腾讯玄武实验室安全动态推送
Tencent Xuanwu Lab Security Daily News
-
[ Attack ] PowerShell 注入狩猎,针对 PowerShell 脚本的安全审计: https://blogs.msdn.microsoft.com/powershell/2018/08/03/powershell-injection-hunter-security-auditing-for-powershell-scripts/
-
[ MalwareAnalysis ] 攻击者利用恶意浏览器扩展收集了数千万用户的 FaceBook 隐私数据: https://www.kaspersky.com/blog/facebook-leak-browser-extensions/24496/
-
[ Others ] 不利用 Schtasks 添加计划任务的反射 DLL 模块: https://ijustwannared.team/2018/08/13/schtasks-without-schtasks-exe-via-reflective-dll/
-
[ Others ] 寻找隐藏的宝石 Part3 - 搜索 .sh 文件快速获胜: https://medium.com/@mateusz.olejarka/finding-hidden-gems-vol-3-quick-win-with-sh-file-722e58636ded