<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/MzUyNTUyNTA5OQ.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Thu, 13 Nov 2025 18:37:18 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>安全架构师的自我修炼：从原则到实践</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485934&amp;idx=1&amp;sn=5c78e9eb82a58938bd5c0c64be2aa748</link><description>啊呸，就你也敢叫安全架构师？！</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-11-13T16:00:53</pubDate></item><item><title>K8s集群入侵排查技巧</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485929&amp;idx=1&amp;sn=99a3600432eae6b0062be56500e04199</link><description>本文我们将来解析一些 K8s 集群入侵排查技巧， 帮助大家快速找到攻击者的入侵痕迹，还原攻击路径，更高效地进行问题排查。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-11-13T11:34:07</pubDate></item><item><title>《云原生安全攻防》-- K8s集群安全事件响应</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485905&amp;idx=1&amp;sn=8dba72c85d854a5115877f717fdf1b8e</link><description>在本节视频中，我们将一起来探讨K8s集群安全事件响应的最佳实践，帮助大家更好地保护K8s环境的安全！</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-11-09T19:51:21</pubDate></item><item><title>【云安全】云数据库安全实操解析：传统风险与平台隐患并存</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485873&amp;idx=1&amp;sn=b223053e6a461319c5dce7aa5f7ba2d5</link><description>云数据库是云计算时代的核心基础设施之一，但其安全风险并不因“上云”而消失。本文以阿里云RDS为例，从访问方式配置、弱口令、注入风险、AccessKey 泄露等多个维度，系统总结了云数据库面临的传统与云平台通用型安全问题。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-07-25T07:42:48</pubDate></item><item><title>【云安全】云服务器ECS攻防剖析：从元数据滥用到横向渗透</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485851&amp;idx=1&amp;sn=06a5be28f86d5039279e4395db1c21d5</link><description>云服务器ECS是云计算的核心组件，但其配置与权限机制一旦被滥用，可能导致严重的安全隐患。本文以阿里云为例，详述ECS元数据服务、RAM角色、STS凭证泄露的攻击路径，并演示如何通过SSRF漏洞获取临时凭证实现横向移动。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-07-24T12:02:32</pubDate></item><item><title>【云安全】对象存储安全全解析：配置误区与攻击实录</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485814&amp;idx=1&amp;sn=beb26b87d3c438c983053b36406a91c8</link><description>本文聚焦对象存储服务在云环境下的典型安全风险，从权限配置误用、Bucket接管到跨云厂商测试复现，逐一揭示可能被低估的攻击面。以阿里云与华为云为例，展示配置疏忽可能导致的数据泄露、服务劫持等问题，适合云上开发、安全运维与攻防从业者阅读收藏。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-07-23T07:41:36</pubDate></item><item><title>【工具二开】魔改哥斯拉：构建更隐蔽的远控框架（实践指南）</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485769&amp;idx=1&amp;sn=26e1779cab5834c3c824ee7b460c325f</link><description>本文系统讲解了对远控框架 Godzilla 进行魔改的实操流程，包括源码反编译、请求体/响应体特征伪装、通信协议自定义（JSON）、代码模板改造、拟态免杀处理，旨在提升远控通信的隐蔽性与对抗性，为攻防实战中的 C2 通信提供定制化解决方案。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-07-22T10:34:46</pubDate></item><item><title>【工具二开】魔改 Cobalt Strike 4.5 全流程实战</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485761&amp;idx=1&amp;sn=db5c43bf3b04e7899bdaf9327e084567</link><description>本文系统梳理了 Cobalt Strike 4.5 的魔改全过程，覆盖从源码反编译、暗桩清除、UI 个性化，到 Profile 定制、证书替换、Beacon 模板加密、通信路径伪装等多个关键技术点。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-07-21T11:24:09</pubDate></item><item><title>CS-PowerShell 免杀实战（万字长文详解）</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485756&amp;idx=1&amp;sn=e5d81edcbb5e92459cd68acd49032a31</link><description>本文系统梳理了 PowerShell 在红队演练与防御对抗中的使用场景、技术特性及常见检测规避方法，涵盖脚本混淆、AMSI/ETW 绕过、C# Loader 实现及 EXE 封装，旨在帮助安全研究者在合法授权环境下理解与提升攻防对抗能力。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-07-20T20:35:46</pubDate></item><item><title>五种 EXE 处理方式，突破静态查杀</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485620&amp;idx=1&amp;sn=5b13ff310ed2d1dd075eef3589420b05</link><description>本文介绍五种常用的EXE文件处理方式，用于绕过静态检测，提升免杀能力。通过对EXE文件的降熵、添加详细信息、自定义签名、花指令以及加壳脱壳等方法，帮助提升红队演练中的隐蔽性与安全测试效果。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-26T10:03:10</pubDate></item><item><title>双重防御：结合反沙箱与反调试的免杀加载策略</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485572&amp;idx=1&amp;sn=c49d309b8575a63e2dd2a32721897f6f</link><description>本文系统讲解了如何通过反沙箱与反调试手段，增强 C2 加载器在实战环境中的生存能力。通过示例演示如何集成环境探测、调试检测等逻辑，配合静态混淆技术，有效对抗自动化分析平台与手动逆向行为，提升免杀能力。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-20T12:01:00</pubDate></item><item><title>伪装大师课：用 UUID / IPv6 / MAC 混淆 Shellcode</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485570&amp;idx=1&amp;sn=1717de677cab62bb70b5d97559c0f6a3</link><description>本文聚焦于三种基于结构化格式的数据伪装技术：UUID Obfuscation、IPv6 Obfuscation、MAC Obfuscation。通过将Shellcode转换为合法格式的字符串，绕过静态检测特征，提升在C2上线阶段的免杀能力。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-20T07:12:42</pubDate></item><item><title>DLL 注入术（四）：狸猫换太子——DLL 劫持的“白加黑”策略</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485562&amp;idx=1&amp;sn=229b7474e7e7ef67de827e2020339a48</link><description>本文聚焦 DLL 劫持（DLL Hijacking）技术在红队测试中的应用，结合“白加黑”策略，通过某白程序中合法 dll 为例，详细解析了如何定位可劫持目标、构造自定义 DLL、绕过签名校验，并完成隐蔽上线。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-19T22:01:00</pubDate></item><item><title>DLL 注入术（三）：基于导入表修改的“白加黑”加载策略</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485553&amp;idx=1&amp;sn=88dd4856bbad8ec5449b1805bc0d8c64</link><description>本文介绍“白加黑”技术在红队演练中的实现原理与实战方式，重点讲解通过修改合法程序的导入表以加载自定义 DLL 的流程与工具使用方法，展示其在行为混淆与静态绕过方面的价值。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-19T12:01:59</pubDate></item><item><title>DLL 注入术（二）：三种方式，让 DLL 顺利运行起来</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485545&amp;idx=1&amp;sn=f547c1a5256dc33d99cdb93319322281</link><description>本文聚焦 Windows 环境下三种常见 DLL 执行方式：rundll32 调用、EXE 加载器加载、远程线程注入，结合加载逻辑与工程实践，展示如何在红队演练中高效、安全地触发自定义 DLL 中的功能代码。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-19T07:03:00</pubDate></item><item><title>DLL 注入术（一）：理解 DLL，掌控加载入口</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485540&amp;idx=1&amp;sn=226a92e7b10d6effe9bd3c9c5f8145f1</link><description>本文作为 DLL 注入技术专题的前置篇，围绕 DLL 基础知识、加载方式、运行原理与实际注入价值展开，辅以 rundll32 启动与自定义加载示例，为后续深入研究多种 DLL 注入手法（如 APC、反射、IAT 劫持）打下基础。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-18T22:10:00</pubDate></item><item><title>潜伏回调：APC注入在红队演练中的多样化实现</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485528&amp;idx=1&amp;sn=ad44b8df2b6194fcf4f8c3b588b92982</link><description>本文深入探讨基于 Windows 异步回调机制的 APC 注入技术，结合自身线程、合法线程、EarlyBird 及自建线程四种方式，逐一分析其在安全演练中对抗检测、提升隐蔽性的策略与效果。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-18T12:02:00</pubDate></item><item><title>远程线程注入：让别的程序替你“干活”</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485526&amp;idx=1&amp;sn=05bf7c2a22e3c095b678d9e19cf6ba06</link><description>本文系统解析远程线程注入（Remote Thread Injection）在合规攻防演练中的应用原理与实现流程，结合静态绕过、可信进程注入与行为混淆等手段，展示其作为经典注入技术在现代防御体系下依旧具备实战价值。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-18T10:02:32</pubDate></item><item><title>披着羊皮的狼：进程镂空技术在红队演练中的伪装应用</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485521&amp;idx=1&amp;sn=281db1b1b95759d12e2bd6ce5901ee7e</link><description>本文围绕 Windows 平台下的进程镂空（Process Hollowing）技术，详解其操作流程、核心API调用、典型变种（如 RunPE、Ghosting），并通过实战演示其在合规红队测试中伪装进程行为的价值与注意事项。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-17T22:01:00</pubDate></item><item><title>Inline Hook 技术：当程序“拐个弯”，你还认得它吗？</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485515&amp;idx=1&amp;sn=3ddd04b5003f1537ed85534f601149e4</link><description>本文系统介绍了 Inline Hook 技术在 Windows 安全测试中的原理与实战价值，涵盖 MinHook 框架使用、函数劫持流程及其在红队演练中的典型应用，展示其在执行流控制与行为插桩方面的独特优势。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-17T09:25:11</pubDate></item><item><title>隐身调用：动态API技术在安全测试中的攻防价值</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485504&amp;idx=1&amp;sn=d2d0061f4fc5800f04becd417df1998e</link><description>本文系统介绍了动态API调用技术在规避静态检测中的作用，通过剖析Windows导入表（IAT）机制，展示了动态解析API方式如何规避安全软件的特征识别，并结合实践演示其在合规测试中的有效性。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-16T12:03:00</pubDate></item><item><title>红队Shellcode分离加载术：把“秘密”藏在更远的地方</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485499&amp;idx=1&amp;sn=357b4dadacb8bc8f9dba04589de9025b</link><description>本文围绕 Shellcode 分离加载的核心思路，系统介绍本地文件、参数注入、远程请求等多种分阶段加载技术，并结合安全测试场景进行实践验证，帮助提升在合法演练中的抗检测能力。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-16T07:47:57</pubDate></item><item><title>红队Shellcode加密术：从裸奔到潜行，内存中的隐秘行动</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485492&amp;idx=1&amp;sn=d671d3da3d1ed878bebd44c90be1e3b9</link><description>本文介绍了各类Shellcode加密技术（如XOR、AES等）及其加载策略，强调在静态检测层面先做好加密伪装，为后续沙箱逃逸和动态防护奠定基础，适用于授权的红队演练与安全测试。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-15T11:56:37</pubDate></item><item><title>VS配置优化：编译器的一行选项，也是红队勇士的免检盒</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485484&amp;idx=1&amp;sn=a37bfaba39ec4cea49cc07281e78505d</link><description>本文具体介绍了在攻防演练中，红队如何进行VS配置优化来提升静态与动态检测规避能力。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-14T21:15:58</pubDate></item><item><title>破解迷雾：红队视角下的 C2 对抗与绕检艺术</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485475&amp;idx=1&amp;sn=f8522361abd1f3b989617b00d0cf405d</link><description>红队C2通信基础与检测链条全解析，聚焦隐蔽执行核心逻辑。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-14T15:07:38</pubDate></item><item><title>【免杀】C2免杀技术（十六）反沙箱/反调试</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485456&amp;idx=1&amp;sn=b289e460a1abfded727820d805e58b4e</link><description>反沙箱（Anti-Sandbox）和反调试（Anti-Debugging）是两种常用于恶意软件对抗分析与检测的</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-06T11:30:41</pubDate></item><item><title>【免杀】C2免杀技术（十五）shellcode混淆uuid/ipv6/mac</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485431&amp;idx=1&amp;sn=5d39ae6297b5e9f04fdb192ae070b0da</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-04T20:21:01</pubDate></item><item><title>【免杀】C2免杀技术（十四）Inline Hook</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485425&amp;idx=1&amp;sn=48b38af871291a5c3d4a94649ef4a841</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-02T10:06:07</pubDate></item><item><title>【免杀】C2免杀技术（十三）Inline Hook 前置篇</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485418&amp;idx=1&amp;sn=d0e9fee1fe9e325b0ad80445d83bf5a2</link><description>Hook技术Hook 技术是操作系统、软件开发和安全攻防中非常核心的技术手段之一。它的本质是“截获函数调用并插入自定义逻辑”。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-06-01T19:18:20</pubDate></item><item><title>【免杀】C2免杀技术（十二）DLL劫持（白加黑）</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485410&amp;idx=1&amp;sn=18639043d532e0eaa3e11878199d362f</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-05-31T12:42:52</pubDate></item><item><title>【免杀】C2免杀技术（十一）DLL导入表注入（白加黑）</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485396&amp;idx=1&amp;sn=7d2f3383448e71b0eca57d74515c6fed</link><description>白加黑“白”：指合法的、可信的、经过签名的程序（白程序），如系统自带程序、正规厂商软件等。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-05-30T21:27:55</pubDate></item><item><title>【免杀】C2免杀技术（十）DLL代码运行</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485380&amp;idx=1&amp;sn=ea7a46fce16d58faec54ace83258f7ae</link><description>一、rundll32运行dll代码rundll32.exe 是 Windows 提供的一个系统程序，专门用于调</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-05-28T21:07:24</pubDate></item><item><title>【免杀】C2免杀技术（十）DLL注入-前置篇补充</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485373&amp;idx=1&amp;sn=890b7eaa5bf0e4e3bc76b242c11a414b</link><description>一、rundll32运行dll代码rundll32.exe 是 Windows 提供的一个系统程序，专门用于调</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-05-26T22:03:09</pubDate></item><item><title>【免杀】C2免杀技术（九）DLL注入-前置篇</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485362&amp;idx=1&amp;sn=34cc68582c4174f6713665722a324011</link><description>一、什么是DLL1、DLL 是 Dynamic Link Library（动态链接库）的缩写，是 Window</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-05-25T18:09:01</pubDate></item><item><title>【免杀】C2免杀技术（八）APC注入</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485353&amp;idx=1&amp;sn=f339ba6cc4ed137d5cf900616f6faf85</link><description>APC（Asynchronous Procedure Call）注入是一种利用Windows提供的异步回调机制</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-05-23T07:40:55</pubDate></item><item><title>【免杀】C2免杀技术（七）远程线程注入</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485340&amp;idx=1&amp;sn=279543744231b9c288d631214e96dd40</link><description>远程线程注入（Remote Thread Injection）是一种常见的进程注入技术，经常用于红队渗透、恶意</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-05-20T21:43:13</pubDate></item><item><title>【免杀】C2免杀技术（六）进程镂空(傀儡进程)</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485330&amp;idx=1&amp;sn=9ca63286cf8506dcc9fa92a214cc04e1</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-05-19T22:23:44</pubDate></item><item><title>【免杀】C2免杀技术（五）动态API</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485318&amp;idx=1&amp;sn=0df7338336fc2c779507b192f0c06df8</link><description>一、什么是动态API？在C2免杀领域中，“动态API” 主要指的是绕过静态检测的一种技术手段，其本质是运行时动态</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-05-19T07:21:35</pubDate></item><item><title>【免杀】C2免杀技术（四）shellcode分离加载</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485317&amp;idx=1&amp;sn=24408252133cc8440e9bd5a9cebfb47c</link><description>前言：说到shellcode分离加载，关于Stager的概念先了解一下概念定义举例特点Stager负责“搭桥”的</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-05-18T18:03:49</pubDate></item><item><title>【免杀】C2免杀技术（二）VS设置</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485291&amp;idx=1&amp;sn=0987f273f347312b148d4db86f759495</link><description>编译器生成的二进制文件特征（代码结构、元数据、指纹）可能被杀软的静态或动态检测规则匹配。VS设置会对免杀效果产生什么影响？</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-05-17T09:27:57</pubDate></item><item><title>【免杀】C2免杀技术（一）概念篇</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485271&amp;idx=1&amp;sn=eb512940e49845c6588147b953a73867</link><description>什么是C2?免杀为什么主要针对Windows？C2有哪些核心概念？杀软的检测流程是什么？如何进行对抗？</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-05-16T22:34:08</pubDate></item><item><title>【免杀】C2免杀技术（三）shellcode加密</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485258&amp;idx=1&amp;sn=dbac32afcaaf8a712ef9d738d1bceccf</link><description>介绍shellcode加密免杀技术，shellcode加密也是shellcode混淆的一种手段...</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-05-15T22:21:31</pubDate></item><item><title>【免杀】C2免杀技术（一）VS设置</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485241&amp;idx=1&amp;sn=7fbba46bff57a9dd98422ccb92401fee</link><description>一、概述编译器生成的二进制文件特征（代码结构、元数据、指纹）可能被杀软的静态或动态检测规则匹配。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-05-12T23:24:37</pubDate></item><item><title>【免杀】C2免杀 | 概念篇</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485227&amp;idx=1&amp;sn=5ec7100fa4045fb4466298fd5bf429ab</link><description>一、什么是 C2 ?Command and Control（命令与控制）的缩写，是指攻击者用来远程控制被入侵设备（如计算机、服务器等）的通信架构。</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-05-09T19:16:52</pubDate></item><item><title>【云安全】云原生- K8S IngressNightmare CVE-2025-1974（漏洞复现完整教程）</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485213&amp;idx=1&amp;sn=0a0df376bfca8f5bbb80fd333850890a</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-04-17T11:45:04</pubDate></item><item><title>【云安全】云原生-centos7搭建/安装/部署k8s1.23.6单节点</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485198&amp;idx=1&amp;sn=3f747cf9be95588cb6a13f1f4a91374d</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-04-16T11:45:34</pubDate></item><item><title>【漏洞复现】Vite 任意文件读取系列漏洞(附POC)</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485186&amp;idx=1&amp;sn=d60c71d512d754e0c55d1747a7c9c042</link><description>2025 Vite 任意文件读取系列漏洞(附POC)</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-04-13T15:46:00</pubDate></item><item><title>【漏洞复现】Next.js中间件权限绕过漏洞 CVE-2025-29927</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485165&amp;idx=1&amp;sn=6bf8e2894f9573d36bfc7203606b2150</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-04-12T19:03:25</pubDate></item><item><title>【应急响应】某变异Webshell流量分析（玄机靶场）</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485139&amp;idx=1&amp;sn=8ff81dc457cde0e50349a54816f9b3ee</link><description>玄机靶场题目靶场链接：https://xj.edisec.net/给了附件，其它靠渗透进入1、黑客上传的木马文</description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-03-24T22:02:55</pubDate></item><item><title>【漏洞复现】Apache Tomcat 远程代码执行 CVE-2025-24813（附靶场WriteUp）</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485109&amp;idx=1&amp;sn=87a748095b42049f0404c4f132bb077f</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-03-15T11:04:05</pubDate></item><item><title>【云安全】云原生-Docker（六）Docker API 未授权访问</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485047&amp;idx=1&amp;sn=82b66b56ef4ca870654c2f11636a252d</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-02-20T09:12:21</pubDate></item><item><title>【云安全】云原生- K8S 污点横移</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247485036&amp;idx=1&amp;sn=8f42f584f4ba1bc89a31a7f5b1d5bcbf</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-02-19T09:12:04</pubDate></item><item><title>【云安全】云原生- K8S Kubelet 未授权访问</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484985&amp;idx=1&amp;sn=aa105132cdc3e4d362c479d53154963e</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-02-16T21:56:21</pubDate></item><item><title>【云安全】云原生- K8S 安装 Dashboard 面板</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484968&amp;idx=1&amp;sn=f636d1e1102975220db1b38d7b9fa9b9</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-02-16T21:24:40</pubDate></item><item><title>【云安全】云原生- K8S kubeconfig 文件泄露</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484955&amp;idx=1&amp;sn=af5c7ad9e052f035cc91b068f36ab614</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-02-16T21:05:14</pubDate></item><item><title>【云安全】云原生- K8S API Server 未授权访问</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484945&amp;idx=1&amp;sn=ffb5076d58774423d9cf136590f6adfd</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-02-16T20:28:10</pubDate></item><item><title>【AI】DeepSeek 概念/影响/使用/部署</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484881&amp;idx=1&amp;sn=1ce74fe3cc4869f130e0b068ec229f45</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-02-02T20:55:31</pubDate></item><item><title>【AI】人工智能没那么神秘！</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484879&amp;idx=1&amp;sn=5ad4a8e0fe4d3be18ea0f01e2935473f</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-02-02T20:25:07</pubDate></item><item><title>【AI】DeepSeek 概念/影响/使用/部署</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484873&amp;idx=1&amp;sn=b8520d6aae393acbc9010a4553c5b460</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-01-31T23:02:57</pubDate></item><item><title>【云安全】云原生-K8S-搭建/安装/部署</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484782&amp;idx=1&amp;sn=e915e38783585176822fe7d83b1fac60</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-01-28T21:15:34</pubDate></item><item><title>【云安全】云原生-K8S-简介</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484722&amp;idx=1&amp;sn=ba4e1e01878dddae81fa21ad3e96a91e</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-01-26T22:01:57</pubDate></item><item><title>【云安全】云原生-Docker（五）容器逃逸之漏洞利用</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484704&amp;idx=1&amp;sn=410d5b5fae6bf9431286297a0a2c6170</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-01-25T19:42:27</pubDate></item><item><title>【云安全】云原生-Docker（四）容器逃逸之危险挂载</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484600&amp;idx=1&amp;sn=76b583205f296a08e1864513322ea1f5</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-01-23T20:17:01</pubDate></item><item><title>【云安全】云原生-Docker（四）容器逃逸之危险挂载</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484598&amp;idx=1&amp;sn=1d92a77127ef91cb7bc335d442405fbd</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-01-23T20:07:02</pubDate></item><item><title>【云安全】云原生-Docker（三）容器逃逸之特权模式</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484541&amp;idx=1&amp;sn=05fbab908428816c26d2e9b6f6bf0191</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-01-22T11:05:03</pubDate></item><item><title>【云安全】云服务-对象存储-安全问题分析</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484514&amp;idx=1&amp;sn=23d5e6484feff5e17ed802e1dbadf191</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-01-21T15:06:42</pubDate></item><item><title>【云安全】云原生-Docker（二）搭建测试环境</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484509&amp;idx=1&amp;sn=767ae27a7dad867b566859e72b5a2c6e</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-01-21T14:42:06</pubDate></item><item><title>【云安全】云原生-Docker（一）安全问题概述</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484414&amp;idx=1&amp;sn=24240cde29e42a4c1d40be5dc842887c</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-01-20T21:32:17</pubDate></item><item><title>【安全研究】安全产品-堡垒机-安全问题分析</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484397&amp;idx=1&amp;sn=fd5f6433d5b4c5d79d3ba8b14ce357a4</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-01-20T16:37:09</pubDate></item><item><title>【云安全】AccessKey泄露-安全问题分析</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484392&amp;idx=1&amp;sn=c8e8b6f7c95e894a44040d9c69cdd7e6</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-01-12T21:49:47</pubDate></item><item><title>【安全产品】堡垒机-安全问题分析-漏洞复现</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484161&amp;idx=1&amp;sn=4fedc2c070e311189f636deb084deda5</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-01-11T20:39:50</pubDate></item><item><title>【云安全】云服务-云数据库-安全问题综述</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484149&amp;idx=1&amp;sn=10c443bfc643c183a0a679c54cd08a5d</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-01-11T11:58:05</pubDate></item><item><title>【云安全】云服务-云服务器ECS-安全问题分析</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484084&amp;idx=1&amp;sn=56999ea9f438281ffad8f0d920528b0a</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-01-10T18:01:13</pubDate></item><item><title>【云安全】云服务-对象存储-安全问题分析</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484022&amp;idx=1&amp;sn=768570cde6972767bbc8db3e906cabf4</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-01-09T21:34:15</pubDate></item><item><title>【云安全】云服务-对象存储-安全问题分析</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247484012&amp;idx=1&amp;sn=58d00a5be58d4ff801dee04fd330d253</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2025-01-07T20:46:54</pubDate></item><item><title>清晨同样的美</title><link>https://mp.weixin.qq.com/s?__biz=MzUyNTUyNTA5OQ==&amp;mid=2247483657&amp;idx=1&amp;sn=c32754c4ad57810b30caaac8c9b72d4e</link><description></description><author>仇辉攻防</author><category>仇辉攻防</category><pubDate>2024-12-25T08:06:55</pubDate></item></channel></rss>