<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/Mzk2NDg3NTc1Mg.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Thu, 05 Mar 2026 14:06:20 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>GachiLoader：通过 API 跟踪击败 Node.js 恶意软件</title><link>https://mp.weixin.qq.com/s/7_pNaYVrnvUPSjr5YgU4Lw</link><description>GachiLoader：通过 API 跟踪击败 Node.js 恶意软件</description><author>红队工坊</author><category>红队工坊</category><pubDate>2026-03-05T10:33:38</pubDate></item><item><title>绕过杀软EDR内存扫描</title><link>https://mp.weixin.qq.com/s/ep376tna5lZX50eu5oLMfA</link><description>绕过杀软EDR内存扫描</description><author>红队工坊</author><category>红队工坊</category><pubDate>2026-02-12T16:17:08</pubDate></item><item><title>NimShellCodeLoader：基于Nim的Windows Shellcode免杀加载器</title><link>https://mp.weixin.qq.com/s/wNrl3wFBqLnL41Q-ZV84GQ</link><description>NimShellCodeLoader入选2022年KCon兵器谱</description><author>红队工坊</author><category>红队工坊</category><pubDate>2026-02-11T12:09:32</pubDate></item><item><title>AI 驱动的免杀：利用AI生成 PowerShell 混淆 Shell，Python一键搞定</title><link>https://mp.weixin.qq.com/s/wirOz97hJkKnm7dNrwW0Pw</link><description>一款基于 Python 编写的使用AI自动化生成PowerShell Payload 的工具</description><author>红队工坊</author><category>红队工坊</category><pubDate>2026-02-09T11:16:59</pubDate></item><item><title>次世代免杀shellocde加载器</title><link>https://mp.weixin.qq.com/s/S2ex-Gc7YDlplTnTT3VPlg</link><description>次世代免杀shellocde加载器</description><author>红队工坊</author><category>红队工坊</category><pubDate>2026-02-05T08:34:03</pubDate></item><item><title>深度预警 | AI Agent 门户 Clawdbot 安全风险：数百名用户服务暴露，敏感凭证面临清空风险</title><link>https://mp.weixin.qq.com/s/7GaCGlwQMg_yVKoeWwhV7A</link><description>深度预警 | AI Agent 门户 Clawdbot 安全风险：数百名用户服务暴露，敏感凭证面临清空风险</description><author>红队工坊</author><category>红队工坊</category><pubDate>2026-01-28T06:00:20</pubDate></item><item><title>PPL 滥用新路径</title><link>https://mp.weixin.qq.com/s/5FgPxXc9PJy79msvPBoEpw</link><description>PPL 滥用新路径</description><author>红队工坊</author><category>红队工坊</category><pubDate>2026-01-27T06:03:12</pubDate></item><item><title>谢邀</title><link>https://mp.weixin.qq.com/s/QgSHX_N_rZqIUUa70KF66Q</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2026-01-05T10:15:51</pubDate></item><item><title>“感冒有点严重”，雷军推迟跨年直播拆车</title><link>https://mp.weixin.qq.com/s/xA8reH9yIiX6C3GgL6laXw</link><description>12月31日上午，小米创办人、董事长兼CEO雷军发文：实在抱歉，我感冒有点严重，原定跨年的直播只能推迟到 1月</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-31T10:49:46</pubDate></item><item><title>后退的雷军和激进的小米17 Ultra</title><link>https://mp.weixin.qq.com/s/_6Lf_sXSYl8zjm2Hf9-IIg</link><description>一个没有雷军的发布会</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-30T06:00:16</pubDate></item><item><title>介绍位新朋友：N1 PRO，你最强的网络安全技术助手</title><link>https://mp.weixin.qq.com/s/WVXH3wkjrXST6_W2bhtrpg</link><description>今日凌晨，我们已经正式上线最新网安技术模型N1 PRO模型。同时也发布了无问AI mini推理模式。</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-29T06:05:54</pubDate></item><item><title>分析软件供应链攻击原理及防御工具</title><link>https://mp.weixin.qq.com/s/moBS80jWec1tCU8InsSSZQ</link><description>分析软件供应链攻击原理及防御工具</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-26T06:19:45</pubDate></item><item><title>节日快乐</title><link>https://mp.weixin.qq.com/s/SDZCLqeSR1f-vIEV85NXAA</link><description>节日快乐🎆🎄\\x26lt;a class=\\x26quot;wx_topic_link\\x26quot; topic-id=\\x26quot;mjkrr8ek-28jeeg\\x26quot; data-topic=\\x26quot;1\\x26quot; style=\\x26quot;color: rgb(87, 107, 149) !important;\\x26quot;\\x26gt;#温馨家居装饰\\x26lt;/a\\x26gt;</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-25T09:35:56</pubDate></item><item><title>利用binfmt_misc注册SUID二进制作为Linux后门</title><link>https://mp.weixin.qq.com/s/zb6-NrGZqUdb73YH4tC57Q</link><description>利用binfmt_misc注册SUID二进制作为Linux后门</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-25T06:00:28</pubDate></item><item><title>通过 Hook wininet 构建自定义 C2 通信信道</title><link>https://mp.weixin.qq.com/s/gpLRhoT37Ry6Qq4zTV_Y7Q</link><description>通过 Hook wininet 构建自定义 C2 通信信道</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-24T06:00:20</pubDate></item><item><title>AdaptixC2 深度剖析：功能、战术与狩猎策略</title><link>https://mp.weixin.qq.com/s/XvBB1bJCIFpoQoAAGKhXcw</link><description>AdaptixC2 深度剖析：功能、战术与狩猎策略</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-23T06:00:24</pubDate></item><item><title>让AI去挖漏洞：11款大模型的黑客能力，我来替你测了个遍</title><link>https://mp.weixin.qq.com/s/P4P-Lx0O4fTrNfr8R9KCSg</link><description>让AI去挖漏洞：11款大模型的黑客能力，我们替你测了个遍</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-22T06:01:42</pubDate></item><item><title>利用Windows 错误报告转储 LSASS 内存</title><link>https://mp.weixin.qq.com/s/JUHK4Rld-uPak7exsJG1VQ</link><description>利用Windows 错误报告转储 LSASS 内存</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-19T06:00:27</pubDate></item><item><title>使用浏览器代理C2的HTTP流量</title><link>https://mp.weixin.qq.com/s/MvcpbB-_Eqnevlxs1VvUeQ</link><description>使用浏览器代理C2的HTTP流量</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-18T06:00:35</pubDate></item><item><title>恶意软件开发系列（九）：使用C/C++内存执行.NET程序</title><link>https://mp.weixin.qq.com/s/iM3rCIXGy77GxIr7ILcXCg</link><description>恶意软件开发系列（九）：使用C/C++内存执行.NET程序</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-17T06:00:40</pubDate></item><item><title>恶意软件开发系列（八）：COFF注入与内存执行</title><link>https://mp.weixin.qq.com/s/9eKwTH_h7PoIOfgbYzGVJg</link><description>恶意软件开发系列（八）：COFF注入与内存执行</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-16T06:00:46</pubDate></item><item><title>Windows 恶意软件开发（七）：突破安全桌面，实现键盘记录器</title><link>https://mp.weixin.qq.com/s/BzLtyg0WpTFKOwI7Wv_h5A</link><description>Windows 恶意软件开发（七）：突破安全桌面，实现键盘记录器</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-15T06:00:36</pubDate></item><item><title>恶意软件开发系列（六）：使用LLVM和模板元编程的高级混淆技术</title><link>https://mp.weixin.qq.com/s/Xwjl2XUsA6y-eKOKKGpwiA</link><description>恶意软件开发系列（六）：使用LLVM和模板元编程的高级混淆技术</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-11T06:00:20</pubDate></item><item><title>恶意软件开发系列（五）： 一些Tips和技巧</title><link>https://mp.weixin.qq.com/s/6v9usDXDN8h3MzB2LwC_Yg</link><description>恶意软件开发系列（五）： 一些Tips和技巧</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-10T06:03:58</pubDate></item><item><title>恶意软件开发系列（四）：反静态分析技术详解</title><link>https://mp.weixin.qq.com/s/YnoOfvd0ITjM4TZP7ANttg</link><description>恶意软件开发系列（四）：反静态分析技术详解</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-09T06:00:30</pubDate></item><item><title>恶意软件开发系列（三）：反调试技术详解</title><link>https://mp.weixin.qq.com/s/vP80n7aOmSN1w1XdTwYILQ</link><description>恶意软件开发系列（三）：反调试技术详解</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-08T08:00:34</pubDate></item><item><title>恶意软件开发系列（二）：与沙箱斗智斗勇</title><link>https://mp.weixin.qq.com/s/9FpaeuCcbZefXdg0v18FFA</link><description>恶意软件开发系列（二）：与沙箱斗智斗勇</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-04T08:04:39</pubDate></item><item><title>恶意软件开发系列（一）：打造一个能躲避杀软的木马</title><link>https://mp.weixin.qq.com/s/plALQUnN7YK8-XU1sRtfVQ</link><description>恶意软件开发系列（一）：打造一个能躲避杀软的木马</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-03T06:00:19</pubDate></item><item><title>分析C2框架的演变及规避检测技术</title><link>https://mp.weixin.qq.com/s/nz1Ydo2Ksp-aR6ICYZNU-Q</link><description>分析C2框架的演变及规避检测技术</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-02T08:00:50</pubDate></item><item><title>深入 Windows VEH：如何导出向量化异常处理器列表</title><link>https://mp.weixin.qq.com/s/fTtLq4XCVREJJBKcaLy89Q</link><description>深入 Windows VEH：如何导出向量化异常处理器列表</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-12-01T08:00:53</pubDate></item><item><title>Windows Installer 提权漏洞分析</title><link>https://mp.weixin.qq.com/s/ivqCEX4mVI4P0-_B40cZ5g</link><description>Windows Installer 提权漏洞分析</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-11-27T08:01:42</pubDate></item><item><title>利用call gadgets技术绕过EDR调用栈检测</title><link>https://mp.weixin.qq.com/s/W0EhjKGgBhPaSno2WRH89w</link><description>利用call gadgets技术绕过EDR调用栈检测</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-11-26T08:02:08</pubDate></item><item><title>利用 Windows 辅助功能实现持久化与横向移动</title><link>https://mp.weixin.qq.com/s/eiWeV7y8jGnj99FC_FGmLw</link><description>利用 Windows 辅助功能实现持久化与横向移动</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-11-25T08:00:45</pubDate></item><item><title>为什么 Rust 在恶意软件开发领域逐渐占据一席之地</title><link>https://mp.weixin.qq.com/s/Pt7kGHfz53SvklKstGv2bw</link><description>为什么 Rust 在恶意软件开发领域逐渐占据一席之地</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-11-24T08:01:07</pubDate></item><item><title>PowerShell红队指南</title><link>https://mp.weixin.qq.com/s/GW8luECl0Eo-4qXklT-1IA</link><description>PowerShell红队指南</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-11-20T08:02:47</pubDate></item><item><title>CS的UDRL, SleepMask和BeaconGate功能详解</title><link>https://mp.weixin.qq.com/s/S3SjvfI3E-iIeR1nKSeDEg</link><description>CS的UDRL, SleepMask和BeaconGate功能详解</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-11-17T10:06:55</pubDate></item><item><title>如何编写免杀的shellcode</title><link>https://mp.weixin.qq.com/s/geo2NEsBLGTOdqIX0V07rA</link><description>如何编写免杀的shellcode</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-11-13T08:00:24</pubDate></item><item><title>EDR对抗和绕过技术盘点</title><link>https://mp.weixin.qq.com/s/c1dfQwB5uhYOhHDA5MKTKQ</link><description>EDR对抗和绕过技术盘点</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-11-11T08:01:16</pubDate></item><item><title>利用CS配置文件的强大功能实现EDR规避 - 第二部分</title><link>https://mp.weixin.qq.com/s/2zTtQhMDCjN7ekcXIftg5Q</link><description>利用CS配置文件的强大功能实现EDR规避 - 第二部分</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-11-10T08:02:21</pubDate></item><item><title>利用CS配置文件的强大功能实现EDR规避 - 第一部分</title><link>https://mp.weixin.qq.com/s/_K0Y_HjNGBdxYfnSFFIUrA</link><description>利用CS配置文件的强大功能实现EDR规避 - 第一部分</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-11-07T08:23:22</pubDate></item><item><title>禁忌内容：如何手动地加载一个PE文件</title><link>https://mp.weixin.qq.com/s/zJF7PqrU0pltuVBD0NRXDw</link><description>禁忌内容：如何手动地加载一个PE文件</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-11-06T08:01:23</pubDate></item><item><title>利用CS4.10中的新特性魔改Beacon</title><link>https://mp.weixin.qq.com/s/JoWhOKi0Hl5MNh7VjAeJCg</link><description>利用CS4.10中的新特性魔改Beacon</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-11-05T08:18:19</pubDate></item><item><title>PowerShell + .NET反射：打造无文件Shellcode加载链</title><link>https://mp.weixin.qq.com/s/LDFOCX8Zk-uQvJgeiXoPqQ</link><description>PowerShell + .NET反射：打造无文件Shellcode加载链</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-11-04T08:01:14</pubDate></item><item><title>内存加载PE绕过EDR</title><link>https://mp.weixin.qq.com/s/7XdioeJK2JfWYAQdrMJ5Vw</link><description>内存加载PE绕过EDR</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-11-03T08:00:38</pubDate></item><item><title>Windows进程间通信：RPC深入探索（第六部分）</title><link>https://mp.weixin.qq.com/s/nKHf-CqpW_eQvq32yhuxWA</link><description>Windows进程间通信：深入探索（第六部分）</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-10-31T08:00:32</pubDate></item><item><title>Windows进程间通信：深入探索（第五部分）</title><link>https://mp.weixin.qq.com/s/G5j9nqG7OvCyz2WfPanjdA</link><description>Windows进程间通信：深入探索（第五部分）</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-10-30T08:11:50</pubDate></item><item><title>Windows进程间通信：深入探索（第四部分）</title><link>https://mp.weixin.qq.com/s/gZYfHLdRq1RFoXRYKXEQyA</link><description>Windows进程间通信：深入探索（第四部分）</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-10-29T08:02:36</pubDate></item><item><title>Windows进程间通信：深入探索（第三部分）</title><link>https://mp.weixin.qq.com/s/E-5YMZcqhmMoIHVRS_iONA</link><description>Windows进程间通信：深入探索（第三部分）</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-10-27T08:01:32</pubDate></item><item><title>Windows进程间通信：深入探索（第二部分）</title><link>https://mp.weixin.qq.com/s/am0VmYvHLYHGL0XdVc3Dsg</link><description>Windows进程间通信：深入探索（第二部分）</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-10-23T08:00:43</pubDate></item><item><title>Windows进程间通信：深入探索（第一部分）</title><link>https://mp.weixin.qq.com/s/0Nu2ujFOQb3L4dWtDtJGzA</link><description>Windows 进程间通信：深入探索背后的世界 - 第一部分</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-10-22T08:19:01</pubDate></item><item><title>可执行命令的DCOM对象-1</title><link>https://mp.weixin.qq.com/s/hg1SgBxsnf28dapTKghFNQ</link><description>可执行命令的DCOM对象-1</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-10-21T08:00:27</pubDate></item><item><title>漏洞赏金指南之条件竞争漏洞</title><link>https://mp.weixin.qq.com/s/egKPJIPS4i7FQp7_qddSpw</link><description>漏洞赏金指南之竞争条件漏洞</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-10-20T08:00:40</pubDate></item><item><title>利用互联网空间搜索引擎搜集C2服务器</title><link>https://mp.weixin.qq.com/s/xrcTgY9_w-f-GqxU_s2WYw</link><description>利用互联网空间搜索引擎搜集C2服务器</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-28T11:19:47</pubDate></item><item><title>COM劫持对抗AV/EDR终章-4</title><link>https://mp.weixin.qq.com/s/86Hd_W48sK9WFj1P1BM5Hw</link><description>COM劫持对抗AV/EDR终章-4</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-26T08:02:37</pubDate></item><item><title>COM劫持对抗AV/EDR-3</title><link>https://mp.weixin.qq.com/s/3ntwiLCbr1cVb0NN4M-eeg</link><description>COM劫持对抗AV/EDR-3</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-25T11:24:35</pubDate></item><item><title>COM劫持对抗AV/EDR-2</title><link>https://mp.weixin.qq.com/s/RsYqra4lc36QIp3R-7iPWg</link><description>COM劫持对抗AV/EDR-2</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-24T08:00:56</pubDate></item><item><title>COM劫持对抗AV/EDR-1</title><link>https://mp.weixin.qq.com/s/2smuGgR5mEdXeJNGUaRaVQ</link><description>COM劫持对抗AV/EDR-1</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-23T08:05:46</pubDate></item><item><title>利用 Crystal Palace API 构建C2功能模块</title><link>https://mp.weixin.qq.com/s/UjwIKPe5MUcP5dyH9HVD1Q</link><description>利用 Crystal Palace API 构建C2功能模块</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-22T08:00:19</pubDate></item><item><title>深入理解 RUNDLL32.EXE</title><link>https://mp.weixin.qq.com/s/jjSnNS-RKzgbt8tm9W7bzA</link><description>深入理解 RUNDLL32.EXE</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-19T08:05:26</pubDate></item><item><title>劫持计划任务MareBackup实现权限提升</title><link>https://mp.weixin.qq.com/s/Zaz30PB9yKvnpjJiexUIYA</link><description>劫持计划任务MareBackup实现权限提升</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-18T08:05:58</pubDate></item><item><title>CS4.10中后渗透工具的开发</title><link>https://mp.weixin.qq.com/s/46xzrZkZ1nCPpv_fpjiJdg</link><description>CS4.10中后渗透工具的开发</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-17T08:10:15</pubDate></item><item><title>免杀开发语言新选择：Crystal</title><link>https://mp.weixin.qq.com/s/jQ1VW-UTxGtdakxMfOr-mw</link><description>免杀开发语言新选择：Crystal</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-16T08:00:35</pubDate></item><item><title>Windows 24H2中的自删除技术研究</title><link>https://mp.weixin.qq.com/s/v7FO2TrUxLfUyZhRUD5a-g</link><description>Windows 24H2中的自删除技术研究</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-15T08:02:00</pubDate></item><item><title>每周下载量达 20 亿的 npm 包被黑客劫持</title><link>https://mp.weixin.qq.com/s/lL1IXnBhvXG0-td86A9EYw</link><description>Hackers hijack npm packages with 2 billion weekly</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-11T08:01:21</pubDate></item><item><title>macOS 和 Linux中的EDR技术</title><link>https://mp.weixin.qq.com/s/NwHp0IBPIzM0gHXb7UMqrA</link><description>macOS 和 Linux中的EDR技术</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-10T08:01:47</pubDate></item><item><title>利用msc格式文件执行任意代码</title><link>https://mp.weixin.qq.com/s/D8o1VJXeE0PAXUziPvD8Xg</link><description>利用msc格式文件执行任意代码</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-09T08:00:55</pubDate></item><item><title>Early Cascade注入绕过EDR</title><link>https://mp.weixin.qq.com/s/LqCjIIDAbaVq1m_nUNIUCg</link><description>Early Cascade注入绕过EDR</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-08T08:01:10</pubDate></item><item><title>在 Windows 11 24H2中Dump Hashes</title><link>https://mp.weixin.qq.com/s/0APZ5O2zH4EP9gTWAeknCw</link><description>在 Windows 11 24H2中Dump Hashes</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-05T08:01:31</pubDate></item><item><title>利用GPP实现持久化</title><link>https://mp.weixin.qq.com/s/DVqAxuK2VloWqtxMu6i79w</link><description>利用GPP实现持久化</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-04T08:01:14</pubDate></item><item><title>规避EDR日志创建计划任务</title><link>https://mp.weixin.qq.com/s/6poGhZLot58slMb_3byNHw</link><description>规避EDR日志创建计划任务</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-03T08:00:22</pubDate></item><item><title>利用BOF获取记事本内存中的访问令牌</title><link>https://mp.weixin.qq.com/s/FSiboaqrZvttAg73Y8S9jw</link><description>利用BOF获取记事本内存中的访问令牌</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-02T08:01:08</pubDate></item><item><title>内网渗透：高效文件侦察的技术演进之路</title><link>https://mp.weixin.qq.com/s/-Qwp7pV2myAPy3JeXvI4Xg</link><description>内网渗透：高效文件侦察的技术演进之路</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-09-01T08:01:19</pubDate></item><item><title>钓鱼攻击之ClickFix-2</title><link>https://mp.weixin.qq.com/s/-OiDvxjoLnJK4dAqIuNAlQ</link><description>钓鱼攻击之ClickFix-2</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-08-29T08:02:54</pubDate></item><item><title>钓鱼攻击之ClickFix-1</title><link>https://mp.weixin.qq.com/s/65UdUPlsZeXhqbZPvItahg</link><description>钓鱼攻击之ClickFix-1</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-08-28T08:01:11</pubDate></item><item><title>借助PPL进程对抗EDR</title><link>https://mp.weixin.qq.com/s/0yjUePuvLThQSB4rmo4wsw</link><description>利用PPL进程对抗EDR</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-08-27T08:00:59</pubDate></item><item><title>调用栈伪造绕过EDR</title><link>https://mp.weixin.qq.com/s/222lRt1nJvO4y8RBbNYnuA</link><description>“调用栈伪造（Stack Spoofing）”是一种很酷的恶意代码技巧。它不新鲜，但最近又被拿出来讨论了。</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-08-26T08:00:27</pubDate></item><item><title>COM劫持技术从入门到放弃</title><link>https://mp.weixin.qq.com/s/gTsepn8o5wvr9zGzbJXzlA</link><description>COM劫持技术从入门到放弃</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-08-25T08:00:29</pubDate></item><item><title>一些渗透测试时可使用的powershell脚本片段</title><link>https://mp.weixin.qq.com/s/-ErZCGNtY2HgbiW0FRja8g</link><description>网站地址：https://powershellforhackers.com/payloads/</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-08-21T08:03:51</pubDate></item><item><title>利用C#窃取令牌获得system权限</title><link>https://mp.weixin.qq.com/s/UXCBQwoSIgeQNIxNSVCYOg</link><description>利用C#窃取令牌获得system权限</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-08-20T08:00:26</pubDate></item><item><title>EDR规避：从盲目堆砌过时技术到化繁为简精准对抗</title><link>https://mp.weixin.qq.com/s/R3Hj3XWB6aBKP2ws0jLe0Q</link><description>终端对抗，抛弃过时和被错误使用的技巧，了解底层原理，精准对抗</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-08-19T08:01:59</pubDate></item><item><title>潜伏：特殊符号伪装文件路径Bypass EDR</title><link>https://mp.weixin.qq.com/s/QYxNcp6WTwX1fVMVfv1d8Q</link><description>路径伪造，bypass EDR</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-08-18T08:00:25</pubDate></item><item><title>利用Python编写Shellcode Loader绕过Defender</title><link>https://mp.weixin.qq.com/s/ae8zDM-tKG28o3icoRWS_w</link><description>开发并改进一个 Python Shellcode Loader，探索对抗它的防御方式以及绕过这些防御的方法</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-08-15T08:00:53</pubDate></item><item><title>从头开始构建BOF加载器</title><link>https://mp.weixin.qq.com/s/r2PtyIDEzSNoajYbm-mnTA</link><description>从头开始构建BOF加载器</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-08-14T08:39:55</pubDate></item><item><title>利用Chromium监控用户的桌面</title><link>https://mp.weixin.qq.com/s/cqZASlBQ2qXECfRgD_gSiw</link><description>利用Chromium来监视用户的桌面</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-08-13T08:00:31</pubDate></item><item><title>渗透测试技巧：利用Windows长文件名实现文件隐身</title><link>https://mp.weixin.qq.com/s/Z1kfSRvbEbriq0OfkvfVMA</link><description>渗透测试技巧：利用Windows长文件名实现文件隐身</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-08-12T08:00:38</pubDate></item><item><title>AppDomainManager劫持：独属于C#程序的dll劫持</title><link>https://mp.weixin.qq.com/s/lfZ0bGxoL00QXprBh0Kkag</link><description>在攻防领域中，存在许多的代码注入技术。今天要分享的是一个经典且实用的技术——AppDomainManager劫持。</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-08-08T08:02:04</pubDate></item><item><title>.Net Startup Hooks：一个被忽视的dll注入技术</title><link>https://mp.weixin.qq.com/s/e6AoFTmWXOx9Q0e_hSpdFg</link><description>前言在Windows安全攻防中，代码注入一直是一个核心话题。</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-08-05T08:02:06</pubDate></item><item><title>在线命令行混淆免杀</title><link>https://mp.weixin.qq.com/s/43_ddkafv8kn8hUpsNl6Mg</link><description>argfuscator 简介ArgFuscator 是一个开源的独立 Web 应用程序，可帮助为常见的系统原</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-07-01T08:00:38</pubDate></item><item><title>数字杀毒环境下免杀对坑技巧一则04</title><link>https://mp.weixin.qq.com/s/F0tue7ITx_C-GTe01TjPlw</link><description>前言读过前几期的文章，相信各位看官已经初步掌握了一些免杀技巧。本期我们将在Visual Studio环境下，手把手演示从代码编写到免杀成型的完整流程。</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-04-29T08:00:13</pubDate></item><item><title>免杀dll劫持代码编写技巧两则</title><link>https://mp.weixin.qq.com/s/5YpVAKjBfEEboqoOXqtjIA</link><description>前言免杀技术绕不过白加黑这一关，利用系统或者安装的软件中，存在正规签名的文件，来运行我们的shellcode</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-04-23T08:01:05</pubDate></item><item><title>祝大佬永不翻车</title><link>https://mp.weixin.qq.com/s/fh1XHaXn47kIkrlk_GRHQg</link><description>谢谢翻车鱼</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-04-15T08:00:14</pubDate></item><item><title>数字杀毒环境下免杀对坑技巧一则03</title><link>https://mp.weixin.qq.com/s/DZLNLn1mhld_vMQaSUCO2Q</link><description>前言你那匹引以为傲的“免杀马”，此刻正在“敌军”的数字堡垒里纵横捭阖，七进七出，如入无人之境。</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-04-14T08:03:03</pubDate></item><item><title>数字杀毒环境下免杀对坑技巧一则02</title><link>https://mp.weixin.qq.com/s/8L5w6whA1eTXr4vfNGzU-A</link><description>前言书接上文，你正在免杀宇宙里遨游，指尖在键盘上疯狂跳跃。突然，旁边战友一声略带沮丧的喊叫把你拽回了现实：“靠，怎么又被干掉了！</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-04-11T08:02:07</pubDate></item><item><title>数字杀毒环境下免杀对坑技巧一则01</title><link>https://mp.weixin.qq.com/s/sCMKp8FcL0k0ZQUcNCxfAw</link><description>前言项目实施在即，兄弟们都在期待着你的“马子”征战沙场。此时，你小心翼翼地将从gayhub上抄来的代码复制到虚拟机的IDE中，进行编辑和生成。</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-04-10T08:00:47</pubDate></item><item><title>基于AI辅助探索：生成用于识别沙箱环境的代码</title><link>https://mp.weixin.qq.com/s/ee2SpUL36TkO2kbFmh-R-A</link><description>前言本文仅限技术研究与讨论，旨在探索利用AI加速安全相关代码开发的可能性，特别是沙箱检测技术。</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-04-02T15:39:01</pubDate></item><item><title>CVE-2025-30208 vite任意文件读取漏洞，附POC</title><link>https://mp.weixin.qq.com/s/q3z5yw_xV3sWBgbiRlt_6g</link><description>漏洞概述最近，Vite 开发服务器曝出了一个严重的安全漏洞，编号为 CVE-2025-30208。</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-04-01T08:02:30</pubDate></item><item><title>500+DLL劫持漏洞曝光</title><link>https://mp.weixin.qq.com/s/tcAWHr0_UxhtLZYgCYTWnA</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-03-25T13:51:46</pubDate></item><item><title>警惕Docker特权模式：轻松提权Root风险</title><link>https://mp.weixin.qq.com/s/8oQsE4XSkqHkAhl0KDjcDw</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-03-21T14:30:59</pubDate></item><item><title>powershell命令-后渗透</title><link>https://mp.weixin.qq.com/s/SdsBip2buPB9lpHoAa3QsA</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-03-20T14:31:06</pubDate></item><item><title>powershell命令-信息收集</title><link>https://mp.weixin.qq.com/s/sPCyESmXM1obUg_ekyzU3w</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-03-19T08:09:52</pubDate></item><item><title>利用合法服务规避流量检测的C2合集</title><link>https://mp.weixin.qq.com/s/MwRu61blRlT-2XPQ_IlEew</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-03-14T14:30:24</pubDate></item><item><title>目录扫描工具ffuf使用技巧</title><link>https://mp.weixin.qq.com/s/xHnNCSOuH6MqLduWF-b9Nw</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-03-13T14:02:28</pubDate></item><item><title>渗透测试Payload合集</title><link>https://mp.weixin.qq.com/s/P7whaRE91LZhXBVl4xEJXw</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-03-12T14:00:47</pubDate></item><item><title>Tiny XSS Payload</title><link>https://mp.weixin.qq.com/s/JLFl3Bzl1NgCp7x_nv5DwQ</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-03-11T14:26:29</pubDate></item><item><title>告别手撸 SQLMap 命令！这款神器让你效率翻倍！</title><link>https://mp.weixin.qq.com/s/oVPdMOt21bdtqZFwqzp2XQ</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-03-09T15:20:07</pubDate></item><item><title>Windows Nim 免杀df实战指南</title><link>https://mp.weixin.qq.com/s/u--TovA9lRSMGBFpQ71Bsg</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-03-08T13:35:34</pubDate></item><item><title>Windows C# 免杀实战指南</title><link>https://mp.weixin.qq.com/s/sQ15Aucrim5Xny68e5JtMQ</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-03-07T08:03:30</pubDate></item><item><title>免杀白文件合集</title><link>https://mp.weixin.qq.com/s/nDdCQu9bY1MPLCVHQHYG7w</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-03-06T08:00:48</pubDate></item><item><title>Linux命令混淆</title><link>https://mp.weixin.qq.com/s/x5sycawiDxGae3IzQkjFzQ</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-03-05T09:03:42</pubDate></item><item><title>Linux命令覆盖提权</title><link>https://mp.weixin.qq.com/s/wVAZoX4TAmi3sf4bstSsiw</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-03-04T10:00:48</pubDate></item><item><title>Nim反弹shell之一行代码\"吊打\"静态分析</title><link>https://mp.weixin.qq.com/s/OcFCBSjlaaOZxchAIlxxeg</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-03-03T21:34:03</pubDate></item><item><title>子域名收集小技巧</title><link>https://mp.weixin.qq.com/s/li8Di3lilyQyQyCGOLX2Tg</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-03-02T15:50:37</pubDate></item><item><title>使用Nim打造\"永不掉线\"的反弹shell</title><link>https://mp.weixin.qq.com/s/BO-05WIx6mhnI0S2ARt0TA</link><description>反弹shell，永不掉线</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-03-01T23:21:08</pubDate></item><item><title>白加黑免杀程序难找？RTDllHijack祝你一臂之力</title><link>https://mp.weixin.qq.com/s/-PRzNXd_s-jpcy-wr0OjiA</link><description>轻松寻找白名单文件</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-02-28T08:00:55</pubDate></item><item><title>weblive资产一键探活，输出精美HTML结果</title><link>https://mp.weixin.qq.com/s/7M2vwy3p6q0aOvzSse48EQ</link><description>资产测存活，我来一把梭</description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-02-27T21:40:41</pubDate></item><item><title>Naabu + Nmap 组合拳，扫端口速度狂飙</title><link>https://mp.weixin.qq.com/s/XJnOSbxXPTha7HYjPtxrxQ</link><description></description><author>红队工坊</author><category>红队工坊</category><pubDate>2025-02-26T22:28:41</pubDate></item><item><title>收藏！网络安全从业者必备：一套搞定所有敏感信息匹配的正则表达式</title><link>https://mp.weixin.qq.com/s/4ESbImdjW1lMXDVGqeehHg</link><description>\\x26lt;a class=\\x26quot;wx_topic_link\\x26quot; topic-id=\\x26quot;mgrzajqy-o0bh3z\\x26quot; data-topic=\\x26quot;1\\x26quot; style=\\x26quot;color: rgb(87, 107, 149) !important;\\x26quot;\\x26gt;#正则表达式\\x26lt;/a\\x26gt;\\x0a\\x26lt;a class=\\x26quot;wx</description><author>红队工坊</author><category>红队工坊</category></item></channel></rss>