%E7%BB%95%E8%BF%87%E5%9F%BA%E4%BA%8E_IP_%E7%9A%84%E5%B0%81%E9%94%81&quot; ez-toc-data-id=&quot;#使用_AWS_API_Gateway_绕过基于_IP_的封锁&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#bypassing-ip-based-blocking-with-aws-api-gateway&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;使用 AWS API Gateway 绕过基于 IP 的封锁&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/aws/bypassing-ip-based-blocking-aws/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://rhinosecuritylabs.com/aws/bypassing-ip-based-blocking-aws/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-在-aws-上使用-mfa-钓鱼用户&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E5%9C%A8_AWS_%E4%B8%8A%E4%BD%BF%E7%94%A8_MFA_%E9%92%93%E9%B1%BC%E7%94%A8%E6%88%B7&quot; ez-toc-data-id=&quot;#在_AWS_上使用_MFA_钓鱼用户&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#phishing-users-with-mfa-on-aws&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;在 AWS 上使用 MFA 钓鱼用户&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/aws/mfa-phishing-on-aws/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://rhinosecuritylabs.com/aws/mfa-phishing-on-aws/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-aws-iam-特权升级-方法和缓解措施&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;AWS_IAM_%E7%89%B9%E6%9D%83%E5%8D%87%E7%BA%A7_-_%E6%96%B9%E6%B3%95%E5%92%8C%E7%BC%93%E8%A7%A3%E6%8E%AA%E6%96%BD&quot; ez-toc-data-id=&quot;#AWS_IAM_特权升级_-_方法和缓解措施&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#aws-iam-privilege-escalation--methods-and-mitigation&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;AWS IAM 特权升级 – 方法和缓解措施&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;aws/aws-privilege-escalation-methods-mitigation/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-渗透测试-aws-存储-踢-s3-存储桶&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95_AWS_%E5%AD%98%E5%82%A8%EF%BC%9A%E8%B8%A2_S3_%E5%AD%98%E5%82%A8%E6%A1%B6&quot; ez-toc-data-id=&quot;#渗透测试_AWS_存储：踢_S3_存储桶&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#penetration-testing-aws-storage-kicking-the-s3-bucket&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;渗透测试 AWS 存储：踢 S3 存储桶&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/penetration-testing/penetration-testing-aws-storage/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;penetration-testing/penetration-testing-aws-storage/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-云安全风险-p2-aws-cloudtrail-中的-csv-注入&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E4%BA%91%E5%AE%89%E5%85%A8%E9%A3%8E%E9%99%A9_P2%EF%BC%9AAWS_CloudTrail_%E4%B8%AD%E7%9A%84_CSV_%E6%B3%A8%E5%85%A5&quot; ez-toc-data-id=&quot;#云安全风险_P2：AWS_CloudTrail_中的_CSV_注入&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#cloud-security-risks-p2-csv-injection-in-aws-cloudtrail&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;云安全风险 (P2)：AWS CloudTrail 中的 CSV 注入&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/aws/cloud-security-csv-injection-aws-cloudtrail/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://rhinosecuritylabs.com/aws/&lt;/a&gt;&lt;br style=&quot;box-sizing: inherit;&quot;/&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/aws/cloud-security-csv-injection-aws-cloudtrail/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;cloud-security-csv-injection-aws-cloudtrail/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-亚马逊的-aws-配置错误-在-amazon-go-中上传任意文件&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E4%BA%9A%E9%A9%AC%E9%80%8A%E7%9A%84_AWS_%E9%85%8D%E7%BD%AE%E9%94%99%E8%AF%AF%EF%BC%9A%E5%9C%A8_Amazon_Go_%E4%B8%AD%E4%B8%8A%E4%BC%A0%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6&quot; ez-toc-data-id=&quot;#亚马逊的_AWS_配置错误：在_Amazon_Go_中上传任意文件&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#amazons-aws-misconfiguration-arbitrary-files-upload-in-amazon-go&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;亚马逊的 AWS 配置错误：在 Amazon Go 中上传任意文件&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/aws/amazon-aws-misconfiguration-amazon-go/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;amazon-aws-misconfiguration-amazon-go/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-权限升级攻击-攻击-aws-iam-权限错误配置&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E6%9D%83%E9%99%90%E5%8D%87%E7%BA%A7%E6%94%BB%E5%87%BB%EF%BC%9A%E6%94%BB%E5%87%BB_AWS_IAM_%E6%9D%83%E9%99%90%E9%94%99%E8%AF%AF%E9%85%8D%E7%BD%AE&quot; ez-toc-data-id=&quot;#权限升级攻击：攻击_AWS_IAM_权限错误配置&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#privilege-escalation-attack--attacking-aws-iam-permission-misconfigurations&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;权限升级攻击：攻击 AWS IAM 权限错误配置&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://payatu.com/blog/mayank.arora/iam_privilege_escalation_attack&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://payatu.com/blog/mayank.arora/iam_privilege_escalation_attack&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-iam-易受攻击-aws-iam-特权升级游乐场&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;IAM_%E6%98%93%E5%8F%97%E6%94%BB%E5%87%BB_-_AWS_IAM_%E7%89%B9%E6%9D%83%E5%8D%87%E7%BA%A7%E6%B8%B8%E4%B9%90%E5%9C%BA&quot; ez-toc-data-id=&quot;#IAM_易受攻击_-_AWS_IAM_特权升级游乐场&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#iam-vulnerable---an-aws-iam-privilege-escalation-playground&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;IAM 易受攻击 – AWS IAM 特权升级游乐场&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://bishopfox.com/blog/aws-iam-privilege-escalation-playground&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://bishopfox.com/blog/aws-iam-privilege-escalation-playground&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-通往云的自动扶梯-aws-中的-5-个-privesc-攻击向量&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E9%80%9A%E5%BE%80%E4%BA%91%E7%9A%84%E8%87%AA%E5%8A%A8%E6%89%B6%E6%A2%AF%EF%BC%9AAWS_%E4%B8%AD%E7%9A%84_5_%E4%B8%AA_Privesc_%E6%94%BB%E5%87%BB%E5%90%91%E9%87%8F&quot; ez-toc-data-id=&quot;#通往云的自动扶梯：AWS_中的_5_个_Privesc_攻击向量&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#escalator-to-the-cloud-5-privesc-attack-vectors-in-aws&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;通往云的自动扶梯：AWS 中的 5 个 Privesc 攻击向量&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://bishopfox.com/blog/5-privesc-attack-vectors-in-aws&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://bishopfox.com/blog/5-privesc-attack-vectors-in-aws&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-易受攻击的-aws-lambda-函数-云攻击中的初始访问&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E6%98%93%E5%8F%97%E6%94%BB%E5%87%BB%E7%9A%84_AWS_Lambda_%E5%87%BD%E6%95%B0-%E4%BA%91%E6%94%BB%E5%87%BB%E4%B8%AD%E7%9A%84%E5%88%9D%E5%A7%8B%E8%AE%BF%E9%97%AE&quot; ez-toc-data-id=&quot;#易受攻击的_AWS_Lambda_函数-云攻击中的初始访问&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#vulnerable-aws-lambda-function--initial-access-in-cloud-attacks&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;易受攻击的 AWS Lambda 函数——云攻击中的初始访问&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://sysdig.com/blog/exploit-mitigate-aws-lambdas-mitre/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://sysdig.com/blog/exploit-mitigate-aws-lambdas-mitre/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-通过-amazon-web-services-的-ec2-进行特权升级攻击&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E9%80%9A%E8%BF%87_Amazon_Web_Services_%E7%9A%84_EC2_%E8%BF%9B%E8%A1%8C%E7%89%B9%E6%9D%83%E5%8D%87%E7%BA%A7%E6%94%BB%E5%87%BB&quot; ez-toc-data-id=&quot;#通过_Amazon_Web_Services_的_EC2_进行特权升级攻击&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#inside-a-privilege-escalation-attack-via-amazon-web-services-ec2&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;通过 Amazon Web Services 的 EC2 进行特权升级攻击&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://thenewstack.io/inside-a-privilege-escalation-attack-via-amazon-web-services-ec2/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;inside-a-privilege-escalation-attack-via-amazon-web-services-ec2/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-aws-攻击&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;AWS_%E6%94%BB%E5%87%BB&quot; ez-toc-data-id=&quot;#AWS_攻击&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#aws-attacks&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;AWS 攻击&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://pentestbook.six2dez.com/enumeration/cloud/aws&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://pentestbook.six2dez.com/enumeration/cloud/aws&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-aws-影子管理员&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;AWS_%E5%BD%B1%E5%AD%90%E7%AE%A1%E7%90%86%E5%91%98&quot; ez-toc-data-id=&quot;#AWS_影子管理员&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#aws-shadow-admin&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;AWS 影子管理员&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://www.admin-magazine.com/Archive/2021/63/Shadow-admin-permissions-and-your-AWS-account&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Shadow-admin-permissions-and-your-AWS-account&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-通过-api-密钥获得-aws-控制台访问权限&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E9%80%9A%E8%BF%87_API_%E5%AF%86%E9%92%A5%E8%8E%B7%E5%BE%97_AWS_%E6%8E%A7%E5%88%B6%E5%8F%B0%E8%AE%BF%E9%97%AE%E6%9D%83%E9%99%90&quot; ez-toc-data-id=&quot;#通过_API_密钥获得_AWS_控制台访问权限&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#gaining-aws-console-access-via-api-keys&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;通过 API 密钥获得 AWS 控制台访问权限&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://www.netspi.com/blog/technical/gaining-aws-console-access-via-api-keys/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;gaining-aws-console-access-via-api-keys/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-为-ec2-自动创建-aws-ami-并复制到其他区域&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E4%B8%BA_EC2_%E8%87%AA%E5%8A%A8%E5%88%9B%E5%BB%BA_AWS_AMI_%E5%B9%B6%E5%A4%8D%E5%88%B6%E5%88%B0%E5%85%B6%E4%BB%96%E5%8C%BA%E5%9F%9F&quot; ez-toc-data-id=&quot;#为_EC2_自动创建_AWS_AMI_并复制到其他区域&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#automate-aws-ami-creation-for-ec2-and-copy-to-other-region&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;为 EC2 自动创建 AWS AMI 并复制到其他区域&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://dheeraj3choudhary.com/automate-aws-ami-creation-for-ec2-and-copy-to-other-region-or-disaster-recovery&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;automate-aws-ami-creation-for-ec2-and&lt;/a&gt;&lt;br style=&quot;box-sizing: inherit;&quot;/&gt;&lt;a href=&quot;https://dheeraj3choudhary.com/automate-aws-ami-creation-for-ec2-and-copy-to-other-region-or-disaster-recovery&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;-copy-to-other-region-or-disaster-recovery&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-instance-connect-将-ssh-密钥推送到-ec2-实例&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;Instance_Connect_-_%E5%B0%86_SSH_%E5%AF%86%E9%92%A5%E6%8E%A8%E9%80%81%E5%88%B0_EC2_%E5%AE%9E%E4%BE%8B&quot; ez-toc-data-id=&quot;#Instance_Connect_-_将_SSH_密钥推送到_EC2_实例&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#instance-connect---push-an-ssh-key-to-ec2-instance&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;Instance Connect – 将 SSH 密钥推送到 EC2 实例&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://cloudonaut.io/connect-to-your-ec2-instance-using-ssh-the-modern-way/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;connect-to-your-ec2-instance-using-ssh-the-modern-way/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-黄金-saml-攻击&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E9%BB%84%E9%87%91_SAML_%E6%94%BB%E5%87%BB&quot; ez-toc-data-id=&quot;#黄金_SAML_攻击&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#golden-saml-attack&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;黄金 SAML 攻击&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;golden-saml-newly-discovered-attack-technique-forges&lt;/a&gt;&lt;br style=&quot;box-sizing: inherit;&quot;/&gt;&lt;a href=&quot;https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;-authentication-to-cloud-apps&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://blog.sygnia.co/detection-and-hunting-of-golden-saml-attack&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;blog.sygnia.co/detection-and-hunting-of-golden-saml-attack&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-从云中的域控制器窃取哈希&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E4%BB%8E%E4%BA%91%E4%B8%AD%E7%9A%84%E5%9F%9F%E6%8E%A7%E5%88%B6%E5%99%A8%E7%AA%83%E5%8F%96%E5%93%88%E5%B8%8C&quot; ez-toc-data-id=&quot;#从云中的域控制器窃取哈希&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#stealing-hashes-from-domain-controllers-in-the-cloud&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;从云中的域控制器窃取哈希&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://medium.com/@_StaticFlow_/cloudcopy-stealing-hashes-from-domain-controllers-in-the-cloud-c55747f0913&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;cloudcopy-stealing-hashes-from-domain-controllers-in-the-cloud&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-aws-pentest-方法论&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;AWS_PenTest_%E6%96%B9%E6%B3%95%E8%AE%BA&quot; ez-toc-data-id=&quot;#AWS_PenTest_方法论&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#aws-pentest-methodology&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;AWS PenTest 方法论&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Cloud%20-%20AWS%20Pentest.md&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Methodology%20and%20Resources/Cloud%20-%20AWS%20Pentest&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-cloudgoat-官方攻略系列-rce-web-app&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;CloudGoat_%E5%AE%98%E6%96%B9%E6%94%BB%E7%95%A5%E7%B3%BB%E5%88%97%EF%BC%9Arce_web_app&quot; ez-toc-data-id=&quot;#CloudGoat_官方攻略系列：rce_web_app&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#cloudgoat-official-walkthrough-series-rce_web_app&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;CloudGoat 官方攻略系列：“rce_web_app”&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/aws/cloudgoat-walkthrough-rce_web_app/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://rhinosecuritylabs.com/aws/cloudgoat-walkthrough-rce_web_app/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;h-azure&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;Azure&quot; ez-toc-data-id=&quot;#Azure&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#azure&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;Azure&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-gke-kubelet-tls-bootstrap-提权-1&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;GKE_Kubelet_TLS_Bootstrap_%E6%8F%90%E6%9D%83-2&quot; ez-toc-data-id=&quot;#GKE_Kubelet_TLS_Bootstrap_提权-2&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#gke-kubelet-tls-bootstrap-privilege-escalation-1&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;GKE Kubelet TLS Bootstrap 提权&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/cloud-security/kubelet-tls-bootstrap-privilege-escalation/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;cloud-security/kubelet-tls-bootstrap-privilege-escalation/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-云安全风险-第-1-部分-azure-csv-注入漏洞&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E4%BA%91%E5%AE%89%E5%85%A8%E9%A3%8E%E9%99%A9%EF%BC%88%E7%AC%AC_1_%E9%83%A8%E5%88%86%EF%BC%89%EF%BC%9AAzure_CSV_%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E&quot; ez-toc-data-id=&quot;#云安全风险（第_1_部分）：Azure_CSV_注入漏洞&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#cloud-security-risks-part-1-azure-csv-injection-vulnerability&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;云安全风险（第 1 部分）：Azure CSV 注入漏洞&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/azure/cloud-security-risks-part-1-azure-csv-injection-vulnerability/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;cloud-security-risks-part-1-azure-csv-injection-vulnerability/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-saas-公司的安全性-利用-infosec-实现商业价值&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;SaaS_%E5%85%AC%E5%8F%B8%E7%9A%84%E5%AE%89%E5%85%A8%E6%80%A7%EF%BC%9A%E5%88%A9%E7%94%A8_Infosec_%E5%AE%9E%E7%8E%B0%E5%95%86%E4%B8%9A%E4%BB%B7%E5%80%BC&quot; ez-toc-data-id=&quot;#SaaS_公司的安全性：利用_Infosec_实现商业价值&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#security-for-saas-companies-leveraging-infosec-for-business-value&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;SaaS 公司的安全性：利用 Infosec 实现商业价值&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/cloud-security/security-saas-companies-leveraging-infosec-business-value/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;security-saas-companies-leveraging-infosec-business-value/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-常见的-azure-安全漏洞和错误配置&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E5%B8%B8%E8%A7%81%E7%9A%84_Azure_%E5%AE%89%E5%85%A8%E6%BC%8F%E6%B4%9E%E5%92%8C%E9%94%99%E8%AF%AF%E9%85%8D%E7%BD%AE&quot; ez-toc-data-id=&quot;#常见的_Azure_安全漏洞和错误配置&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#common-azure-security-vulnerabilities-and-misconfigurations&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;常见的 Azure 安全漏洞和错误配置&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/cloud-security/common-azure-security-vulnerabilities/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;rhinosecuritylabs.com/cloud-security/&lt;/a&gt;&lt;br style=&quot;box-sizing: inherit;&quot;/&gt;&lt;a href=&quot;https://rhinosecuritylabs.com/cloud-security/common-azure-security-vulnerabilities/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;common-azure-security-vulnerabilities/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-枚举有效的电子邮件&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E6%9E%9A%E4%B8%BE%E6%9C%89%E6%95%88%E7%9A%84%E7%94%B5%E5%AD%90%E9%82%AE%E4%BB%B6&quot; ez-toc-data-id=&quot;#枚举有效的电子邮件&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#enumerate-valid-emails&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;枚举有效的电子邮件&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://zigmax.net/enumerate-valid-emails-accounts%EF%BF%BC/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://zigmax.net/enumerate-valid-emails-accounts%EF%BF%BC/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-枚举-azure-子域&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E6%9E%9A%E4%B8%BE_Azure_%E5%AD%90%E5%9F%9F&quot; ez-toc-data-id=&quot;#枚举_Azure_子域&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#enumerate-azure-subdomains&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;枚举 Azure 子域&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://www.netspi.com/blog/technical/cloud-penetration-testing/enumerating-azure-services/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;cloud-penetration-testing/enumerating-azure-services/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://m0chan.github.io/2019/12/16/Subdomain-Takeover-Azure-CDN.html&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Subdomain-Takeover-Azure-CDN.html&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-azure-攻击&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;Azure_%E6%94%BB%E5%87%BB&quot; ez-toc-data-id=&quot;#Azure_攻击&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#azure-attacks&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;Azure 攻击&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://pentestbook.six2dez.com/enumeration/cloud/azure&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://pentestbook.six2dez.com/enumeration/cloud/azure&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-azure-active-directory-帐户枚举&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;Azure_Active_Directory_%E5%B8%90%E6%88%B7%E6%9E%9A%E4%B8%BE&quot; ez-toc-data-id=&quot;#Azure_Active_Directory_帐户枚举&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#azure-active-directory-account-enumeration&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;Azure Active Directory 帐户枚举&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://helloitsliam.com/2021/11/18/azure-active-directory-account-enumeration/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;azure-active-directory-account-enumeration/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-滥用-microsoft-的-azure-域来托管网络钓鱼攻击&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E6%BB%A5%E7%94%A8_Microsoft_%E7%9A%84_Azure_%E5%9F%9F%E6%9D%A5%E6%89%98%E7%AE%A1%E7%BD%91%E7%BB%9C%E9%92%93%E9%B1%BC%E6%94%BB%E5%87%BB&quot; ez-toc-data-id=&quot;#滥用_Microsoft_的_Azure_域来托管网络钓鱼攻击&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#abusing-microsofts-azure-domains-to-host-phishing-attacks&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;滥用 Microsoft 的 Azure 域来托管网络钓鱼攻击&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://www.zscaler.fr/blogs/security-research/abusing-microsofts-azure-domains-host-phishing-attacks&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;abusing-microsofts-azure-domains-host-phishing-attacks&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-防御-evilginx2-mfa-绕过&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E9%98%B2%E5%BE%A1_EvilGinx2_MFA_%E7%BB%95%E8%BF%87&quot; ez-toc-data-id=&quot;#防御_EvilGinx2_MFA_绕过&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#defending-against-the-evilginx2-mfa-bypass&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;防御 EvilGinx2 MFA 绕过&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad/defending-against-the-evilginx2-mfa-bypass/m-p/501719&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;microsoft-entra-azure-ad/defending-against&lt;/a&gt;&lt;br style=&quot;box-sizing: inherit;&quot;/&gt;&lt;a href=&quot;https://techcommunity.microsoft.com/t5/microsoft-entra-azure-ad/defending-against-the-evilginx2-mfa-bypass/m-p/501719&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;-the-evilginx2-mfa-bypass/mp/501719&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://thecloudtechnologist.com/2019/04/29/defending-against-evilginx2-in-office-365/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;defending-against-evilginx2-in-office-365/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-365-stealer-简介-理解和执行非法许可授予攻击&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;365-Stealer_%E7%AE%80%E4%BB%8B_-_%E7%90%86%E8%A7%A3%E5%92%8C%E6%89%A7%E8%A1%8C%E9%9D%9E%E6%B3%95%E8%AE%B8%E5%8F%AF%E6%8E%88%E4%BA%88%E6%94%BB%E5%87%BB&quot; ez-toc-data-id=&quot;#365-Stealer_简介_-_理解和执行非法许可授予攻击&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#introduction-to-365-stealer---understanding-and-executing-the-illicit-consent-grant-attack&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;365-Stealer 简介 – 理解和执行非法许可授予攻击&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://www.alteredsecurity.com/post/introduction-to-365-stealer&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://www.alteredsecurity.com/post/introduction-to-365-stealer&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://www.cloud-architekt.net/detection-and-mitigation-consent-grant-attacks-azuread/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;detection-and-mitigation-consent-grant-attacks-azuread/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-azure-ad-密码喷洒-从攻击到检测-和预防&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;Azure_AD_%E5%AF%86%E7%A0%81%E5%96%B7%E6%B4%92%EF%BC%9B%E4%BB%8E%E6%94%BB%E5%87%BB%E5%88%B0%E6%A3%80%E6%B5%8B%EF%BC%88%E5%92%8C%E9%A2%84%E9%98%B2%EF%BC%89%E3%80%82&quot; ez-toc-data-id=&quot;#Azure_AD_密码喷洒；从攻击到检测（和预防）。&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#azure-ad-password-spray-from-attack-to-detection-and-prevention&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;Azure AD 密码喷洒；从攻击到检测（和预防）。&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://derkvanderwoude.medium.com/password-spray-from-attack-to-detection-and-prevention-87c48cede0c0&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;password-spray-from-attack-to-detection-and-prevention-87c48cede0c0&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://jeffreyappel.nl/protecting-against-password-spray-attacks-with-azure-sentinel-and-azure-ad/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;protecting-against-password-spray-attacks-with-azure-sentinel-and-azure-ad/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-通过-pass-the-prt-横向移动到云端&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E9%80%9A%E8%BF%87_PASS-THE-PRT_%E6%A8%AA%E5%90%91%E7%A7%BB%E5%8A%A8%E5%88%B0%E4%BA%91%E7%AB%AF&quot; ez-toc-data-id=&quot;#通过_PASS-THE-PRT_横向移动到云端&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#lateral-movement-to-the-cloud-with-pass-the-prt&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;通过 PASS-THE-PRT 横向移动到云端&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://stealthbits.com/blog/lateral-movement-to-the-cloud-pass-the-prt/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;ateral-movement-to-the-cloud-pass-the-prt/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://derkvanderwoude.medium.com/pass-the-prt-attack-and-detection-by-microsoft-defender-for-afd7dbe83c94&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;pass-the-prt-attack-and-detection-by-microsoft-defender-for&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-azure-ad-通过证书&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;Azure_AD_%E9%80%9A%E8%BF%87%E8%AF%81%E4%B9%A6&quot; ez-toc-data-id=&quot;#Azure_AD_通过证书&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#azure-ad-pass-the-certificate&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;Azure AD 通过证书&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://medium.com/@mor2464/azure-ad-pass-the-certificate-d0c5de624597&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://medium.com/@mor2464/azure-ad-pass-the-certificate&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-如何通过-ssh-连接到特定的-azure-web-app-实例&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E5%A6%82%E4%BD%95%E9%80%9A%E8%BF%87_SSH_%E8%BF%9E%E6%8E%A5%E5%88%B0%E7%89%B9%E5%AE%9A%E7%9A%84_Azure_Web_App_%E5%AE%9E%E4%BE%8B&quot; ez-toc-data-id=&quot;#如何通过_SSH_连接到特定的_Azure_Web_App_实例&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#how-to-ssh-into-specific-azure-web-app-instance&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;如何通过 SSH 连接到特定的 Azure Web App 实例&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://codez.deedx.cz/posts/how-to-ssh-into-web-app-instance/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://codez.deedx.cz/posts/how-to-ssh-into-web-app-instance/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-攻击-azure-azure-ad-并介绍-powerzure&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E6%94%BB%E5%87%BB_Azure%E3%80%81Azure_AD_%E5%B9%B6%E4%BB%8B%E7%BB%8D_PowerZure&quot; ez-toc-data-id=&quot;#攻击_Azure、Azure_AD_并介绍_PowerZure&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#attacking-azure-azure-ad-and-introducing-powerzure&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;攻击 Azure、Azure AD 并介绍 PowerZure&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://posts.specterops.io/attacking-azure-azure-ad-and-introducing-powerzure-ca70b330511a&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;attacking-azure-azure-ad-and-introducing-powerzure-ca70b330511a&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-未检测到的-azure-active-directory-暴力破解攻击&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E6%9C%AA%E6%A3%80%E6%B5%8B%E5%88%B0%E7%9A%84_Azure_Active_Directory_%E6%9A%B4%E5%8A%9B%E7%A0%B4%E8%A7%A3%E6%94%BB%E5%87%BB&quot; ez-toc-data-id=&quot;#未检测到的_Azure_Active_Directory_暴力破解攻击&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#undetected-azure-active-directory-brute-force-attacks&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;未检测到的 Azure Active Directory 暴力破解攻击&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://www.secureworks.com/research/undetected-azure-active-directory-brute-force-attacks&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;undetected-azure-active-directory-brute-force-attacks&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-azure-ad-如何容易受到暴力破解和-dos-攻击&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;Azure_AD_%E5%A6%82%E4%BD%95%E5%AE%B9%E6%98%93%E5%8F%97%E5%88%B0%E6%9A%B4%E5%8A%9B%E7%A0%B4%E8%A7%A3%E5%92%8C_DOS_%E6%94%BB%E5%87%BB&quot; ez-toc-data-id=&quot;#Azure_AD_如何容易受到暴力破解和_DOS_攻击&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#how-azure-ad-could-be-vulnerable-to-brute-force-and-dos-attacks&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;Azure AD 如何容易受到暴力破解和 DOS 攻击&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://medium.com/hackernoon/azure-brute-farce-17e27dc05f85&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://medium.com/hackernoon/azure-brute-farce-17e27dc05f85&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; id=&quot;h-如何在-azure-和-o365-中绕过-mfa&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E5%A6%82%E4%BD%95%E5%9C%A8_Azure_%E5%92%8C_O365_%E4%B8%AD%E7%BB%95%E8%BF%87_MFA&quot; ez-toc-data-id=&quot;#如何在_Azure_和_O365_中绕过_MFA&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#how-to-bypass-mfa-in-azure-and-o365&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;如何在 Azure 和 O365 中绕过 MFA&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://secwise.be/how-to-bypass-mfa-in-azure-and-o365-part-1/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://secwise.be/how-to-bypass-mfa-in-azure-and-o365-part-1/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;h-aws-安全工具&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;AWS_%E5%AE%89%E5%85%A8%E5%B7%A5%E5%85%B7&quot; ez-toc-data-id=&quot;#AWS_安全工具&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#aws-security-tools&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;AWS 安全工具&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/toniblyx/my-arsenal-of-aws-security-tools&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;github.com/toniblyx/my-arsenal-of-aws-security-tools&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/blackbotsecurity/AWS-Attack&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://github.com/blackbotsecurity/AWS-Attack&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/awslabs/aws-cloudsaga&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://github.com/awslabs/aws-cloudsaga&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/awslabs/aws-support-tools&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://github.com/awslabs/aws-support-tools&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/0xVariable/AWS-Security-Tools&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://github.com/0xVariable/AWS-Security-Tools&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://cybersecurityup.github.io/awstrm/index.html&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://cybersecurityup.github.io/awstrm/index.html&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/dafthack/CloudPentestCheatsheets/blob/master/cheatsheets/AWS.md&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;CloudPentestCheatsheets/blob/master/cheatsheets/AWS.md&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/RhinoSecurityLabs/cloudgoat&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://github.com/RhinoSecurityLabs/cloudgoat&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;h-azure-安全工具&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;Azure_%E5%AE%89%E5%85%A8%E5%B7%A5%E5%85%B7&quot; ez-toc-data-id=&quot;#Azure_安全工具&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/CyberSecurityUP/Cloud-Security-Attacks#azure-security-tools&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;Azure 安全工具&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/NetSPI/MicroBurst/blob/master/Misc/Invoke-EnumerateAzureBlobs.ps1&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Invoke-EnumerateAzureBlobs.ps1&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://microsoft.github.io/Azure-Threat-Research-Matrix/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://microsoft.github.io/Azure-Threat-Research-Matrix/&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/Cloud-Architekt/AzureAD-Attack-Defense&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://github.com/Cloud-Architekt/AzureAD-攻击-防御&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/dafthack/CloudPentestCheatsheets/blob/master/cheatsheets/Azure.md&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;CloudPentestCheatsheets/blob/master/cheatsheets&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/Kyuu-Ji/Awesome-Azure-Pentest/blob/main/README.md&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://github.com/Kyuu-Ji/Awesome-Azure-Pentest&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/ine-labs/AzureGoat&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://github.com/ine-labs/AzureGoat&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/kmcquade/awesome-azure-security&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://github.com/kmcquade/awesome-azure-security&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/nccgroup/azucar&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://github.com/nccgroup/azucar&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;</description><pubDate>Sun, 09 Apr 2023 17:39:18 +0800</pubDate></item><item><title>linWinPwn–Active Directory漏描</title><link>http://xiaodi8.com/?id=323</link><description>&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;h-描述&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;描述&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;linWinPwn 是一个 bash 脚本，可以自动执行许多 Active Directory 枚举和漏洞检查。该脚本使用了许多工具并作为它们的包装器。&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;工具包括：&lt;mark class=&quot;has-inline-color&quot; style=&quot;box-sizing: inherit; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; color: rgb(248, 10, 10);&quot;&gt;impacket、bloodhound、crackmapexec、enum4linux-ng、ldapdomaindump、lsassy、smbmap、kerbrute、adidnsdump、certipy、silenthound&amp;nbsp;&lt;/mark&gt;等。&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;当您只能在有限的时间内访问 Active Directory 环境，并且您希望自动执行枚举过程并有效地收集证据时，linWinPwn 特别有用。此外，linWinPwn 可以取代 Windows 上枚举工具的使用，以减少创建的工件（例如，PowerShell 命令、Windows 事件、磁盘上创建的文件）的数量，&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;mark class=&quot;has-inline-color&quot; style=&quot;box-sizing: inherit; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; color: rgb(249, 1, 1);&quot;&gt;并绕过某些反病毒或 EDR&lt;/mark&gt;&lt;/span&gt;。这可以通过创建从 Windows 主机（例如，VDI 机器或工作站或笔记本电脑）到远程 Linux 机器（例如，Pentest 笔记本电脑或 VPS）的 SSH 隧道，并使用代理链运行 linWinPwn 来执行远程动态端口转发来实现.&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;下载及使用：&lt;a href=&quot;https://www.ddosi.org/linwinpwn&quot; _src=&quot;https://www.ddosi.org/linwinpwn&quot;&gt;https://www.ddosi.org/linwinpwn&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;img src=&quot;http://xiaodi8.com/zb_users/upload/2023/04/202304091681033049185139.png&quot; alt=&quot;image.png&quot;/&gt;&lt;/p&gt;</description><pubDate>Sun, 09 Apr 2023 17:36:57 +0800</pubDate></item><item><title>VeinMind Tools镜像&amp;amp;容器漏描</title><link>http://xiaodi8.com/?id=322</link><description>&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;VeinMind Tools简介&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;veinmind中文名为&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;问脉&lt;/span&gt;，寓意&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;容器安全见筋脉，望闻问切治病害。&lt;/span&gt;&amp;nbsp;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;mark class=&quot;has-inline-color&quot; style=&quot;box-sizing: inherit; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; color: rgb(250, 2, 2);&quot;&gt;旨在成为云原生领域的一剂良方&lt;/mark&gt;&lt;/span&gt;.&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;问脉是是由长亭科技自研，基于&amp;nbsp;&lt;a href=&quot;https://github.com/chaitin/libveinmind&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;veinmind-sdk&amp;nbsp;(opens new window)&lt;/a&gt;打造的容器安全工具集，目前已支持镜像恶意文件、后门、敏感信息、弱口令等扫描功能.&lt;/p&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E5%8A%9F%E8%83%BD%E7%89%B9%E6%80%A7&quot; ez-toc-data-id=&quot;#功能特性&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;功能特性&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;支持以平行容器模式部署，开箱即用.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;支持与多种容器运行时无缝衔接&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;支持多维度威胁风险检测&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;目前已支持的检测插件如下&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;p&gt;&lt;/p&gt;&lt;figure class=&quot;wp-block-table&quot; style=&quot;box-sizing: inherit; margin: 1em 0px 1.5em; max-width: 100%; overflow-x: auto; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;table width=&quot;703&quot;&gt;&lt;thead style=&quot;box-sizing: inherit; border-bottom: 3px solid;&quot;&gt;&lt;tr style=&quot;box-sizing: inherit;&quot; class=&quot;firstRow&quot;&gt;&lt;th style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial; font-weight: 400; text-align: initial; background: rgba(0, 0, 0, 0.05);&quot;&gt;插件&lt;/th&gt;&lt;th style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial; font-weight: 400; text-align: initial; background: rgba(0, 0, 0, 0.05);&quot;&gt;功能&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody style=&quot;box-sizing: inherit;&quot;&gt;&lt;tr style=&quot;box-sizing: inherit;&quot;&gt;&lt;td style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial;&quot;&gt;&lt;a href=&quot;https://github.com/chaitin/veinmind-tools/tree/master/plugins/go/veinmind-malicious&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;veinmind-malicious(opens new window)&lt;/a&gt;&lt;/td&gt;&lt;td style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial;&quot;&gt;扫描镜像中的&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;mark class=&quot;has-inline-color&quot; style=&quot;box-sizing: inherit; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; color: rgb(250, 4, 4);&quot;&gt;恶意文件&lt;/mark&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style=&quot;box-sizing: inherit;&quot;&gt;&lt;td style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial;&quot;&gt;&lt;a href=&quot;https://github.com/chaitin/veinmind-tools/tree/master/plugins/go/veinmind-weakpass&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;veinmind-weakpass(opens new window)&lt;/a&gt;&lt;/td&gt;&lt;td style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial;&quot;&gt;扫描镜像中的弱口令&lt;/td&gt;&lt;/tr&gt;&lt;tr style=&quot;box-sizing: inherit;&quot;&gt;&lt;td style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial;&quot;&gt;&lt;a href=&quot;https://github.com/chaitin/veinmind-tools/tree/master/plugins/python/veinmind-sensitive&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;veinmind-sensitive(opens new window)&lt;/a&gt;&lt;/td&gt;&lt;td style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial;&quot;&gt;扫描镜像中的敏感信息&lt;/td&gt;&lt;/tr&gt;&lt;tr style=&quot;box-sizing: inherit;&quot;&gt;&lt;td style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial;&quot;&gt;&lt;a href=&quot;https://github.com/chaitin/veinmind-tools/tree/master/plugins/python/veinmind-backdoor&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;veinmind-backdoor(opens new window)&lt;/a&gt;&lt;/td&gt;&lt;td style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial;&quot;&gt;扫描镜像中的&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;mark class=&quot;has-inline-color&quot; style=&quot;box-sizing: inherit; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; color: rgb(248, 4, 4);&quot;&gt;后门&lt;/mark&gt;&lt;/span&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style=&quot;box-sizing: inherit;&quot;&gt;&lt;td style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial;&quot;&gt;&lt;a href=&quot;https://github.com/chaitin/veinmind-tools/tree/master/plugins/python/veinmind-history&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;veinmind-history(opens new window)&lt;/a&gt;&lt;/td&gt;&lt;td style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial;&quot;&gt;扫描镜像中的异常历史命令&lt;/td&gt;&lt;/tr&gt;&lt;tr style=&quot;box-sizing: inherit;&quot;&gt;&lt;td style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial;&quot;&gt;&lt;a href=&quot;https://github.com/chaitin/veinmind-tools/tree/master/plugins/go/veinmind-asset&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;veinmind-asset(opens new window)&lt;/a&gt;&lt;/td&gt;&lt;td style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial;&quot;&gt;扫描镜像中的资产信息&lt;/td&gt;&lt;/tr&gt;&lt;tr style=&quot;box-sizing: inherit;&quot;&gt;&lt;td style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial;&quot;&gt;&lt;a href=&quot;https://github.com/chaitin/veinmind-tools/tree/master/plugins/go/veinmind-webshell&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;veinmind-asset(opens new window)&lt;/a&gt;&lt;/td&gt;&lt;td style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial;&quot;&gt;扫描镜像中的 webshell&lt;/td&gt;&lt;/tr&gt;&lt;tr style=&quot;box-sizing: inherit;&quot;&gt;&lt;td style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial;&quot;&gt;&lt;a href=&quot;https://github.com/chaitin/veinmind-tools/tree/master/plugins/go/veinmind-escalate&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;veinmind-escalate(opens new window)&lt;/a&gt;&lt;/td&gt;&lt;td style=&quot;box-sizing: inherit; padding: 0.5em; border-color: initial;&quot;&gt;扫描镜像中的 webshell&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/figure&gt;&lt;p&gt;&lt;/p&gt;&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;h-下载地址&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;下载地址&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h3 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E2%91%A0GitHub&quot; ez-toc-data-id=&quot;#①GitHub&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;①GitHub:&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/chaitin/veinmind-tools/releases/download/v2.0.0/veinmind-webshell_linux_amd64&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;veinmind-webshell_linux_amd64&lt;/a&gt;&amp;nbsp;45.5 MB&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/chaitin/veinmind-tools/releases/download/v2.0.0/veinmind-log4j2_linux_amd64&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;veinmind-log4j2_linux_amd64&lt;/a&gt;&amp;nbsp;45.5 MB&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/chaitin/veinmind-tools/releases/download/v2.0.0/veinmind-unsafe-mount_linux_amd64&quot; style=&quot;box-sizing: inherit; background-color: transparent; outline: 0px; cursor: url(&amp;quot;https://xss2.oss-cn-beijing.aliyuncs.com/img0/2.png&amp;quot;), pointer;&quot;&gt;veinmind-unsafe-mount_linux_amd64&lt;/a&gt;45.4 MB&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/chaitin/veinmind-tools/releases/download/v2.0.0/veinmind-iac_linux_amd64&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;veinmind-iac_linux_amd64&lt;/a&gt;&amp;nbsp;53 MB&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/chaitin/veinmind-tools/archive/refs/tags/v2.0.0.zip&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Source code(zip)&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/chaitin/veinmind-tools/archive/refs/tags/v2.0.0.tar.gz&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Source code(tar.gz)&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E2%91%A1%E4%BA%91%E4%B8%AD%E8%BD%AC%E7%BD%91%E7%9B%98&quot; ez-toc-data-id=&quot;#②云中转网盘&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;②云中转网盘&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;a href=&quot;https://www.yunzhongzhuan.com/#sharefile=yMnpRHte_127247&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;yunzhongzhuan.com/#sharefile=yMnpRHte_127247&lt;br style=&quot;box-sizing: inherit;&quot;/&gt;&lt;/a&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;mark class=&quot;has-inline-color&quot; style=&quot;box-sizing: inherit; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; color: rgb(248, 0, 0);&quot;&gt;解压密码:www.ddosi.org&lt;/mark&gt;&lt;/span&gt;&lt;/p&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;云原生设施兼容性&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;h-项目地址&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E9%A1%B9%E7%9B%AE%E5%9C%B0%E5%9D%80&quot; ez-toc-data-id=&quot;#项目地址&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;项目地址:&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;GitHub:&lt;br style=&quot;box-sizing: inherit;&quot;/&gt;&lt;a href=&quot;https://github.com/chaitin/veinmind-tools&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://github.com/chaitin/veinmind-tools&lt;/a&gt;&lt;/p&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E6%96%87%E6%A1%A3%E5%9C%B0%E5%9D%80&quot; ez-toc-data-id=&quot;#文档地址&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;文档地址&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;a href=&quot;https://veinmind.chaitin.com/docs&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://veinmind.chaitin.com/docs&lt;/a&gt;&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;转载于：&lt;a href=&quot;https://www.ddosi.org/veinmind/&quot; _src=&quot;https://www.ddosi.org/veinmind/&quot;&gt;https://www.ddosi.org/veinmind/&lt;/a&gt; &lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;安装：&lt;a href=&quot;https://www.ddosi.org/veinmind/&quot; _src=&quot;https://www.ddosi.org/veinmind/&quot;&gt;https://www.ddosi.org/veinmind/&lt;/a&gt;&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;img src=&quot;http://xiaodi8.com/zb_users/upload/2023/04/202304091681032992119006.png&quot; alt=&quot;image.png&quot;/&gt;&lt;/p&gt;</description><pubDate>Sun, 09 Apr 2023 17:33:51 +0800</pubDate></item><item><title>3462个默认设备平台密码整理</title><link>http://xiaodi8.com/?id=321</link><description>&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;关于&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;所有默认凭据都放在一个位置，以协助蓝/红团队成员使用默认密码查找设备.&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;PS：大部分凭据是从 changeme、routersploit 和 Seclists 项目中提取的，&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;您可以使用这些工具来自动化该过程&lt;a href=&quot;https://github.com/ztgrace/changeme&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://github.com/ztgrace/changeme&lt;/a&gt;，&lt;a href=&quot;https://github.com/threat9/routersploit&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://github.com/threat9/routersploit&lt;/a&gt;（为了出色的工作）&lt;/p&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;数据来源&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/ztgrace/changeme&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Changeme&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/threat9/routersploit&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Routersploit&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/govolution/betterdefaultpasslist&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;betterdefaultpasslist&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/danielmiessler/SecLists/tree/master/Passwords/Default-Credentials&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Seclists&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://github.com/arnaudsoullie/ics-default-passwords&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;ics-default-passwords&lt;/a&gt;（感谢@noraj）&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;供应商文档/博客&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;安装&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;默认凭证备忘单可通过&lt;a href=&quot;https://pypi.org/project/defaultcreds-cheat-sheet/&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;pypi获得&lt;/a&gt;&lt;/p&gt;&lt;pre class=&quot;hljs language-ruby&quot; style=&quot;box-sizing: inherit; font-size: 0.9375rem; font-family: &amp;quot;courier 10 pitch&amp;quot;, Courier, monospace; overflow: auto; margin-top: 1.5em; margin-bottom: 1.5em; padding: 5px; max-width: 100%; border: 1px solid rgb(229, 229, 229); background-color: rgb(43, 43, 43); line-height: 1.6; color: rgb(248, 248, 242);&quot;&gt;$&amp;nbsp;pip3&amp;nbsp;install&amp;nbsp;defaultcreds-cheat-sheet$&amp;nbsp;creds&amp;nbsp;search&amp;nbsp;tomcat&lt;/pre&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;测试于&lt;/p&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;kali Linux&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Ubuntu&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h5 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.25rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E6%89%8B%E5%8A%A8%E5%AE%89%E8%A3%85&quot; ez-toc-data-id=&quot;#手动安装&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;a href=&quot;https://github.com/ihebski/DefaultCreds-cheat-sheet#manual-installation&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;手动安装&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h5&gt;&lt;pre class=&quot;hljs language-shell&quot; style=&quot;box-sizing: inherit; font-size: 0.9375rem; font-family: &amp;quot;courier 10 pitch&amp;quot;, Courier, monospace; overflow: auto; margin-top: 1.5em; margin-bottom: 1.5em; padding: 5px; max-width: 100%; border: 1px solid rgb(229, 229, 229); background-color: rgb(43, 43, 43); line-height: 1.6; color: rgb(248, 248, 242);&quot;&gt;$&amp;nbsp;git&amp;nbsp;clone&amp;nbsp;&amp;nbsp;
$&amp;nbsp;pip3&amp;nbsp;install&amp;nbsp;-r&amp;nbsp;requirements.txt
$&amp;nbsp;cp&amp;nbsp;creds&amp;nbsp;/usr/bin/&amp;nbsp;&amp;amp;&amp;amp;&amp;nbsp;chmod&amp;nbsp;+x&amp;nbsp;/usr/bin/creds
$&amp;nbsp;creds&amp;nbsp;search&amp;nbsp;tomcat&lt;/pre&gt;&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;h-文件下载地址&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;文件下载地址&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;h-项目地址&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;项目地址&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;GitHub:&lt;br style=&quot;box-sizing: inherit;&quot;/&gt;&lt;a href=&quot;https://github.com/ihebski/DefaultCreds-cheat-sheet&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://github.com/ihebski/DefaultCreds-cheat-sheet&lt;/a&gt;&lt;/p&gt;&lt;h3 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E2%91%A0GitHub&quot; ez-toc-data-id=&quot;#①GitHub&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;①GitHub:&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;a href=&quot;https://github.com/ihebski/DefaultCreds-cheat-sheet/blob/main/DefaultCreds-Cheat-Sheet.csv&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;DefaultCreds-Cheat-Sheet.csv&lt;/a&gt;&lt;/p&gt;&lt;h3 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E2%91%A1%E4%BA%91%E4%B8%AD%E8%BD%AC%E4%B8%8B%E8%BD%BD%E5%9C%B0%E5%9D%80&quot; ez-toc-data-id=&quot;#②云中转下载地址&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;②云中转下载地址&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;a href=&quot;https://www.yunzhongzhuan.com/#sharefile=j3uWz9Og_128043&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;yunzhongzhuan.com/#sharefile=j3uWz9Og_128043&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;img src=&quot;http://xiaodi8.com/zb_users/upload/2023/04/202304091681032777763887.png&quot; alt=&quot;image.png&quot;/&gt;&lt;/p&gt;</description><pubDate>Sun, 09 Apr 2023 17:31:36 +0800</pubDate></item><item><title>fuzz4bounty漏洞赏金猎人优秀字典列表</title><link>http://xiaodi8.com/?id=320</link><description>&lt;p&gt;&lt;br/&gt;&lt;img src=&quot;http://xiaodi8.com/zb_users/upload/2023/04/202304091681032637459014.png&quot; alt=&quot;image.png&quot;/&gt;&lt;/p&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;fuzz4bounty漏洞赏金猎人优秀字典列表&lt;/h2&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;下载地址&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;h3 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E2%91%A0GitHub&quot; ez-toc-data-id=&quot;#①GitHub&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;①GitHub&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;a href=&quot;https://github.com/0xPugazh/fuzz4bounty/archive/refs/heads/master.zip&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;github.com/0xPugazh/fuzz4bounty.zip&lt;/a&gt;&lt;/p&gt;&lt;h3 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.5rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E2%91%A1%E4%BA%91%E4%B8%AD%E8%BD%AC%E7%BD%91%E7%9B%98&quot; ez-toc-data-id=&quot;#②云中转网盘&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;②云中转网盘:&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h3&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;a href=&quot;https://www.yunzhongzhuan.com/#sharefile=PiRYZPkh_135179&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;yunzhongzhuan.com/#sharefile=PiRYZPkh_135179&lt;br style=&quot;box-sizing: inherit;&quot;/&gt;&lt;/a&gt;解压密码:www.ddosi.org&lt;/p&gt;&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;h-项目地址&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E9%A1%B9%E7%9B%AE%E5%9C%B0%E5%9D%80&quot; ez-toc-data-id=&quot;#项目地址&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;项目地址&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;GitHub:&lt;br style=&quot;box-sizing: inherit;&quot;/&gt;&lt;a href=&quot;https://github.com/0xPugazh/fuzz4bounty&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;https://github.com/0xPugazh/fuzz4bounty&lt;/a&gt;&lt;/p&gt;</description><pubDate>Sun, 09 Apr 2023 17:29:11 +0800</pubDate></item><item><title>BlueTeam-Tools 蓝队防守及应急响应工具清单</title><link>http://xiaodi8.com/?id=319</link><description>&lt;h1 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 2.25rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;img src=&quot;http://xiaodi8.com/zb_users/upload/2023/04/202304091681032510172182.png&quot; alt=&quot;image.png&quot;/&gt;&lt;/h1&gt;&lt;h1 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 2.25rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;工具清单&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h1&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E8%93%9D%E9%98%9F%E6%8A%80%E5%B7%A7-4%E4%B8%AA%E6%8A%80%E5%B7%A7&quot; ez-toc-data-id=&quot;#蓝队技巧-4个技巧&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;蓝队技巧&lt;/span&gt;-4个技巧&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#payload-extraction-with-process-hacker&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;使用 Process Hacker&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&amp;nbsp;@embee_research提取有效载荷&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#prevent-script-execution-via-double-click&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;通过双击&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;默认应用程序 GPO 更改防止脚本执行&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#detect-cryptojacking-malware-with-proxy-logs&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;使用代理日志检测 Cryptojacking 恶意软件&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;Dave Mckay&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#remove-null-bytes-in-cyberchef-malware-analysis&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;删除 CyberChef 恶意软件分析中的空字节&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;@Securityinbits&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E7%BD%91%E7%BB%9C%E6%8E%A2%E6%B5%8B%E5%92%8C%E5%8F%91%E7%8E%B0-6%E4%B8%AA%E5%B7%A5%E5%85%B7&quot; ez-toc-data-id=&quot;#网络探测和发现-6个工具&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;网络探测和发现&lt;/span&gt;-6个工具&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#nmap&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Nmap&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;网络扫描仪&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#nuclei&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;nuclei&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;漏洞扫描器&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#masscan&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Masscan&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;快速网络扫描仪&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#angry-ip-scanner&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Angry IP Scanner&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&amp;nbsp;IP/端口扫描器&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#zmap&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;ZMap&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;大型网络扫描仪&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#shodan&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Shodan&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;面向互联网的资产搜索引擎&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E6%BC%8F%E6%B4%9E%E7%AE%A1%E7%90%86-4%E7%A7%8D%E5%B7%A5%E5%85%B7&quot; ez-toc-data-id=&quot;#漏洞管理-4种工具&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;漏洞管理&lt;/span&gt;-4种工具&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#openvas&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;OpenVAS&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;开源漏洞扫描器&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#nessus-essentials&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Nessus Essentials&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;漏洞扫描器&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#nexpose&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Nexpose&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;漏洞管理工具&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#hackerone&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;HackerOne&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;漏洞赏金管理平台&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E5%AE%89%E5%85%A8%E7%9B%91%E6%8E%A7-10%E4%B8%AA%E5%B7%A5%E5%85%B7&quot; ez-toc-data-id=&quot;#安全监控-10个工具&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;安全监控&lt;/span&gt;-10个工具&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#sysmon&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;适用于 Windows 的Sysmon&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;系统监视器&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#kibana&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Kibana&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;数据可视化和探索&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#logstash&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Logstash&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;数据收集和处理&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#parsedmarc&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;parsedmarc&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&amp;nbsp;Email DMARC 数据可视化&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#phishing-catcher&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;使用 Certstream 的&lt;/em&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#phishing-catcher&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;网络钓鱼捕手&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#maltrail&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;maltrail&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;恶意流量检测系统&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#autorunstowineventlog&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;AutorunsToWinEventLog&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&amp;nbsp;Windows 自动运行事件分析器&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#procfilter&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;procfilter&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&amp;nbsp;YARA 集成进程拒绝框架&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#velociraptor&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#velociraptor&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;velociraptor&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;可见性和收集工具&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#sysmonsearch&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;SysmonSearch&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&amp;nbsp;Sysmon 事件日志可视化&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E5%A8%81%E8%83%81%E5%B7%A5%E5%85%B7%E5%92%8C%E6%8A%80%E6%9C%AF-11%E4%B8%AA%E5%B7%A5%E5%85%B7&quot; ez-toc-data-id=&quot;#威胁工具和技术-11个工具&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;威胁工具和技术&lt;/span&gt;-11个工具&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#lolbas-projectgithubio&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;lolbas-project.github.io&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&amp;nbsp;Living Off The Land Windows 二进制文件&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#gtfobinsgithubio&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;gtfobins.github.io&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&amp;nbsp;Living Off The Land Linux 二进制文件&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#filesecio&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;filesec.io&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;攻击者文件扩展名&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#kql-search&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#kql-search&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;KQL Search&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;KQL 查询聚合器&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#unprotect-project&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Unprotect Project&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;恶意软件规避技术知识库&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#chainsaw&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#chainsaw&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;chainsaw&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;快速 Windows 取证文物搜索器&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#freq&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;freq&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;域生成算法恶意软件检测&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#yargen&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;yarGen&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&amp;nbsp;YARA 规则生成器&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#emailanalyzer&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;EmailAnalyzer&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;可疑邮件分析器&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#vcg&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;VCG&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&amp;nbsp;Code安全扫描工具&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#cyberchef&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;CyberChef&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&amp;nbsp;GCHQ 在线数据操作平台&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E5%A8%81%E8%83%81%E6%83%85%E6%8A%A5-4%E4%B8%AA%E5%B7%A5%E5%85%B7&quot; ez-toc-data-id=&quot;#威胁情报-4个工具&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;威胁情报&lt;/span&gt;-4个工具&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#maltego&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Maltego&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;威胁情报平台&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#misp&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;MISP&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;恶意软件信息共享平台&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#threatconnect&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;ThreatConnect&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;威胁数据聚合&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#adversary-emulation-library&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Adversary Emulation Library&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;一个开放的对手仿真计划库&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E4%BA%8B%E4%BB%B6%E5%93%8D%E5%BA%94%E8%AE%A1%E5%88%92-5%E7%A7%8D%E5%B7%A5%E5%85%B7&quot; ez-toc-data-id=&quot;#事件响应计划-5种工具&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;事件响应计划&lt;/span&gt;-5种工具&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#nist&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;NIST&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;网络安全框架&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#incident-response-plan&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;事件响应的&lt;/em&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#incident-response-plan&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;事件响应计划框架&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#ransomware-response-plan&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;用于勒索软件响应的勒索软件响应计划&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;框架&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#incident-response-reference-guide&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;事件响应参考指南&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;事件准备指导文件&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#awesome-incident-response&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Awesome Incident Response&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;事件响应工具列表&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E6%81%B6%E6%84%8F%E8%BD%AF%E4%BB%B6%E6%A3%80%E6%B5%8B%E5%92%8C%E5%88%86%E6%9E%90-11_%E7%A7%8D%E5%B7%A5%E5%85%B7&quot; ez-toc-data-id=&quot;#恶意软件检测和分析-11_种工具&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;恶意软件检测和分析&lt;/span&gt;-11 种工具&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#virustotal&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;VirusTotal&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;恶意 IOC 共享平台&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#ida&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;IDA&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;恶意软件反汇编器和调试器&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#ghidra&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Ghidra&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;恶意软件逆向工程工具&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#decode-vbe&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;decode-vbe&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;编码的 VBE 脚本解码器&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#pafish&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;pafish&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;虚拟机沙盒检测器&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#lookyloo&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;lookyloo&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;钓鱼域名映射&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#yara&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;通过模式匹配识别&lt;/em&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#yara&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;YARA恶意软件&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#cuckoo-sandbox&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Cuckoo Sandbox&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;恶意软件分析沙箱&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#radare2&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Radare2&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;逆向工程框架&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#dnspy&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;dnSpy&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&amp;nbsp;.NET 调试器和汇编编辑器&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#malware-traffic-analysisnet&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;malware-traffic-analysis.net&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;恶意软件和数据包捕获示例&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E6%95%B0%E6%8D%AE%E6%81%A2%E5%A4%8D-3%E4%B8%AA%E5%B7%A5%E5%85%B7&quot; ez-toc-data-id=&quot;#数据恢复-3个工具&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;数据恢复&lt;/span&gt;-3个工具&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#recuva&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Recuva&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;文件恢复&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#extundelete&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Extundelete&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&amp;nbsp;Ext3 或 ext4 分区恢复&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#testdisk&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;TestDisk&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;数据恢复&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E6%95%B0%E5%AD%97%E5%8F%96%E8%AF%81-3%E4%B8%AA%E5%B7%A5%E5%85%B7&quot; ez-toc-data-id=&quot;#数字取证-3个工具&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;数字取证&lt;/span&gt;-3个工具&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#sans-sift&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;SANS SIFT&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;取证工具包&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#the-sleuth-kit&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;The Sleuth Kit&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&amp;nbsp;Disk 图像分析工具&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#autopsy&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#autopsy&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Autopsy&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;数字取证平台&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E5%AE%89%E5%85%A8%E6%84%8F%E8%AF%86%E5%9F%B9%E8%AE%AD-3%E4%B8%AA%E5%B7%A5%E5%85%B7&quot; ez-toc-data-id=&quot;#安全意识培训-3个工具&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;安全意识培训&lt;/span&gt;-3个工具&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#tryhackme&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;TryHackMe&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;网络安全挑战平台&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#hackthebox&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;HackTheBox&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;网络安全挑战平台&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#phishme&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;PhishMe&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;网络钓鱼培训&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2 class=&quot;wp-block-heading&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span class=&quot;ez-toc-section&quot; id=&quot;%E6%B2%9F%E9%80%9A%E4%B8%8E%E5%8D%8F%E4%BD%9C-2%E4%B8%AA%E5%B7%A5%E5%85%B7&quot; ez-toc-data-id=&quot;#沟通与协作-2个工具&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;box-sizing: inherit;&quot;&gt;沟通与协作&lt;/span&gt;-2个工具&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;ul style=&quot;box-sizing: border-box; margin-top: 1.5em; margin-bottom: 1.5em; padding: 0px 0px 0px 1.25em; list-style-position: initial; list-style-image: initial; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot; class=&quot; list-paddingleft-2&quot;&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#twitter&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Twitter&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;网络安全帐户&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;a href=&quot;https://github.com/A-poc/BlueTeam-Tools#facebook-theatexchange&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;Facebook TheatExchange&lt;/a&gt;&lt;/span&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;恶意指标分享平台&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;br/&gt;&lt;/p&gt;</description><pubDate>Sun, 09 Apr 2023 17:28:00 +0800</pubDate></item><item><title>Kali Linux 2023.1发布-10周年版</title><link>http://xiaodi8.com/?id=318</link><description>&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;Kali Linux 2023.1 发布（Kali Purple 和 Python 变更）&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;10th anniversary&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;今天我们发布了 Kali 2023.1（也是我们&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;10 周年&lt;/span&gt;-2023 年 3 月 13 日，星期一）！当您读完这篇文章时，它就可以立即&lt;a href=&quot;https://www.kali.org/get-kali/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;下载&lt;/a&gt;或&lt;a href=&quot;https://www.kali.org/docs/general-use/updating-kali/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;更新了。&lt;/a&gt;&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;鉴于我们成立 10 周年，我们很高兴地宣布，我们准备了一些特别的东西来庆祝。&lt;a href=&quot;https://www.timeanddate.com/countdown/birthday?iso=20230315T12&amp;p0=%3A&amp;msg=Kali+10+Years&amp;font=cursive&amp;csz=1#&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;请继续关注2023 年 3 月 15 日星期三&lt;/a&gt;12:00:00&amp;nbsp;&lt;a href=&quot;https://time.is/UTC&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;UTC/+0 GMT&lt;/a&gt;发布的博文，了解更多信息！&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;Kali Linux 2023.1 发布（Kali Purple 和 Python 变更）&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;10th anniversary&lt;/span&gt;&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;今天我们发布了 Kali 2023.1（也是我们&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;10 周年&lt;/span&gt;-2023 年 3 月 13 日，星期一）！当您读完这篇文章时，它就可以立即&lt;a href=&quot;https://www.kali.org/get-kali/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;下载&lt;/a&gt;或&lt;a href=&quot;https://www.kali.org/docs/general-use/updating-kali/&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;更新了。&lt;/a&gt;&lt;/p&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;鉴于我们成立 10 周年，我们很高兴地宣布，我们准备了一些特别的东西来庆祝。&lt;a href=&quot;https://www.timeanddate.com/countdown/birthday?iso=20230315T12&amp;p0=%3A&amp;msg=Kali+10+Years&amp;font=cursive&amp;csz=1#&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;请继续关注2023 年 3 月 15 日星期三&lt;/a&gt;12:00:00&amp;nbsp;&lt;a href=&quot;https://time.is/UTC&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot; style=&quot;box-sizing: inherit; background-color: transparent;&quot;&gt;UTC/+0 GMT&lt;/a&gt;发布的博文，了解更多信息！&lt;/p&gt;&lt;h2 class=&quot;wp-block-heading&quot; id=&quot;kali-purple&quot; style=&quot;box-sizing: inherit; clear: both; margin-top: 0.75em; margin-bottom: 0.75em; line-height: 1.4; font-size: 1.75rem; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;Kali Purple&lt;span class=&quot;ez-toc-section-end&quot; style=&quot;box-sizing: inherit;&quot;&gt;&lt;/span&gt;&lt;/h2&gt;&lt;blockquote class=&quot;wp-block-quote&quot; style=&quot;box-sizing: border-box; margin: 1.5em 0px; padding-left: 1.25em; border-left-width: 3px; border-left-style: solid; border-color: var(--light-border-color); color: var(--medium-text-color); font-size: 1.125rem; overflow-wrap: break-word; font-family: Oxygen, arial, helvetica, sans-serif; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 0.5em;&quot;&gt;&lt;em style=&quot;box-sizing: inherit;&quot;&gt;&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;我们正在公平竞争&lt;/span&gt;！&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p style=&quot;box-sizing: inherit; margin-top: 1.5em; margin-bottom: 1.5em; color: rgb(0, 128, 0); font-family: Oxygen, arial, helvetica, sans-serif; font-size: 16px; white-space: normal; background-color: rgb(255, 255, 255);&quot;&gt;多年来，我们已经完善了我们的专长，即进攻性安全。&lt;span style=&quot;box-sizing: inherit; font-weight: 700;&quot;&gt;&lt;mark class=&quot;has-inline-color&quot; style=&quot;box-sizing: inherit; background-image: initial; background-position: initial; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; color: rgb(247, 6, 6);&quot;&gt;我们现在开始涉足一个新领域，防御性安全！&lt;/mark&gt;&lt;/span&gt;我们正在进行“Kali Purple”的初步技术预览预发布。这仍处于起步阶段，需要时间才能成熟。但是你可以开始看到 Kali 正在扩展的方向。您也可以成为帮助塑造方向的一部分！&lt;/p&gt;&lt;p&gt;&lt;img src=&quot;http://xiaodi8.com/zb_users/upload/2023/04/202304091681032428108527.png&quot; alt=&quot;image.png&quot;/&gt;&lt;img src=&quot;http://xiaodi8.com/zb_users/upload/2023/04/202304091681032440379715.png&quot; alt=&quot;image.png&quot;/&gt;&lt;/p&gt;</description><pubDate>Sun, 09 Apr 2023 17:26:35 +0800</pubDate></item></channel></rss><!--1,044.15 ms , 7 query , 1955kb memory , 0 error-->