<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/Mzk2NDg3Mzk2OQ.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Fri, 11 Jul 2025 23:40:05 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>服务器端原型污染：安全的黑盒检测</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483992&amp;idx=1&amp;sn=cbe726eeb0a99e1ccf93acbd787a8f12</link><description>原型链污染漏洞及安全检测的方法介绍</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-07-11T18:01:17</pubDate></item><item><title>Dirty Vanity：一种新的代码注入与绕过EDR的方法</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483967&amp;idx=1&amp;sn=948bd1b84c9d7111bb5e61747130efdb</link><description>使用Dirty Vanity绕过EDR防护</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-05-14T19:15:11</pubDate></item><item><title>使用GhostTask生成计划任务</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483955&amp;idx=1&amp;sn=36948425a2b752e46e251701ae0c9d16</link><description>使用GhostTask实现篡改计划任务，植入隐藏后门。</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-04-29T20:30:14</pubDate></item><item><title>篡改计划任务</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483950&amp;idx=1&amp;sn=f44c4eb12ab19c451a14e5437ff0a100</link><description>绕过ETW篡改计划任务实现持久化</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-04-28T00:08:35</pubDate></item><item><title>RAG 受到攻击：LLM 漏洞如何影响真实系统</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483926&amp;idx=1&amp;sn=e08a8201fa29f7036f0c0217d786c06f</link><description>通过重点介绍检索增强生成（RAG）来深入探讨这种漏洞在实际系统中的表现</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-04-21T21:31:46</pubDate></item><item><title>从零开始打造一个超级AI红队队员：零日计划</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483914&amp;idx=1&amp;sn=bef301c686dcd29f9b693ed169b74e98</link><description>本系列文章将探讨人工智能红队测试所面临的挑战，传统安全方法为何失效，以及打造一个超越人类专家的人工智能红队队员</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-04-21T08:01:08</pubDate></item><item><title>T1048-通过替代协议进行数据渗出</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483906&amp;idx=1&amp;sn=b87286949f49d71f3445c1e9dcc9265b</link><description>攻击者可能会通过与现有命令控制通道不同的协议来窃取数据。防守者可根据文中的技术验证实际的防护能力</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-04-18T00:15:44</pubDate></item><item><title>T1047-Windows管理规范（WMI）</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483902&amp;idx=1&amp;sn=76b8785c1cc70ee8df69a479a43d6cac</link><description>红队人员可以利用WMIC绕过限制执行系统命令，蓝队人员可根据测试项对安全能力做检查</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-04-14T23:47:41</pubDate></item><item><title>WinPwn食用指南</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483898&amp;idx=1&amp;sn=fa41bd2703ecf8ea821c275104c9c501</link><description>WinPwn，主要用于自动化 Windows 系统内部渗透测试过程，涵盖侦察和利用阶段。</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-04-12T22:51:00</pubDate></item><item><title>T1041 - 通过C2通道渗出数据</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483891&amp;idx=1&amp;sn=122dfb213e6f701e5ab05ce4bd76d4fb</link><description>本文重点介绍通过DNS请求实现数据渗出，攻击者通过将数据作为子域名向服务端请求实现数据渗出，服务端对子域名做解析还原。企业可根据本文提供的样例做参考，检测自身对DNS数据渗出的防护能力。</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-04-11T21:49:08</pubDate></item><item><title>T1036-伪装（二）</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483887&amp;idx=1&amp;sn=f8c0b4b59b524f8fb4187022a62d3e5a</link><description>红队人员可以利用伪装技术实现后门隐藏，蓝队也可借助本文检查是否能够识别对应的伪装技术</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-04-08T21:06:50</pubDate></item><item><title>T1036-伪装（一）</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483883&amp;idx=1&amp;sn=8033112b3f784599c8bd966689d31225</link><description>Atomic Red Team™是一个映射到MITRE ATT\\x26amp;CK®框架的测试库。</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-04-07T21:58:43</pubDate></item><item><title>T1027-混淆文件或信息</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483872&amp;idx=1&amp;sn=5c123d883cd040f8c2146fca44d9da8f</link><description>Atomic Red Team™是一个映射到MITRE ATT\\x26amp;CK®框架的测试库。</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-04-01T21:21:39</pubDate></item><item><title>T1021 - 远程服务</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483868&amp;idx=1&amp;sn=c01d6a8f4c47e1375b05ea70cca75650</link><description>Atomic Red Team™是一个映射到MITRE ATT\\x26amp;CK®框架的测试库。</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-27T23:24:32</pubDate></item><item><title>T1016 - 系统网络配置发现</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483859&amp;idx=1&amp;sn=5f162dc0c6591786d4ce3461732db3a0</link><description>Atomic Red Team™是一个映射到MITRE ATT\\x26amp;CK®框架的测试库。</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-26T22:16:04</pubDate></item><item><title>T1014 - rootkit</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483855&amp;idx=1&amp;sn=12f58ad56b5f6b674b3513d480e4db72</link><description>Atomic Red Team™是一个映射到MITRE ATT\\x26amp;CK®框架的测试库。</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-25T23:41:22</pubDate></item><item><title>T1006 - 直接卷访问、T1007-系统服务发现</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483851&amp;idx=1&amp;sn=165f2b81d81bd104b54fca8771e7f71c</link><description>Atomic Red Team™是一个映射到MITRE ATT\\x26amp;CK®框架的测试库。</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-24T23:36:39</pubDate></item><item><title>T1005 - 从本地系统获取数据</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483846&amp;idx=1&amp;sn=de26adf12668c92e72bbce17f246f271</link><description>Atomic Red Team™是一个映射到MITRE ATT\\x26amp;CK®框架的测试库。</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-23T21:31:56</pubDate></item><item><title>逐步突破大语言模型限制</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483842&amp;idx=1&amp;sn=4517fa1c740d9f4a97aad6ce14c6027e</link><description>逐步突破大语言模型限制</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-20T23:11:04</pubDate></item><item><title>T1003.008 - 操作系统凭证转储：/etc/passwd、/etc/master.passwd和/etc/shadow</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483827&amp;idx=1&amp;sn=a8807a8139eff16461f39c5a4761e4f6</link><description>Atomic Red Team™是一个映射到MITRE ATT\\x26amp;CK®框架的测试库。</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-19T23:20:50</pubDate></item><item><title>大语言模型红队测试：全面的分步指南</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483823&amp;idx=1&amp;sn=10384908ebba7c3ceef13498d7cba52d</link><description>大语言模型红队测试：分步测试指南</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-18T22:04:13</pubDate></item><item><title>T1003.007 - 操作系统凭证转储：Proc文件系统</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483812&amp;idx=1&amp;sn=2cb446a38111625b37605684812763b7</link><description>T1003.007 - 操作系统凭证转储：Proc文件系统</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-17T22:41:17</pubDate></item><item><title>T1003.005、006 - 缓存的域凭证、DCSync</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483808&amp;idx=1&amp;sn=12cff563d906f9980f915918f10eafa3</link><description>T1003.005、006 - 缓存的域凭证、DCSync</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-16T23:09:27</pubDate></item><item><title>T1003.003 - 操作系统凭证转储：NTDS</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483804&amp;idx=1&amp;sn=ae4b7d1c90c0247bc2826744c794203a</link><description>T1003.003 - 操作系统凭证转储：NTDS</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-14T22:52:06</pubDate></item><item><title>T1003.004 - 操作系统凭证转储：LSA机密</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483804&amp;idx=2&amp;sn=ad6bb3db18e89f524c6add65698a3b81</link><description>T1003.004 - 操作系统凭证转储：LSA机密</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-14T22:52:06</pubDate></item><item><title>T1003.002 - 操作系统凭证转储：安全账户管理器</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483798&amp;idx=1&amp;sn=c53023c59a59c6c01c2769b4b5bd6960</link><description>T1003.002 - 操作系统凭证转储：安全账户管理器</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-13T20:49:42</pubDate></item><item><title>探索红队基础设施构建艺术 —《Red-Team-Infrastructure》</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483794&amp;idx=1&amp;sn=36555b0b7f43d5f414a9c89ea94fe65a</link><description>探索红队基础设施构建艺术 —《Red-Team-Infrastructure》</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-12T20:25:13</pubDate></item><item><title>15 种绕过 PowerShell 执行策略的方法</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483789&amp;idx=1&amp;sn=99aeef6dcc315c89c4c8bff2ba8c180d</link><description>15 种绕过 PowerShell 执行策略的方法</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-11T20:48:55</pubDate></item><item><title>T1003.001 - 操作系统凭证转储：LSASS进程内存</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483743&amp;idx=1&amp;sn=1daa806051bb6e412047edcbd7c41e68</link><description>T1003.001 - 操作系统凭证转储：LSASS进程内存</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-10T20:07:47</pubDate></item><item><title>T1003 - 操作系统凭证转储</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483737&amp;idx=1&amp;sn=cfe1220ced21de3ca55646f8eef8d834</link><description>Atomic Red Team：T1003 - 操作系统凭证转储</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-06T23:44:11</pubDate></item><item><title>Jenkins CVE-2024-43044 漏洞分析</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483733&amp;idx=1&amp;sn=f184844b23a39f716270fbd3b5107928</link><description>Jenkins CVE-2024-43044 漏洞分析</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-05T23:49:02</pubDate></item><item><title>T1001.002 - 通过隐写术进行数据混淆</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483720&amp;idx=1&amp;sn=82ed4f652982a3b8ca72cdd512beb1dc</link><description>Atomic Red Team™ T001.002</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-03-04T23:49:05</pubDate></item><item><title>用于检测工程的Kerberos攻击技术</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483714&amp;idx=1&amp;sn=d7333efc033b369289224c614ded2ce1</link><description></description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-02-28T20:53:34</pubDate></item><item><title>大语言模型（LLM）渗透测试入门</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483665&amp;idx=1&amp;sn=6c92aa52c3024adb084d089dea219e0f</link><description>破解 AI 的艺术：利用大型语言模型</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-02-24T23:17:01</pubDate></item><item><title>云渗透测试（路线图）成长之路</title><link>https://mp.weixin.qq.com/s?__biz=Mzk2NDg3Mzk2OQ==&amp;mid=2247483653&amp;idx=1&amp;sn=2f7b069300d32f819a7fb71447e9427c</link><description>云渗透测试（路线图）成长之路</description><author>网空安全手札</author><category>网空安全手札</category><pubDate>2025-02-23T23:25:28</pubDate></item></channel></rss>