<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/Mzk1NzM5MTI2Mg.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Thu, 21 Aug 2025 17:30:53 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>从进程创建到Early Cascade Injection</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484995&amp;idx=1&amp;sn=dc6c91d18d44876de08e67d3f06f128b</link><description>通过AppVerifier和ShimEnginer接口来起到一种隐蔽的起进程形式的注入。</description><author>半只红队</author><category>半只红队</category><pubDate>2025-08-21T16:00:01</pubDate></item><item><title>从Syscall到线程调用栈</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484961&amp;idx=1&amp;sn=7b5bfad998e24dea74d6dc6eeba4dfa9</link><description>Syscall 这种东西，见仁见智，不同的人，不同场景，不同EDR，不同对抗环境，效果不同 。</description><author>半只红队</author><category>半只红队</category><pubDate>2025-07-24T14:47:31</pubDate></item><item><title>避免注入链：Primitive Injection</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484892&amp;idx=1&amp;sn=b97c48f14b44444c9e2a8d98d658b620</link><description>避免注入链：Primitive Injection</description><author>半只红队</author><category>半只红队</category><pubDate>2025-06-30T14:22:36</pubDate></item><item><title>探讨进程注入：CONTEXT-Only</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484880&amp;idx=1&amp;sn=74731199fa59eb0317aea9dd541aca01</link><description>探讨进程注入：CONTEXT-Only</description><author>半只红队</author><category>半只红队</category><pubDate>2025-06-09T22:22:48</pubDate></item><item><title>【高级睡眠混淆】| 堆栈不在，何必欺骗？</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484852&amp;idx=1&amp;sn=e7f0bb8c4807d2fafea0ac5c94ca9b26</link><description>堆栈不在，何必欺骗？</description><author>半只红队</author><category>半只红队</category><pubDate>2025-05-21T23:21:46</pubDate></item><item><title>【SpoofCall】| 从栈回溯中聊聊堆栈欺骗</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484833&amp;idx=1&amp;sn=9f266618eea9764fb773328367e30295</link><description>《从栈回溯中谈谈堆栈欺骗》从基本的堆栈欺骗再到DEFCON提出的巧妙实现</description><author>半只红队</author><category>半只红队</category><pubDate>2025-05-10T14:41:09</pubDate></item><item><title>【UDRLTrick】| CS Heap Encypt实现</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484786&amp;idx=1&amp;sn=36f35d013c1880aca93afd3a61055f3d</link><description>【UDRLTrick】| CS Heap Encypt实现</description><author>半只红队</author><category>半只红队</category><pubDate>2025-04-22T12:49:28</pubDate></item><item><title>【fscan插件】| 用gokrb5构建你的fscan插件（二）</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484715&amp;idx=1&amp;sn=239a3234a80e48f67d16e56d71493e7f</link><description>【fscan插件】| 用gokrb5构建你的fscan插件（二）</description><author>半只红队</author><category>半只红队</category><pubDate>2025-04-07T10:40:20</pubDate></item><item><title>【fscan插件】| 用gokrb5构建fscan插件（一）</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484699&amp;idx=1&amp;sn=339a02d6f79f25ff9ce0a6b29c7bd3a4</link><description>【fscan插件】| 用gokrb5构建你的fscan插件</description><author>半只红队</author><category>半只红队</category><pubDate>2025-03-26T22:01:46</pubDate></item><item><title>【Fscan】|  POC与指纹编写</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484682&amp;idx=1&amp;sn=09e396d42d28ffbeff94180c181c03e9</link><description>【Fscan】|  POC与指纹编写</description><author>半只红队</author><category>半只红队</category><pubDate>2025-03-17T13:07:59</pubDate></item><item><title>【CS-BOF插件】| 移除EDR六大内核回调</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484612&amp;idx=1&amp;sn=503f344add62347234340f40c339e076</link><description>【CS-BOF插件】| 移除EDR六大内核回调</description><author>半只红队</author><category>半只红队</category><pubDate>2025-03-10T15:38:07</pubDate></item><item><title>【360过父】| 360核晶断链绕过父进程</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484581&amp;idx=1&amp;sn=840758396b6d5d6060218a1978ace5f3</link><description>【360过父】| 360核晶断链绕过父进程</description><author>半只红队</author><category>半只红队</category><pubDate>2025-03-04T19:50:50</pubDate></item><item><title>【Fscan二开】| Fscan中的瑞士军刀</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484569&amp;idx=1&amp;sn=c12b8370d1527aafba12095e7aac1710</link><description>【Fscan二开】| Fscan中的瑞士军刀</description><author>半只红队</author><category>半只红队</category><pubDate>2025-03-02T17:40:32</pubDate></item><item><title>【内核对抗】| 换个角度内核级致盲AV-EDR</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484508&amp;idx=1&amp;sn=eed57fd71be58a8a59823ac94a19479a</link><description>【内核对抗】| 换个角度内核级致盲AV-EDR</description><author>半只红队</author><category>半只红队</category><pubDate>2025-02-17T17:06:49</pubDate></item><item><title>【Win11抓不到密码?】| 内存匹配规则的添加！！</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484433&amp;idx=1&amp;sn=c880bb48a013ff14e3bab913ecbfe043</link><description>【Win11抓不到密码?】| 内存匹配规则的添加！！</description><author>半只红队</author><category>半只红队</category><pubDate>2025-02-03T23:25:04</pubDate></item><item><title>deepseek被攻击，让一篇AI科幻爽文全网一起“造假”.....爱国饭是真容易吃啊</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484414&amp;idx=1&amp;sn=e0687c1f6d62a3dcc2a187af2721c6b2</link><description>AI爽文，全网狂欢</description><author>半只红队</author><category>半只红队</category><pubDate>2025-02-01T15:56:02</pubDate></item><item><title>【CS单兵后渗透插件v1.0】| OpSec 标准下的红队武器化</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484412&amp;idx=1&amp;sn=f7e81d418014efc190a265ea5b403424</link><description>【CS单兵后渗透插件发布】| OpSec 标准下的红队武器化</description><author>半只红队</author><category>半只红队</category><pubDate>2025-01-28T22:17:04</pubDate></item><item><title>【CS武器化插件】| BOF读取ToDesk和向日葵密码信息</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484326&amp;idx=1&amp;sn=d1da617b6d8c6a19e20c3543f60afc58</link><description>【CS武器化插件】| BOF读取ToDesk和向日葵密码信息</description><author>半只红队</author><category>半只红队</category><pubDate>2025-01-24T08:02:07</pubDate></item><item><title>【永不空军！】| 360核晶等杀软环境下钓鱼思路分享</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484316&amp;idx=1&amp;sn=ab9ac916c896017f20ab1efeb8dc19cb</link><description>【钓鱼思路】| 360核晶等杀软环境下钓鱼思路分享</description><author>半只红队</author><category>半只红队</category><pubDate>2025-01-20T08:06:02</pubDate></item><item><title>【无需Patch】| 最简单最朴素绕过AMSI</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484156&amp;idx=1&amp;sn=0bd24cccc21657f0a9d4bc5832be2ea3</link><description>【无需Patch】| 最简单最朴素绕过AMSI</description><author>半只红队</author><category>半只红队</category><pubDate>2025-01-16T08:02:56</pubDate></item><item><title>【原神怎么你了】| BYOVD-击溃结束常见国产杀软</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484116&amp;idx=1&amp;sn=938506fe873a8dc0bdf5610037268530</link><description>利用某神在Ring0层结束某擎某绒某电脑管家源代码</description><author>半只红队</author><category>半只红队</category><pubDate>2025-01-12T22:11:05</pubDate></item><item><title>【新手误区】| 单exe过360核晶？？</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484033&amp;idx=1&amp;sn=f9c2658f6c936dc00ecee65660a930ad</link><description>【新手误区】| 单exe过360核晶？？</description><author>半只红队</author><category>半只红队</category><pubDate>2025-01-04T15:22:56</pubDate></item><item><title>【武器开发】| 开发你的第一个BOF</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247484006&amp;idx=1&amp;sn=4153933cdb8b7efe88bab1385806afca</link><description>【武器开发】| 开发你的第一个BOF</description><author>半只红队</author><category>半只红队</category><pubDate>2025-01-02T23:36:10</pubDate></item><item><title>【从0到1】| 绕过企业版卡巴斯基EDR内存扫描详细思路及源码</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247483939&amp;idx=1&amp;sn=a2b4cc9adb80dfba7245f6a3b12a12a8</link><description>【从0到1】| 绕过企业版卡巴斯基EDR内存扫描详细思路</description><author>半只红队</author><category>半只红队</category><pubDate>2024-12-30T08:00:08</pubDate></item><item><title>【冷饭新炒？】｜令牌移除居然还没失效</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247483915&amp;idx=1&amp;sn=18ccf27e68c9e61166bf51cae745bdf8</link><description>【冷饭新炒？】｜令牌移除居然还没失效</description><author>半只红队</author><category>半只红队</category><pubDate>2024-12-28T16:01:50</pubDate></item><item><title>【免杀加载器】| 对抗企业版卡巴斯基EDR内存扫描</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247483881&amp;idx=1&amp;sn=559674531d4a410f917e7f0b180dc0ad</link><description>【随便写一个loader】| 对抗企业版卡巴斯基内存扫描</description><author>半只红队</author><category>半只红队</category><pubDate>2024-12-27T08:30:29</pubDate></item><item><title>【杀软对抗之趣】｜ Ring3非驱动结束企业版卡巴斯基EDR</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247483866&amp;idx=1&amp;sn=6f14d8109cf9dd8d67703d4ee722144f</link><description>【杀软对抗之趣】｜ Ring3非驱动结束卡巴斯基</description><author>半只红队</author><category>半只红队</category><pubDate>2024-12-26T08:15:46</pubDate></item><item><title>【杀软对抗】| 重生之我在Ring3继续强杀天擎和杀软组件</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247483853&amp;idx=1&amp;sn=f5e17754932070b55adaf3830216a2f7</link><description>【杀软对抗】| 重生之我在Ring3继续强杀天擎和杀软组件</description><author>半只红队</author><category>半只红队</category><pubDate>2024-12-25T03:00:03</pubDate></item><item><title>【Kill !】| Ring3非驱动不重启结束V10天晴，物理机360核晶体！</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247483842&amp;idx=1&amp;sn=d64db1b0bd7d9a113edef8da9449a51e</link><description>【Kill !】| Ring3非驱动不重启结束V10天晴，物理机360核晶体！</description><author>半只红队</author><category>半只红队</category><pubDate>2024-12-23T16:38:42</pubDate></item><item><title>【强杀已死，致盲万岁！！】 | Ring3非驱动致盲360核晶全家桶 ！！</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247483820&amp;idx=1&amp;sn=b93386c3f56157dedfd61ddf4dd32cad</link><description>Ring3非驱动致盲360核晶全家桶 ！！！</description><author>半只红队</author><category>半只红队</category><pubDate>2024-12-20T15:37:46</pubDate></item><item><title>【强杀？致盲！】｜让你的火绒失去对抗病毒的能力</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247483798&amp;idx=1&amp;sn=e840d05d4d37a8f716df7ceba50bd4ec</link><description>[强杀？致盲！] ｜让你的火绒失去对抗病毒的能力</description><author>半只红队</author><category>半只红队</category><pubDate>2024-12-19T11:51:45</pubDate></item><item><title>Bypass 360物理机核晶添加用户</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247483784&amp;idx=1&amp;sn=c75ea845a96799c91499ff455c6b9807</link><description>Bypass 360物理机核晶添加用户</description><author>半只红队</author><category>半只红队</category><pubDate>2024-12-17T14:54:45</pubDate></item><item><title>基于系统调用的杀软对抗技法与完善</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247483757&amp;idx=1&amp;sn=66ee4b3104841386b013b0520f6d61b7</link><description>直接系统调用、间接系统调用及其完善</description><author>半只红队</author><category>半只红队</category><pubDate>2024-12-15T23:44:16</pubDate></item><item><title>BOF化绕过360核晶Dumplsass进程</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247483736&amp;idx=1&amp;sn=2d4dc2cf7d2f605086c59a2d098f5238</link><description>绕过实体机360核晶Dump lsass进程，全程BOF化，执行后将lsass.dmp拖到自己主机进行离线破解即可。</description><author>半只红队</author><category>半只红队</category><pubDate>2024-12-13T18:01:56</pubDate></item><item><title>BSOD权限维持 | 让你无视像卡巴斯基EDR这样强大的EDR</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247483723&amp;idx=1&amp;sn=fafe76528870669586b2b0ec13dd6603</link><description>无视像卡巴斯基EDR这样强大的EDR</description><author>半只红队</author><category>半只红队</category><pubDate>2024-12-12T20:12:10</pubDate></item><item><title>【免杀唠嗑】| DLL注入</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247483709&amp;idx=1&amp;sn=a84d3f6254e53d412881a3da9727e66e</link><description>整理了一下免杀的基础，DLL注入，虽然这个方法再实战中没啥用了是个累赘，但是这种方法还是要知道的。</description><author>半只红队</author><category>半只红队</category><pubDate>2024-12-09T18:47:36</pubDate></item><item><title>【免杀唠嗑】| 学免杀前要了解什么</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247483702&amp;idx=1&amp;sn=df65072921958c1a992cb88a7e9b66b6</link><description>这篇文章主要介绍免杀的前置知识，与其他前置知识文章不太一样，这篇文章主要告诉你，前置知识有啥。</description><author>半只红队</author><category>半只红队</category><pubDate>2024-12-08T23:26:23</pubDate></item><item><title>【免杀工具】| Bypass真实机核晶360权限维权</title><link>https://mp.weixin.qq.com/s?__biz=Mzk1NzM5MTI2Mg==&amp;mid=2247483678&amp;idx=1&amp;sn=c1802d2297de4b8977b5970b5cd88ed1</link><description>物理机Bypass 360权限维持</description><author>半只红队</author><category>半只红队</category><pubDate>2024-12-07T22:01:08</pubDate></item></channel></rss>