´Ó BeijingCrypt¹¥»÷¿´Ìì«‘EDR·À»¤Êµ¼ù£¬£¬£¬£¬£¬£¬ÐÞ½¨´úÂëÎó²îÖ®ÍâµÄÖÕ¶ËÇå¾²ÆÁÕÏ

Ðû²¼Ê±¼ä 2026-03-02

½üÆÚ£¬£¬£¬£¬£¬£¬AnthropicÍÆ³öµÄClaude Code Security×÷Ϊһ¿î¼¯³ÉÓÚClaude CodeµÄAIÇå¾²¹¤¾ß£¬£¬£¬£¬£¬£¬±¸ÊܹØ×¢¡£ ¡£¡£Çø±ðÓÚÒÀÀµ¹æÔòÆ¥ÅäµÄ¹Å°å¾²Ì¬ÆÊÎö¹¤¾ß£¬£¬£¬£¬£¬£¬ËüÄÜÄ£ÄâÇå¾²Ñо¿Ô±µÄÆÊÎöÂß¼­£¬£¬£¬£¬£¬£¬Éî¶ÈÃ÷È·´úÂë½á¹¹£¬£¬£¬£¬£¬£¬Í¨¹ý×é¼þ½»»¥ÓëÊý¾ÝÁ÷תÆÊÎö£¬£¬£¬£¬£¬£¬¾«×¼Ê¶Íâ¹Å°åÊÖ¶ÎÒ×ÒÅ©µÄÖØ´óÎó²î¡£ ¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬Claude Code SecurityµÄÄÜÁ¦½çÏßÔÚÓÚ¾²Ì¬´úÂëÆÊÎö£¬£¬£¬£¬£¬£¬ÎÞ·¨´¥¼°¶¯Ì¬ÔËÐÐʱµÄÇå¾²·À»¤¡£ ¡£¡£


ÔÚÏÖʵ¹¥»÷³¡¾°ÖУ¬£¬£¬£¬£¬£¬´ó×Ú¹¥»÷·½·¨²¢·ÇʹÓôúÂëÎó²î£¬£¬£¬£¬£¬£¬¶øÊÇͨ¹ýÔ¶³Ì×ÀÃæ±¬ÆÆ¡¢Êý¾Ý¿â¶Ë¿Ú¹¥»÷¡¢´¹ÂÚÓʼþµÈ·½·¨£¬£¬£¬£¬£¬£¬Ö±½Ó¶ÔÖÕ¶Ë¡¢¶Ë¿Ú»òȨÏÞ¾ÙÐÐÍ»ÆÆ£¬£¬£¬£¬£¬£¬½ø¶øÖ²Èë¶ñÒâ³ÌÐò»òÇÔÈ¡Êý¾Ý¡£ ¡£¡£ÕâÀද̬¡¢ÊµÊ±ÖÕ¶ËÈëÇÖÐÐΪ£¬£¬£¬£¬£¬£¬ÐèÒÀÀµÖն˲àµÄÈ«Á÷³ÌÐÐΪ¼à²âÓ뼴ʱ×èµ²£¬£¬£¬£¬£¬£¬ÕâÕýÊÇEDR²úÆ·µÄ½¹µãÄÜÁ¦ËùÔÚ£¬£¬£¬£¬£¬£¬Ò²ÊǾ²Ì¬AI¹¤¾ßµÄ·À»¤Ã¤Çø¡£ ¡£¡£


BeijingCrypt±äÖÖÀÕË÷²¡¶¾¹¥»÷ÊÖ·¨ÆÊÎö


ÒÔ½üÆÚijÆóÒµÔâÓöµÄBeijingCrypt±äÖÖÀÕË÷²¡¶¾¹¥»÷ΪÀý£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñ¼´ÊôÓڵ䷶µÄÎÞ´úÂëÎó²îʹÓÃÐͶ¯Ì¬¹¥»÷¡£ ¡£¡£¹¥»÷Á´Â·ÍêÈ«ÍÑÀë´úÂë²ãÃæ£¬£¬£¬£¬£¬£¬´ÓÊÖÒÕÉÏÈÃClaude Code SecurityµÈAI´úÂ빤¾ßʧȥ·À»¤×÷Óᣠ¡£¡£


? ÈëÇÖÁ´Â·Òþ²Ø×¨Òµ£º¹¥»÷Õßͨ¹ý±©Á¦ÆÆ½â¹¥ÆÆSQL ServerÊý¾Ý¿âÃÜÂ룬£¬£¬£¬£¬£¬Íê³É³õÊ¼Í»ÆÆºóÁ¬Ã¦Ö´ÐÐPowerShell¶ñÒâÏÂÁ£¬£¬£¬£¬£¬Ö²ÈëCobaltStrikeºóÃÅ£¬£¬£¬£¬£¬£¬½ø¶øÏÂÔØÍøÂçɨÃ蹤¾ßÓëÀÕË÷³ÌÐòµÄ¶ñÒâÎļþ¡£ ¡£¡£Õû¸öÀú³ÌÒÀÍÐÖÕ¶ËÀú³ÌÖð²ãÍÆ½ø£¬£¬£¬£¬£¬£¬ÐÐΪÒþ²ØÇÒÖ±Ö¸½¹µãÊý¾Ý¿â¡£ ¡£¡£

¼ÓÃÜÆÆËð¾ßÓÐɱ¾øÐÔ£º²¡¶¾ÀÖ³ÉÖ²Èëºó£¬£¬£¬£¬£¬£¬Ëæ¼´¶ÔÊý¾Ý¿â±¸·Ý¡¢×°ÖóÌÐò¡¢°ì¹«ë¹¼þµÈ½¹µã×ʲú¾ÙÐиßÇ¿¶È¼ÓÃÜ£¬£¬£¬£¬£¬£¬Îļþºó׺ͳһ¸ÄΪ.bixi£¬£¬£¬£¬£¬£¬²¢ÁôÏÂÀÕË÷ÐÅ¡£ ¡£¡£ÈôÆóÒµÎÞÓÐÓñ¸·Ý£¬£¬£¬£¬£¬£¬½¹µãÊý¾Ý½«ÃæÁÙÓÀÊÀÐÔɥʧ£¬£¬£¬£¬£¬£¬ÓªÒµÔËÐÐÔâÊÜÑÏÖØ¹¥»÷¡£ ¡£¡£

¹¥»÷ÐÐΪ¾ß±¸ÆÕÊÊÐÔ£º¸Ã¹¥»÷ÎÞÐèʹÓÃÆóÒµ×ÔÑлò¿ªÔ´´úÂëµÄÎó²î£¬£¬£¬£¬£¬£¬½öÕë¶ÔÖÕ¶Ë×°±¸¡¢Êý¾Ý¿âµÄ»ù´¡È¨ÏÞÓë¶Ë¿Ú·À»¤¶Ì°å£¬£¬£¬£¬£¬£¬Èκα£´æÈõÃÜÂë¡¢¶Ë¿Ú̻¶¡¢ÐÐΪ¼à²âȱʧµÄÆóÒµ¶¼¿ÉÄܳÉΪĿµÄ¡£ ¡£¡£


ͼƬ1.jpg

Îļþ±»¼ÓÃܺ󣬣¬£¬£¬£¬£¬ºó׺¾ù±äΪ.bixi


ͼƬ2.png

BeijingCrypt±äÖÖÀÕË÷²¡¶¾µÄÀÕË÷ÐÅ


EDRÔËÐÐʱ·À»¤ ¶¯Ì¬¼à²â ¾«×¼×è»÷


ÃæÁٴ˴θßÄѶȶ¯Ì¬¹¥»÷£¬£¬£¬£¬£¬£¬Z6×ðÁú¿­Ê±Ìì«‘EDRÒÀ¸½ÖÕ¶ËÐÐΪʵʱ¼à²â¡¢¹¥»÷Àú³ÌÊ÷ËÝÔ´¡¢¶ñÒâ³ÌÐò¾«×¼Ê¶±ðµÈ½¹µãÊÖÒÕ£¬£¬£¬£¬£¬£¬ÊµÏÖÁ˶Թ¥»÷µÄÈ«Á÷³Ì×èµ²¡£ ¡£¡£


Ò»¡¢ºÁÃë¼¶Òì³£ÐÐΪ¼ì²â


ͨ¹ý¶ÔÖÕ¶ËÀú³ÌµÄʵʱ¼à¿Ø£¬£¬£¬£¬£¬£¬¾«×¼²¶»ñµ½SQLServerÀú³ÌÖ´ÐеĸßΣpowershell¶ñÒâÏÂÁ£¬£¬£¬£¬£¬µÚһʱ¼äʶ±ð³öÒì³£Àú³ÌÐÐΪ£¬£¬£¬£¬£¬£¬ÊµÏÖ¶Ô¹¥»÷ÐÐΪµÄÔçÆÚÔ¤¾¯£¬£¬£¬£¬£¬£¬´Óʱ¼äά¶ÈѹËõ¹¥»÷ʵÑé¿Õ¼ä¡£ ¡£¡£


ͼƬ3.png

SQLServerÀú³ÌÖ´ÐÐpowershellÏÂÁîÀú³ÌÊ÷


¶þ¡¢È«Á´Â·¹¥»÷ËÝÔ´


ͨ¹ý¹¹½¨¹¥»÷Àú³ÌÊ÷£¬£¬£¬£¬£¬£¬ÇåÎú»¹Ô­ÁË´Ówininit.exeµ½services.exe£¬£¬£¬£¬£¬£¬ÔÙµ½sqlservr.exe£¬£¬£¬£¬£¬£¬×îÖÕ´¥·¢cmd.exeÓëpowershell.exeÖ´ÐжñÒâÏÂÁîµÄÍêÕûÀú³ÌÊ÷£¬£¬£¬£¬£¬£¬ÎªÇå¾²´¦Öóͷ£Ìṩ¾«×¼µÄÊÖÒÕÒÀ¾Ý¡£ ¡£¡£


ͼƬ4.png

Ö²ÈëCobaltStrikeºóÃÅÏÂÁî


Èý¡¢¶àά¶È¶ñÒâ³ÌÐòʶ±ð


»ùÓÚÌØÕ÷¿âÆ¥ÅäÓëÐÐΪÆÊÎöÏàÁ¬ÏµµÄÊÖÒÕÊֶΣ¬£¬£¬£¬£¬£¬ÀÖ³Éʶ±ð²¢±ê¼ÇÁËCobaltStrikeºóÃÅ¡¢ÍøÂçɨÃ蹤¾ß¡¢ÀÕË÷³ÌÐòµÈÖÖÖÖ¶ñÒâ³ÌÐò£¬£¬£¬£¬£¬£¬Ã÷È·ÖÖÖÖΣº¦µÄÊÖÒÕÀàÐÍÓë´¦Öóͷ£½¨Ò飬£¬£¬£¬£¬£¬ÊµÏÖ¶Ô¶ñÒâ³ÌÐòµÄ¾«×¼×è¶Ï¡£ ¡£¡£


ͼƬ5.png

Ìì«‘EDR²¡¶¾²éɱ¼ì²â³ö´ËÀÕË÷²¡¶¾Ïà¹ØÀú³Ì


ËÄ¡¢Öն˲ãÃæÈ«Á÷³Ì×èµ²


´Ó¶ñÒâÏÂÁîÖ´ÐС¢ºóÃÅÖ²Èëµ½¶ñÒâÎļþÏÂÔØ£¬£¬£¬£¬£¬£¬ÔÚÖն˲ãÃæÓÐÓÃ×èµ²¹¥»÷¸÷»·½Ú£¬£¬£¬£¬£¬£¬×èÖ¹²¡¶¾Èö²¥ÓëÎļþµÄ´ó¹æÄ£¼ÓÃÜ£¬£¬£¬£¬£¬£¬ÎªÆóÒµ×°±¸ºÍÊý¾ÝÇå¾²ÖþÀÎÁËÖÕ¶ËÊÖÒÕ·ÀµØ¡£ ¡£¡£


´Ë´ÎBeijingCryptÀÕË÷¹¥»÷ÊÂÎñÅú×¢£¬£¬£¬£¬£¬£¬AIÊÖÒÕËäΪ´úÂëÎó²î·À»¤ÌṩÁËÓÐÓÃÊֶΣ¬£¬£¬£¬£¬£¬µ«ÒÀÀµÎÞ´úÂëÎó²îµÄ¶¯Ì¬¹¥»÷²¢Î´ÏûÊÅ£¬£¬£¬£¬£¬£¬·´¶øÒÔ¸üÒþ²ØµÄÊֶΡ¢¸üÆÕÊʵÄ·¾¶£¬£¬£¬£¬£¬£¬³ÉΪÆóҵĿ½ñÃæÁÙµÄÖ÷ÒªÇå¾²Íþв¡£ ¡£¡£´ÓÊÖÒÕÊôÐÔ¿´£¬£¬£¬£¬£¬£¬EDRµÈ¶¯Ì¬ÔËÐÐʱ·À»¤²úÆ·¾Û½¹ÐÐΪ¼à²âÓëʵʱ×èµ²£¬£¬£¬£¬£¬£¬Êܾ²Ì¬AI¹¤¾ßÓ°Ïì×îС£¬£¬£¬£¬£¬£¬ÊÇÓ¦¶Ô´ËÀ๥»÷µÄ½¹µãÊֶΣ¬£¬£¬£¬£¬£¬Ò²ÊÇÍøÂçÇ徲ϵͳÖо߱¸¸ßÊÖÒÕ±ÚÀݵÄÒªº¦»·½Ú¡£ ¡£¡£


ÍêÉÆµÄ´úÂë²¢²»µÈͬÓÚÔËÐÐʱµÄÇå¾²£¬£¬£¬£¬£¬£¬½ñÊÀÂë¿ÉÓÉAIÌìÉú£¬£¬£¬£¬£¬£¬·ÀÓùÄÜÁ¦Ò²±ØÐèÏòÖÇÄÜÌå½ø»¯¡£ ¡£¡£Z6×ðÁú¿­Ê±Ò»Á¬Éî¸ûEDRÖÕ¶ËÇå¾²ÁìÓò£¬£¬£¬£¬£¬£¬½«AIÖÇÄÜÆÊÎöÓëEDRʵʱ·À»¤Éî¶ÈÈںϣ¬£¬£¬£¬£¬£¬Í¨¹ýÒ»Á¬ÊÖÒÕÁ¢Òì´òÔìÈ«·½Î»µÄÖÕ¶ËÇå¾²½â¾ö¼Æ»®£¬£¬£¬£¬£¬£¬ÎªÓû§ÖþÀΡ°ÔËÐÐʱ¡±Óë¡°AI¶Ô¿¹¡±Ë«ÖØ·ÀµØ¡£ ¡£¡£