ׯÏÐÓÎÏ·

֤ȯ¼ò³Æ£º×¯ÏÐÓÎÏ· ֤ȯ´úÂ룺002212
7x24СʱЧÀÍ£º 400-777-0777

windowsÐÅÏ¢ÍøÂ繤¾ß

winlogÒ»¿î»ùÓÚgoµÄwindowsÐÅÏ¢ÍøÂ繤¾ß£¬£¬£¬Ö÷ÒªÍøÂçÄ¿µÄ×°±¸rdp¶Ë¿ÚµÇ¼¡¢mstscÔ¶³ÌÅþÁ¬¼Í¼¡¢mstscÃÜÂëºÍÇå¾²ÊÂÎñÖÐ ¡£¡£¡£¡£¡£

windowsÐÅÏ¢ÍøÂ繤¾ß

Ðû²¼Ê±¼ä£º2022-08-16
ä¯ÀÀ´ÎÊý£º4198
·ÖÏí£º

ÏîÄ¿×÷Õߣºi11us0ry

ÏîÄ¿µØµã£ºhttps://github.com/i11us0ry/winlog

Ò»¡¢¹¤¾ßÏÈÈÝ

winlogÒ»¿î»ùÓÚgoµÄwindowsÐÅÏ¢ÍøÂ繤¾ß£¬£¬£¬Ö÷ÒªÍøÂçÄ¿µÄ×°±¸rdp¶Ë¿ÚµÇ¼¡¢mstscÔ¶³ÌÅþÁ¬¼Í¼¡¢mstscÃÜÂëºÍÇå¾²ÊÂÎñÖÐ ¡£¡£¡£¡£¡£

¶þ¡¢×°ÖÃÓëʹÓÃ

1¡¢»ñÈ¡ÍâµØRDP¶Ë¿Ú£º

\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp

2¡¢»ñȡĿ½ñÓû§mstscÔ¶³ÌÅþÁ¬¼Í¼£¬£¬£¬°üÀ¨host¡¢port¡¢loginName

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Terminal Server Client\DefaultHKEY_CURRENT_USER\SOFTWARE\Microsoft\Terminal Server Client\Servers

3¡¢»ñȡĿ½ñЧÀÍÆ÷Çå¾²ÈÕÖ¾4624¡¢4625ÊÂÎñ

Advapi32.dll --> ReadEventLogW --> Security --> 4624¡¢4625

4¡¢×¥È¡ÃÜÂë

ÈôÊÇÓû§Ê¹ÓÃmstsc¾ÙÐÐÔ¶³ÌÅþÁ¬Ê±Ñ¡ÔñÁ˱£´æÆ¾Ö¤£¬£¬£¬Ôò¿ÉÒÔŲÓÃmimikatzץȡÓû§±£´æµÄÃÜÂë

5¡¢Ê¹ÓÃʱִÐÐexe£¬£¬£¬ÈôÊÇÐèÒª»ñÈ¡ÃÜÂëÐèÒªÒ»ÆðÉÏ´«mimikatz£¬£¬£¬²¢Ê¹ÓÃ-pÖ¸¶¨mimikatz£¬£¬£¬Â·¾¶ÈçÏ£º

Èý¡¢ÏÂÔØµØµã£º

ͨ¹ýÏîÄ¿µØµãÏÂÔØ

¿Í»§Ð§ÀÍÈÈÏß

400-777-0777
7*24СʱЧÀÍ

ÁªÏµÓÊÏä

servicing@topsec.com.cn

ɨÂë¹Ø×¢
¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿