ׯÏÐÓÎÏ·

֤ȯ¼ò³Æ£º×¯ÏÐÓÎÏ· ֤ȯ´úÂ룺002212
7x24СʱЧÀÍ£º 400-777-0777

windowsÐÅÏ¢ÍøÂ繤¾ß

winlogÒ»¿î»ùÓÚgoµÄwindowsÐÅÏ¢ÍøÂ繤¾ß£¬£¬£¬£¬Ö÷ÒªÍøÂçÄ¿µÄ×°±¸rdp¶Ë¿ÚµÇ¼¡¢mstscÔ¶³ÌÅþÁ¬¼Í¼¡¢mstscÃÜÂëºÍÇå¾²ÊÂÎñÖС£¡£¡£¡£

windowsÐÅÏ¢ÍøÂ繤¾ß

Ðû²¼Ê±¼ä£º2022-08-16
ä¯ÀÀ´ÎÊý£º4198
·ÖÏí£º

ÏîÄ¿×÷Õߣºi11us0ry

ÏîÄ¿µØµã£ºhttps://github.com/i11us0ry/winlog

Ò»¡¢¹¤¾ßÏÈÈÝ

winlogÒ»¿î»ùÓÚgoµÄwindowsÐÅÏ¢ÍøÂ繤¾ß£¬£¬£¬£¬Ö÷ÒªÍøÂçÄ¿µÄ×°±¸rdp¶Ë¿ÚµÇ¼¡¢mstscÔ¶³ÌÅþÁ¬¼Í¼¡¢mstscÃÜÂëºÍÇå¾²ÊÂÎñÖС£¡£¡£¡£

¶þ¡¢×°ÖÃÓëʹÓÃ

1¡¢»ñÈ¡ÍâµØRDP¶Ë¿Ú£º

\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp

2¡¢»ñȡĿ½ñÓû§mstscÔ¶³ÌÅþÁ¬¼Í¼£¬£¬£¬£¬°üÀ¨host¡¢port¡¢loginName

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Terminal Server Client\DefaultHKEY_CURRENT_USER\SOFTWARE\Microsoft\Terminal Server Client\Servers

3¡¢»ñȡĿ½ñЧÀÍÆ÷Çå¾²ÈÕÖ¾4624¡¢4625ÊÂÎñ

Advapi32.dll --> ReadEventLogW --> Security --> 4624¡¢4625

4¡¢×¥È¡ÃÜÂë

ÈôÊÇÓû§Ê¹ÓÃmstsc¾ÙÐÐÔ¶³ÌÅþÁ¬Ê±Ñ¡ÔñÁ˱£´æÆ¾Ö¤£¬£¬£¬£¬Ôò¿ÉÒÔŲÓÃmimikatzץȡÓû§±£´æµÄÃÜÂë

5¡¢Ê¹ÓÃʱִÐÐexe£¬£¬£¬£¬ÈôÊÇÐèÒª»ñÈ¡ÃÜÂëÐèÒªÒ»ÆðÉÏ´«mimikatz£¬£¬£¬£¬²¢Ê¹ÓÃ-pÖ¸¶¨mimikatz£¬£¬£¬£¬Â·¾¶ÈçÏ£º

Èý¡¢ÏÂÔØµØµã£º

ͨ¹ýÏîÄ¿µØµãÏÂÔØ

¿Í»§Ð§ÀÍÈÈÏß

400-777-0777
7*24СʱЧÀÍ

ÁªÏµÓÊÏä

servicing@topsec.com.cn

ɨÂë¹Ø×¢
¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿