| 
 | 
 
| 
 Blue Team Notes  
 
一些对蓝队工作有用的技巧  
 
- Shell Style
 - Windows
 
- OS Queries
 - Account Queries
 - Service Queries
 - Network Queries
 - Remoting Queries
 - Firewall Queries
 - SMB Queries
 - Process Queries
 - Recurring Task Queries
 - File Queries
 - Registry Queries
 - Driver Queries
 - DLL Queries
 - AV Queries
 - Log Queries
 - Powershell Tips
 
 
  - Linux
 
- Bash History
 - Grep and Ack
 - Processes and Networks
 - Files
 - Bash Tips
 
 
  - MacOS
 - Malware
 
- Rapid Malware Analysis
 - Unquarantine Malware
 - Process Monitor
 - Hash Check Malware
 - Decoding Powershell
 
 
  - SOC
 
 - Honeypots
 
 - Network Traffic
 
- Capture Traffic
 - TShark
 - Extracting Stuff
 - PCAP Analysis IRL
 
 
  - Digital Forensics
 
- Volatility
 - Quick Forensics
 - Chainsaw
 - Browser History
 - Which logs to pull in an incident
 - USBs
 
  
 
  |   
本帖子中包含更多资源
您需要 登录 才可以下载或查看,没有账号?立即注册 
 
 
 
x
 
 
 
 
 |