<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Doonsec's feed</title><link>http://wechat.doonsec.com/MzkzODgwNzczMw.xml</link><description>The latest security articles about WeChat official account</description><language>zh-CN</language><lastBuildDate>Tue, 19 Nov 2024 14:58:23 GMT</lastBuildDate><generator>PyRSS2Gen-1.1.0</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><image><url>http://wechat.doonsec.com/</url><title>Doonsec</title><link>http://wechat.doonsec.com/static/front/img/doonsec_bak3.png</link></image><item><title>Linux应急响应：进程环境变量的妙用</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODgwNzczMw==&amp;mid=2247483766&amp;idx=1&amp;sn=4b0cd039df6bf9db2204cb02472692bf</link><description></description><author>风奕安全</author><category>风奕安全</category><pubDate>2024-11-19T10:26:49</pubDate></item><item><title>Linux进程伪装(三)：优化版本demo</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODgwNzczMw==&amp;mid=2247483756&amp;idx=1&amp;sn=1e294c47ee90d120b904b4aa2f93943f</link><description>Linux进程伪装demo，实现进程名、命令行、环境变量、进程树的伪装，有一定的自适应性。</description><author>风奕安全</author><category>风奕安全</category><pubDate>2024-11-06T17:09:21</pubDate></item><item><title>Linux进程伪装(二)：进程名&amp;&amp;命令行</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODgwNzczMw==&amp;mid=2247483750&amp;idx=1&amp;sn=a466f7b89ae63f63efd2d05aa68a7f1d</link><description></description><author>风奕安全</author><category>风奕安全</category><pubDate>2024-11-04T14:25:37</pubDate></item><item><title>Linux应急响应：查看文件的创建时间</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODgwNzczMw==&amp;mid=2247483731&amp;idx=1&amp;sn=76a6fad310cb5e392a472cb697614e56</link><description>你还在用ctime作为恶意样本的创建时间吗？本文告诉你Linux下如何正确获取文件的创建时间。</description><author>风奕安全</author><category>风奕安全</category><pubDate>2024-10-30T19:58:03</pubDate></item><item><title>一条命令修改Linux文件ctime</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODgwNzczMw==&amp;mid=2247483726&amp;idx=1&amp;sn=898767ffb25eb4ffd50b0a943474c9e4</link><description>一条命令修改Linux文件ctime</description><author>风奕安全</author><category>风奕安全</category><pubDate>2024-10-29T16:41:11</pubDate></item><item><title>Linux进程伪装(一)：伪装内核线程</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODgwNzczMw==&amp;mid=2247483721&amp;idx=1&amp;sn=a380dc5a01b9e3ec3bb269e965e85774</link><description>检测Linux中伪装的内核线程</description><author>风奕安全</author><category>风奕安全</category><pubDate>2024-10-28T15:32:46</pubDate></item><item><title>Linux修改文件更改时间ctime</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODgwNzczMw==&amp;mid=2247483711&amp;idx=1&amp;sn=6640f32ceb1ab9326059cde1d468c047</link><description>如何通过内核模块修改文件ctime</description><author>风奕安全</author><category>风奕安全</category><pubDate>2024-10-21T16:21:23</pubDate></item><item><title>Linux应急响应 | 查询文件创建时间</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODgwNzczMw==&amp;mid=2247483702&amp;idx=1&amp;sn=a79d9bd91750ae8937ffff88c943c141</link><description></description><author>风奕安全</author><category>风奕安全</category><pubDate>2024-10-17T14:09:05</pubDate></item><item><title>Linux应急响应：恢复恶意进程文件</title><link>https://mp.weixin.qq.com/s?__biz=MzkzODgwNzczMw==&amp;mid=2247483697&amp;idx=1&amp;sn=a9a07866a7bc6d33a88ba4e6ad9d3f57</link><description>一文告诉你Linux应急响应如何恢复恶意进程删除的样本文件以及底层原理</description><author>风奕安全</author><category>风奕安全</category><pubDate>2024-10-16T09:29:00</pubDate></item></channel></rss>