【远程控制】GotoHTTP 无视杀软实现远控 - 极核GetShell
【远程控制】GotoHTTP 无视杀软实现远控 - 极核GetShell
本文介绍了如何使用GotoHTTP远程控制软件绕过杀毒软件进行远控,适用于目标机器为Windows的场景。优点包括无需安装控制端、低带宽运行和支持图形界面等,但需管理员权限并可能被某些杀软拦截。提供了详细的使用方法,包括在拥有完全权限或仅有命令行权限的情况下的操作步骤,并强调了成功连接后的注意事项。
4 tabletop exercises every security team should run | CSO Online
4 tabletop exercises every security team should run | CSO Online
Security teams should run tabletop exercises to prepare for ransomware, third-party risks, insider threats, and distributed denial-of-service (DDoS) attacks. These exercises help identify vulnerabilities, improve response strategies, and ensure compliance with regulatory requirements. Key questions for each scenario include data encryption, partner vetting, insider threat detection, and DDoS mitigation plans. Regularly conducting these exercises with relevant stakeholders, including legal and communications teams, enhances overall cybersecurity readiness.
Build a Command-Line App with Python in 7 Easy Steps - KDnuggets
Build a Command-Line App with Python in 7 Easy Steps - KDnuggets
This tutorial guides readers through building a command-line TO-DO list app in Python using the argparse and os modules. It covers creating a project directory, setting up an argument parser, and defining functions to add, list, and remove tasks. The tutorial also includes steps to parse command-line arguments and run the app. It concludes with suggestions for further improvements, such as error handling and adding task priorities. The tutorial emphasizes learning by building and provides a link to the complete code on GitHub.
Containerize Python Apps with Docker in 5 Easy Steps - KDnuggets
Containerize Python Apps with Docker in 5 Easy Steps - KDnuggets
This post from KDnuggets outlines a five-step process to containerize Python applications using Docker. It covers installing Docker, coding a Python application, creating a Dockerfile, building the Docker image, and running the Docker container. The tutorial uses a command-line TO-DO list app as an example and emphasizes the benefits of Docker for managing dependencies and creating isolated, reproducible environments.
微软Azure订阅如何添加超级协助管理账号 - 如有乐享
微软Azure订阅如何添加超级协助管理账号 - 如有乐享
本文介绍了在微软Azure订阅中添加超级协助管理账号的步骤。通过添加协管账号可以降低账号订阅被封的概率,提供超管账号被封或者忘记密码的补救方案,并管理某些服务如OpenAI模型。需要一个有效订阅的Azure和一个被邀请的微软账号。步骤包括访问订阅详情,添加角色分配,选择特权管理角色和所有者,选择成员,设置条件,最后确认邀请并使用被邀请账号登录Azure控制面板。
ired.team 红队笔记 渗透测试备忘单
ired.team 红队笔记 渗透测试备忘单
这篇文章是关于渗透测试备忘单和红队笔记的。它包含了各种命令和技术,如检查Powershell日志记录、检查WinEvent日志中的SecureString泄露、审计政策、检查LSASS是否在PPL中运行等。此外,还包括了一些利用技术,如二进制利用、破解ZIP密码、设置简单的HTTP服务器等。文章还提供了一些有用的命令和工具,如MySQL用户定义功能提权、Docker权限提升、重置root密码等。最后,还提供了一些网络工具和技术,如端口转发、SSH隧道、文件传输协议等。
Incident-Response-Powershell 应急响应脚本
Incident-Response-Powershell 应急响应脚本
这篇文章介绍了一个名为"Incident-Response-Powershell"的应急响应脚本,可以帮助响应Windows设备上的网络攻击。脚本包括收集Windows事件、安全事件、即插即用设备、本地管理员等信息,并可以将取证文物导出为CSV文件以进行SIEM导入。文章还提供了脚本的下载地址和效果图。
Cloudfalre Access应用问题一二 » 老E的博客
Cloudfalre Access应用问题一二 » 老E的博客
Cloudflare Access是一种企业级Zero Trust产品,提供免费的无限期、无流量限制、50台设备支持的零信任解决方案。本文简要记录了团队域的手动加入、客户端设备控制和身份验证策略等内容。
Azure Application registrations, Enterprise Apps, and managed identities - adatum
Azure Application registrations, Enterprise Apps, and managed identities - adatum
This post provides information on Azure application registrations, enterprise applications, and managed identities. It explains the purpose of application registrations and the trust relationship established between Microsoft's identity platform and custom applications. It also discusses enterprise applications as the application identity within Azure AD and the relationship between app registrations and enterprise applications. Additionally, the post covers managed identities and their role in assigning identities to Azure resources. The author aims to clarify these concepts in the context of authentication in Azure.
bin456789/reinstall: 一键重装 / 一键 dd / One-click Reinstall OS
bin456789/reinstall: 一键重装 / 一键 dd / One-click Reinstall OS
该文档是关于一键重装脚本的介绍。该脚本具有多个功能,包括安装Linux、DD、重启到Alpine救援系统、重启到netboot.xyz和安装Windows ISO。脚本具有多个亮点,如使用官方安装程序、实时获取资源、适配不同规格的服务器、支持多种操作系统和提供多种安装方式。此外,还提供了下载和使用的说明。
RedteaGO - 最划算的大陆漫游 eSim 流量卡,原生境外 IP,注册就送 3 刀。 - 思有云 - IOIOX
RedteaGO - 最划算的大陆漫游 eSim 流量卡,原生境外 IP,注册就送 3 刀。 - 思有云 - IOIOX
RedteaGO是一个提供eSim全球漫游上网的平台,针对中国大陆有长期优惠套餐,每天1GB只需0.49美元,注册时使用邀请码"STIL0009"可获得3美元余额。通过实用测试发现,购买套餐后激活即可使用,网速稳定且足够日常使用,适用于备选方案。
SOC2 – Index
SOC2 – Index
This document provides information about SOC2, including objectives related to privacy, controls per TugboatLogic, types of SOC2 reports, SSAE 18, management insights, additional frameworks, and references. SOC2 focuses on controls and policies related to access control, security operations, risk management, business continuity, organization and management, asset management, information and communications, audit and compliance, data security, SDLC security, and continuous compliance. It is important for service organizations to comply with SOC2 requirements to ensure the security and privacy of data.