<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/MzkzMDgyMTM1Ng.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Thu, 19 Feb 2026 00:45:16 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>这是一波来自大年初一的更新</title><link>https://mp.weixin.qq.com/s/4q_Gz2YZGgouOk9x0zukFQ</link><description>这是一波来自大年初一的更新</description><author>黑晶</author><category>黑晶</category><pubDate>2026-02-17T16:32:06</pubDate></item><item><title>去学吧，我把知识都放在这个网站了</title><link>https://mp.weixin.qq.com/s/-mjgLvuaCQQnWeNx--Zh9g</link><description>去学吧，我把知识都放在这个网站了</description><author>黑晶</author><category>黑晶</category><pubDate>2026-01-29T18:31:37</pubDate></item><item><title>让我大调查一下你们</title><link>https://mp.weixin.qq.com/s/iEbVsbsq5iA_neUb894h7Q</link><description>让我大调查一下你们</description><author>黑晶</author><category>黑晶</category><pubDate>2026-01-15T20:32:35</pubDate></item><item><title>为什么你的截屏老是截不全</title><link>https://mp.weixin.qq.com/s/wuBd9BTsNU-7WL7AwW-SdA</link><description>为什么你的截屏老是截不全</description><author>黑晶</author><category>黑晶</category><pubDate>2026-01-13T19:30:55</pubDate></item><item><title>BlackCat 小小的更新一下</title><link>https://mp.weixin.qq.com/s/_QBnzFM__YnCS5ry8sbgPw</link><description>BlackCat 小小的更新一下</description><author>黑晶</author><category>黑晶</category><pubDate>2026-01-11T08:01:37</pubDate></item><item><title>先占个坑，正在猛猛开发</title><link>https://mp.weixin.qq.com/s/mm9JWb4DE7Yh-sYCPMLjOw</link><description>先占个坑，正在猛猛开发</description><author>黑晶</author><category>黑晶</category><pubDate>2026-01-02T15:10:21</pubDate></item><item><title>Claude Code入门食用指南</title><link>https://mp.weixin.qq.com/s/pBzs0W_QTXxuBZaKUojp-Q</link><description>Claude Code入门食用指南</description><author>黑晶</author><category>黑晶</category><pubDate>2025-12-30T19:38:39</pubDate></item><item><title>这个行业现状好像全世界都差不多？</title><link>https://mp.weixin.qq.com/s/hjiYFfmJ6DkzzOYv67UBew</link><description>这个行业现状好像全世界都差不多？</description><author>黑晶</author><category>黑晶</category><pubDate>2025-12-22T18:33:39</pubDate></item><item><title>AI Coding的红温时刻</title><link>https://mp.weixin.qq.com/s/EZ3aFJyaqFKwZ3tg9JX-og</link><description>AI Coding的红温时刻</description><author>黑晶</author><category>黑晶</category><pubDate>2025-12-08T20:35:26</pubDate></item><item><title>好奇现在学习新东西都是通过什么途径</title><link>https://mp.weixin.qq.com/s/GhP___bYvPJf5g_5f8KodQ</link><description>好奇现在学习新东西都是通过什么途径</description><author>黑晶</author><category>黑晶</category><pubDate>2025-12-04T18:57:04</pubDate></item><item><title>历时两天半，BlackCat终于搞定</title><link>https://mp.weixin.qq.com/s/G3lbZAct9ZN8d8ceS6lSRQ</link><description>历时两天半，BlackCat终于搞定</description><author>黑晶</author><category>黑晶</category><pubDate>2025-12-03T19:21:24</pubDate></item><item><title>AI练习生之C2开发日记（一）</title><link>https://mp.weixin.qq.com/s/dO79eEsSxNV0xqEppKZaPQ</link><description>AI练习生之C2开发日记（一）</description><author>黑晶</author><category>黑晶</category><pubDate>2025-12-01T20:57:07</pubDate></item><item><title>windows下利用进程克隆实现 EDR 规避</title><link>https://mp.weixin.qq.com/s/fZTG1csMRImSsO6nilPEHg</link><description>windows下利用进程克隆实现 EDR 规避摘要</description><author>黑晶</author><category>黑晶</category><pubDate>2025-11-24T19:45:27</pubDate></item><item><title>假如让AI来设计C2会怎么样</title><link>https://mp.weixin.qq.com/s/IBxix2UOFdCdzF1Jr1p2TQ</link><description>假如让AI来设计C2会怎么样</description><author>黑晶</author><category>黑晶</category><pubDate>2025-11-18T19:34:08</pubDate></item><item><title>EDR对抗从入门到入狱之八：操作系统启动链的守门人 —— ELAM驱动</title><link>https://mp.weixin.qq.com/s/d9bCxH-jaajvW6djTUqiTg</link><description>EDR对抗从入门到入狱之八：操作系统启动链的守门人 —— ELAM驱动</description><author>黑晶</author><category>黑晶</category><pubDate>2025-11-11T08:01:29</pubDate></item><item><title>EDR对抗从入门到入狱之七: 反病毒扫描器的前世今生与YARA规则深度剖析</title><link>https://mp.weixin.qq.com/s/yBKNTn0BQQ6Ess2r_4chxA</link><description>EDR对抗从入门到入狱之七: 反病毒扫描器的前世今生与YARA规则深度剖析</description><author>黑晶</author><category>黑晶</category><pubDate>2025-10-30T08:00:39</pubDate></item><item><title>EDR对抗从入门到入狱之六: Event Tracing for Windows</title><link>https://mp.weixin.qq.com/s/zfrcK7FW3ShFxzd-0BAi6g</link><description>EDR对抗从入门到入狱之六: Event Tracing for Windows (ETW) 深度剖析</description><author>黑晶</author><category>黑晶</category><pubDate>2025-10-27T18:51:52</pubDate></item><item><title>EDR对抗从入门到入狱之五：网络过滤</title><link>https://mp.weixin.qq.com/s/ueXRWtpcN_CtPRYgT-OjXA</link><description>EDR对抗从入门到入狱之五：网络过滤</description><author>黑晶</author><category>黑晶</category><pubDate>2025-10-25T13:31:40</pubDate></item><item><title>EDR对抗从入门到入狱之四: 微过滤深度剖析与文件系统监控</title><link>https://mp.weixin.qq.com/s/YqhRYYlMNz_be3TAfcw1UA</link><description>EDR对抗从入门到入狱之四: 微过滤深度剖析与文件系统监控</description><author>黑晶</author><category>黑晶</category><pubDate>2025-10-23T19:08:27</pubDate></item><item><title>EDR对抗从入门到入狱之三: Image Load 监控与注册表回调</title><link>https://mp.weixin.qq.com/s/aKgSBXOabMbpB8QUMQUUMQ</link><description>EDR对抗从入门到入狱之三: Image Load 监控与注册表回调</description><author>黑晶</author><category>黑晶</category><pubDate>2025-10-22T19:03:39</pubDate></item><item><title>EDR对抗从入门到入狱之二: 回调机制</title><link>https://mp.weixin.qq.com/s/HAF-Fi9Jzx0wx5N52Z484A</link><description>EDR对抗从入门到入狱之二: 回调机制</description><author>黑晶</author><category>黑晶</category><pubDate>2025-10-21T20:29:37</pubDate></item><item><title>EDR对抗从入门到入狱: Hook原理与对抗</title><link>https://mp.weixin.qq.com/s/4dHjjpZAP2PkOiqtIngvgQ</link><description>EDR对抗从入门到入狱: Hook原理与对抗</description><author>黑晶</author><category>黑晶</category><pubDate>2025-10-20T21:36:00</pubDate></item><item><title>如何用“程序入口点”玩进程注入</title><link>https://mp.weixin.qq.com/s/focPKaQnzLA8Fk-z2CeaWQ</link><description>如何用“程序入口点”玩进程注入</description><author>黑晶</author><category>黑晶</category><pubDate>2025-10-16T19:33:49</pubDate></item><item><title>Windows Bootkit 与 Rootkit 概述</title><link>https://mp.weixin.qq.com/s/uswWbdBGKM6oDgBdqwuGkA</link><description>Windows Bootkit 与 Rootkit 概述</description><author>黑晶</author><category>黑晶</category><pubDate>2025-10-13T20:40:53</pubDate></item><item><title>还在手搓免杀？时代变了</title><link>https://mp.weixin.qq.com/s/VVmDDPcChtWF_yA-zv47zQ</link><description>还在手搓免杀？时代变了</description><author>黑晶</author><category>黑晶</category><pubDate>2025-08-21T18:51:01</pubDate></item><item><title>Hijack Windows MareBackup 计划任务实现本地提权分析</title><link>https://mp.weixin.qq.com/s/6s6RJTR7oqhbVwkXHigSKw</link><description>Hijack Windows MareBackup 计划任务实现本地提权分析</description><author>黑晶</author><category>黑晶</category><pubDate>2025-06-23T20:04:17</pubDate></item><item><title>红队研发：C2的心跳设计</title><link>https://mp.weixin.qq.com/s/aNdfTg0VUGEo2JxBBwdXgQ</link><description>红队研发：C2的心跳设计</description><author>黑晶</author><category>黑晶</category><pubDate>2025-06-10T20:49:58</pubDate></item><item><title>免杀：Win Defender特征定位辅助工具推荐</title><link>https://mp.weixin.qq.com/s/pOOr4peAogs86VNyusTy9w</link><description>免杀：Win Defender特征定位辅助工具推荐</description><author>黑晶</author><category>黑晶</category><pubDate>2025-04-25T20:30:45</pubDate></item><item><title>红队C2研发日记2：C2 Server端的认证实现</title><link>https://mp.weixin.qq.com/s/GnxHWDGSeF5UpvD-pwMiEg</link><description>红队C2研发日记2：C2 Server端的认证实现</description><author>黑晶</author><category>黑晶</category><pubDate>2025-04-17T20:58:20</pubDate></item><item><title>用Avalonia UI构建远控界面</title><link>https://mp.weixin.qq.com/s/TWPaeRwkAUgO3YQ3GCnmxg</link><description>用Avalonia UI构建远控界面</description><author>黑晶</author><category>黑晶</category><pubDate>2025-04-07T19:33:12</pubDate></item><item><title>红队开发：利用Golang突破ja3检测</title><link>https://mp.weixin.qq.com/s/xDDZfmnG0QVzguuKaKlzQQ</link><description>红队开发：利用Golang突破ja3检测</description><author>黑晶</author><category>黑晶</category><pubDate>2025-03-10T19:33:55</pubDate></item><item><title>红队C2数据通信之TLV模型</title><link>https://mp.weixin.qq.com/s/ZVrCXaC-alIupn7RdMQVgw</link><description>红队C2数据通信之TLV模型</description><author>黑晶</author><category>黑晶</category><pubDate>2025-03-03T19:28:13</pubDate></item><item><title>如何设计一个CobaltStrike的Job管理机制</title><link>https://mp.weixin.qq.com/s/r6xts2ea_KE59iXNcJzzYQ</link><description>如何设计一个CobaltStrike的Job管理机制</description><author>黑晶</author><category>黑晶</category><pubDate>2025-02-21T19:35:47</pubDate></item><item><title>巧妙利用截屏窃取2FA认证码</title><link>https://mp.weixin.qq.com/s/1NvhTgc3h6QpOeZqxJNOxw</link><description>巧妙利用截屏窃取2FA认证码</description><author>黑晶</author><category>黑晶</category><pubDate>2025-02-13T19:26:24</pubDate></item><item><title>红队研发：编写一个屏幕 Monitor 程序</title><link>https://mp.weixin.qq.com/s/ZSh-S9QmfyUjaSPCAAjqEA</link><description>红队研发：编写一个屏幕 Monitor 程序</description><author>黑晶</author><category>黑晶</category><pubDate>2025-02-10T18:54:46</pubDate></item><item><title>红队开发：让自己的Shellcode实现SMC</title><link>https://mp.weixin.qq.com/s/1QAlz649TnjRQ2bIOoL6OQ</link><description>红队开发：让自己的Shellcode实现SMC</description><author>黑晶</author><category>黑晶</category><pubDate>2025-01-21T18:46:41</pubDate></item><item><title>Web3智能合约：预言机（Oracle）使用入门</title><link>https://mp.weixin.qq.com/s/xlOld2xDDUSghCjjSpU_aA</link><description>Web3智能合约：预言机（Oracle）使用入门</description><author>黑晶</author><category>黑晶</category><pubDate>2025-01-15T20:54:43</pubDate></item><item><title>分享的图片、视频、链接</title><link>https://mp.weixin.qq.com/s/LjByU3H_QMamP2KcJv28lw</link><description></description><author></author><category></category><pubDate>2025-01-07T20:35:30</pubDate></item><item><title>外网露出：新版 CobaltStrike 顶级免杀套件Arsenal kit</title><link>https://mp.weixin.qq.com/s/Uc10mSDsAY8Scl289_K2xA</link><description>外网露出：新版 CobaltStrike 顶级免杀套件Arsenal kit</description><author>黑晶</author><category>黑晶</category><pubDate>2025-01-07T19:43:48</pubDate></item><item><title>红队研发: 利用Xterm构建Web Terminal</title><link>https://mp.weixin.qq.com/s/wO0ce_fPisVXtCJGJCdNvw</link><description>红队研发: 利用Xterm构建Web Terminal</description><author>黑晶</author><category>黑晶</category><pubDate>2025-01-04T21:13:18</pubDate></item><item><title>Web3 智能合约: Solidity 基础数据类型</title><link>https://mp.weixin.qq.com/s/FlQfTOqNDVxL1HXwITG0pA</link><description>Web3 智能合约: Solidity 基础数据类型</description><author>黑晶</author><category>黑晶</category><pubDate>2025-01-03T19:59:56</pubDate></item><item><title>权限维持漫谈，合理利用本地环境</title><link>https://mp.weixin.qq.com/s/iqgnsvuh2x2H4eG3hbMDyQ</link><description>权限维持漫谈，合理利用本地环境</description><author>黑晶</author><category>黑晶</category><pubDate>2025-01-01T15:28:39</pubDate></item><item><title>Core Impact 价值10000美金的专业红队工具</title><link>https://mp.weixin.qq.com/s/f5uRMeQy7lNse_IaGWv2VA</link><description>Core Impact 价值10000美金的专业红队工具</description><author>黑晶</author><category>黑晶</category><pubDate>2024-12-30T20:11:35</pubDate></item><item><title>新型 DCOM 横向移动攻击</title><link>https://mp.weixin.qq.com/s/sjrCwcBHwFv5-yp1J0B-aw</link><description>新型 DCOM 横向移动攻击</description><author>黑晶</author><category>黑晶</category><pubDate>2024-12-28T19:48:19</pubDate></item><item><title>部署属于自己的EDR对抗环境</title><link>https://mp.weixin.qq.com/s/pPxOBlbtgnLJX0zKQ_iuuA</link><description>部署属于自己的EDR对抗环境</description><author>黑晶</author><category>黑晶</category><pubDate>2024-12-26T20:50:16</pubDate></item><item><title>对抗杀软的父进程检测</title><link>https://mp.weixin.qq.com/s/xSss0gOaCYayPtFUjRSRFA</link><description>对抗杀软的父进程检测</description><author>黑晶</author><category>黑晶</category><pubDate>2024-12-23T22:05:12</pubDate></item><item><title>C#黑客编程必须掌握的知识 (下)</title><link>https://mp.weixin.qq.com/s/ufp8VNm6pU1AxQCL9fRtWw</link><description>C#黑客编程必须掌握的知识 (下)</description><author>黑晶</author><category>黑晶</category><pubDate>2024-12-21T17:18:33</pubDate></item><item><title>让数字x60杀软核晶失效的自适应模式</title><link>https://mp.weixin.qq.com/s/9LULcqYbJHQBxLwyPQkPtA</link><description>让数字x60杀软核晶失效的自适应模式</description><author>黑晶</author><category>黑晶</category><pubDate>2024-12-20T22:32:54</pubDate></item><item><title>C#黑客编程必须掌握的知识 (上)</title><link>https://mp.weixin.qq.com/s/vb8WA4mujKmrMAnZ1ZvXmQ</link><description>C#黑客编程必须掌握的知识 (上)</description><author>黑晶</author><category>黑晶</category><pubDate>2024-12-17T21:20:26</pubDate></item><item><title>免杀 WindowsDefender 之特征码定位</title><link>https://mp.weixin.qq.com/s/_IZtB15kT89bAcud0xAsWw</link><description>免杀 WindowsDefender 之特征码定位</description><author>黑晶</author><category>黑晶</category><pubDate>2024-12-14T15:48:38</pubDate></item><item><title>银狐木马：杀死核晶状态下的x60</title><link>https://mp.weixin.qq.com/s/DnHbZ5-jm-zWVDqJGWACmA</link><description>银狐木马：杀死核晶状态下的x60</description><author>黑晶</author><category>黑晶</category><pubDate>2024-12-12T21:39:19</pubDate></item><item><title>银狐木马：杀死核晶状态下的x60</title><link>https://mp.weixin.qq.com/s/uYkuheKpSvVkmZ3T5tiGxg</link><description>银狐木马：杀死核晶状态下的x60</description><author>黑晶</author><category>黑晶</category><pubDate>2024-12-12T21:31:14</pubDate></item><item><title>银狐木马: 插件源码学习之本体上线模块</title><link>https://mp.weixin.qq.com/s/t-8hNjOMFNbMqQrksfHAKA</link><description>银狐木马: 插件源码学习之本体上线模块</description><author>黑晶</author><category>黑晶</category><pubDate>2024-12-09T21:38:44</pubDate></item><item><title>DLL回调注入机制-DllNotification Injection</title><link>https://mp.weixin.qq.com/s/K3oS3FYUUdmvHSTbVI56Rg</link><description>DLL回调注入机制-DllNotification Injection</description><author>黑晶</author><category>黑晶</category><pubDate>2024-12-08T21:13:51</pubDate></item><item><title>银狐木马: 插件源码学习之文件系统</title><link>https://mp.weixin.qq.com/s/C15JSftLwBvVpFPnAQL2lQ</link><description>银狐木马: 插件源码学习之文件系统</description><author>黑晶</author><category>黑晶</category><pubDate>2024-12-05T21:07:22</pubDate></item><item><title>银狐木马: 插件源码学习之系统管理(下)</title><link>https://mp.weixin.qq.com/s/0E3fSF8VZ7NvaK6Faopgww</link><description>银狐木马: 插件源码学习之系统管理(下)</description><author>黑晶</author><category>黑晶</category><pubDate>2024-12-04T20:09:27</pubDate></item><item><title>银狐木马: 插件源码学习之系统管理(上)</title><link>https://mp.weixin.qq.com/s/Xo_cDiIpYJYDRI6xip85Sw</link><description>银狐木马: 插件源码学习之系统管理(上)</description><author>黑晶</author><category>黑晶</category><pubDate>2024-12-03T20:09:32</pubDate></item><item><title>银狐木马: 插件源码学习之DDOS攻击</title><link>https://mp.weixin.qq.com/s/Y6iJEZQiaqeQhjz140Wn1A</link><description>银狐木马: 插件源码学习之DDOS攻击</description><author>黑晶</author><category>黑晶</category><pubDate>2024-11-30T15:43:45</pubDate></item><item><title>银狐木马: 插件源码学习之远程交谈</title><link>https://mp.weixin.qq.com/s/asqNuvMUDEWL1R6x43-LUQ</link><description>银狐木马: 插件源码学习之远程交谈</description><author>黑晶</author><category>黑晶</category><pubDate>2024-11-29T16:03:18</pubDate></item><item><title>银狐木马: 插件源码学习之远程终端</title><link>https://mp.weixin.qq.com/s/TGGMcTRPFvJ_r49feBO5jg</link><description>银狐木马: 插件源码学习之远程终端</description><author>黑晶</author><category>黑晶</category><pubDate>2024-11-27T20:29:16</pubDate></item><item><title>银狐木马插件源码学习之注入管理</title><link>https://mp.weixin.qq.com/s/UjPA4k8a3gYmTaqvkXeebw</link><description>银狐木马插件源码学习之注入管理</description><author>黑晶</author><category>黑晶</category><pubDate>2024-11-25T21:38:39</pubDate></item><item><title>硬件断点与AMSI扫描绕过</title><link>https://mp.weixin.qq.com/s/W8JhfGHphMClJm2mo10bSQ</link><description>硬件断点与AMSI扫描绕过</description><author>黑晶</author><category>黑晶</category><pubDate>2024-11-23T18:51:18</pubDate></item><item><title>免杀基础：x64汇编&amp;shellcode开发 第四部分</title><link>https://mp.weixin.qq.com/s/wnq7Ho9jfy-NKwzZNZ_Png</link><description>免杀基础：x64汇编\\x26amp;shellcode开发 第四部分</description><author>黑晶</author><category>黑晶</category><pubDate>2024-11-20T20:38:37</pubDate></item><item><title>免杀中shellcode加解密算法对熵的影响</title><link>https://mp.weixin.qq.com/s/-N-NGNQZDW-opNNXeIaDGA</link><description>免杀中对shellcode加解密算法对熵的影响</description><author>黑晶</author><category>黑晶</category><pubDate>2024-11-19T21:19:54</pubDate></item><item><title>免杀基础：x64汇编&amp;shellcode开发 第三部分</title><link>https://mp.weixin.qq.com/s/Yl_AVdliGYzLBwiVqM7ozw</link><description>免杀基础：x64汇编\\x26amp;shellcode开发 第三部分</description><author>黑晶</author><category>黑晶</category><pubDate>2024-11-18T20:16:41</pubDate></item><item><title>免杀基础：x64汇编&amp;shellcode开发 第一部分</title><link>https://mp.weixin.qq.com/s/0R4xjvHJHj_fbizU-06byg</link><description>免杀基础：x64汇编\\x26amp;shellcode开发一</description><author>黑晶</author><category>黑晶</category><pubDate>2024-11-15T21:29:05</pubDate></item><item><title>恶意软件开发第 9 部分 - 托管 CLR 和托管代码注入</title><link>https://mp.weixin.qq.com/s/RYhjNFNRCztsVEJoRBI3nw</link><description>恶意软件开发第 9 部分 - 托管 CLR 和托管代码注入</description><author>黑晶</author><category>黑晶</category><pubDate>2024-11-11T20:57:16</pubDate></item><item><title>恶意软件开发第 8 部分 - COFF 注入和内存中执行</title><link>https://mp.weixin.qq.com/s/0avrK9MG77TPjaRBPoSzRw</link><description>恶意软件开发第 8 部分 - COFF 注入和内存中执行</description><author>黑晶</author><category>黑晶</category><pubDate>2024-11-10T12:08:16</pubDate></item><item><title>恶意软件开发第四部分 - 反静态分析技巧</title><link>https://mp.weixin.qq.com/s/dCg6EDLgZ3M5qIUXHpQByA</link><description>恶意软件开发第四部分 - 反静态分析技巧</description><author>黑晶</author><category>黑晶</category><pubDate>2024-11-06T22:00:50</pubDate></item></channel></rss>