´Ó BeijingCrypt¹¥»÷¿´Ìì«‘EDR·À»¤Êµ¼ù £¬£¬£¬£¬£¬ÐÞ½¨´úÂëÎó²îÖ®ÍâµÄÖÕ¶ËÇå¾²ÆÁÕÏ

Ðû²¼Ê±¼ä 2026-03-02

½üÆÚ £¬£¬£¬£¬£¬AnthropicÍÆ³öµÄClaude Code Security×÷Ϊһ¿î¼¯³ÉÓÚClaude CodeµÄAIÇå¾²¹¤¾ß £¬£¬£¬£¬£¬±¸ÊܹØ×¢¡£¡£¡£¡£¡£Çø±ðÓÚÒÀÀµ¹æÔòÆ¥ÅäµÄ¹Å°å¾²Ì¬ÆÊÎö¹¤¾ß £¬£¬£¬£¬£¬ËüÄÜÄ£ÄâÇå¾²Ñо¿Ô±µÄÆÊÎöÂß¼­ £¬£¬£¬£¬£¬Éî¶ÈÃ÷È·´úÂë½á¹¹ £¬£¬£¬£¬£¬Í¨¹ý×é¼þ½»»¥ÓëÊý¾ÝÁ÷תÆÊÎö £¬£¬£¬£¬£¬¾«×¼Ê¶Íâ¹Å°åÊÖ¶ÎÒ×ÒÅ©µÄÖØ´óÎó²î¡£¡£¡£¡£¡£È»¶ø £¬£¬£¬£¬£¬Claude Code SecurityµÄÄÜÁ¦½çÏßÔÚÓÚ¾²Ì¬´úÂëÆÊÎö £¬£¬£¬£¬£¬ÎÞ·¨´¥¼°¶¯Ì¬ÔËÐÐʱµÄÇå¾²·À»¤¡£¡£¡£¡£¡£


ÔÚÏÖʵ¹¥»÷³¡¾°ÖÐ £¬£¬£¬£¬£¬´ó×Ú¹¥»÷·½·¨²¢·ÇʹÓôúÂëÎó²î £¬£¬£¬£¬£¬¶øÊÇͨ¹ýÔ¶³Ì×ÀÃæ±¬ÆÆ¡¢Êý¾Ý¿â¶Ë¿Ú¹¥»÷¡¢´¹ÂÚÓʼþµÈ·½·¨ £¬£¬£¬£¬£¬Ö±½Ó¶ÔÖÕ¶Ë¡¢¶Ë¿Ú»òȨÏÞ¾ÙÐÐÍ»ÆÆ £¬£¬£¬£¬£¬½ø¶øÖ²Èë¶ñÒâ³ÌÐò»òÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£ÕâÀද̬¡¢ÊµÊ±ÖÕ¶ËÈëÇÖÐÐΪ £¬£¬£¬£¬£¬ÐèÒÀÀµÖն˲àµÄÈ«Á÷³ÌÐÐΪ¼à²âÓ뼴ʱ×èµ² £¬£¬£¬£¬£¬ÕâÕýÊÇEDR²úÆ·µÄ½¹µãÄÜÁ¦ËùÔÚ £¬£¬£¬£¬£¬Ò²ÊǾ²Ì¬AI¹¤¾ßµÄ·À»¤Ã¤Çø¡£¡£¡£¡£¡£


BeijingCrypt±äÖÖÀÕË÷²¡¶¾¹¥»÷ÊÖ·¨ÆÊÎö


ÒÔ½üÆÚijÆóÒµÔâÓöµÄBeijingCrypt±äÖÖÀÕË÷²¡¶¾¹¥»÷ΪÀý £¬£¬£¬£¬£¬¸ÃÊÂÎñ¼´ÊôÓڵ䷶µÄÎÞ´úÂëÎó²îʹÓÃÐͶ¯Ì¬¹¥»÷¡£¡£¡£¡£¡£¹¥»÷Á´Â·ÍêÈ«ÍÑÀë´úÂë²ãÃæ £¬£¬£¬£¬£¬´ÓÊÖÒÕÉÏÈÃClaude Code SecurityµÈAI´úÂ빤¾ßʧȥ·À»¤×÷Óᣡ£¡£¡£¡£


? ÈëÇÖÁ´Â·Òþ²Ø×¨Òµ£º¹¥»÷Õßͨ¹ý±©Á¦ÆÆ½â¹¥ÆÆSQL ServerÊý¾Ý¿âÃÜÂë £¬£¬£¬£¬£¬Íê³É³õÊ¼Í»ÆÆºóÁ¬Ã¦Ö´ÐÐPowerShell¶ñÒâÏÂÁî £¬£¬£¬£¬£¬Ö²ÈëCobaltStrikeºóÃÅ £¬£¬£¬£¬£¬½ø¶øÏÂÔØÍøÂçɨÃ蹤¾ßÓëÀÕË÷³ÌÐòµÄ¶ñÒâÎļþ¡£¡£¡£¡£¡£Õû¸öÀú³ÌÒÀÍÐÖÕ¶ËÀú³ÌÖð²ãÍÆ½ø £¬£¬£¬£¬£¬ÐÐΪÒþ²ØÇÒÖ±Ö¸½¹µãÊý¾Ý¿â¡£¡£¡£¡£¡£

¼ÓÃÜÆÆËð¾ßÓÐɱ¾øÐÔ£º²¡¶¾ÀÖ³ÉÖ²Èëºó £¬£¬£¬£¬£¬Ëæ¼´¶ÔÊý¾Ý¿â±¸·Ý¡¢×°ÖóÌÐò¡¢°ì¹«ë¹¼þµÈ½¹µã×ʲú¾ÙÐиßÇ¿¶È¼ÓÃÜ £¬£¬£¬£¬£¬Îļþºó׺ͳһ¸ÄΪ.bixi £¬£¬£¬£¬£¬²¢ÁôÏÂÀÕË÷ÐÅ¡£¡£¡£¡£¡£ÈôÆóÒµÎÞÓÐÓñ¸·Ý £¬£¬£¬£¬£¬½¹µãÊý¾Ý½«ÃæÁÙÓÀÊÀÐÔɥʧ £¬£¬£¬£¬£¬ÓªÒµÔËÐÐÔâÊÜÑÏÖØ¹¥»÷¡£¡£¡£¡£¡£

¹¥»÷ÐÐΪ¾ß±¸ÆÕÊÊÐÔ£º¸Ã¹¥»÷ÎÞÐèʹÓÃÆóÒµ×ÔÑлò¿ªÔ´´úÂëµÄÎó²î £¬£¬£¬£¬£¬½öÕë¶ÔÖÕ¶Ë×°±¸¡¢Êý¾Ý¿âµÄ»ù´¡È¨ÏÞÓë¶Ë¿Ú·À»¤¶Ì°å £¬£¬£¬£¬£¬Èκα£´æÈõÃÜÂë¡¢¶Ë¿Ú̻¶¡¢ÐÐΪ¼à²âȱʧµÄÆóÒµ¶¼¿ÉÄܳÉΪĿµÄ¡£¡£¡£¡£¡£


ͼƬ1.jpg

Îļþ±»¼ÓÃÜºó £¬£¬£¬£¬£¬ºó׺¾ù±äΪ.bixi


ͼƬ2.png

BeijingCrypt±äÖÖÀÕË÷²¡¶¾µÄÀÕË÷ÐÅ


EDRÔËÐÐʱ·À»¤ ¶¯Ì¬¼à²â ¾«×¼×è»÷


ÃæÁٴ˴θßÄѶȶ¯Ì¬¹¥»÷ £¬£¬£¬£¬£¬°ÙÀÖ²©Ìì«‘EDRÒÀ¸½ÖÕ¶ËÐÐΪʵʱ¼à²â¡¢¹¥»÷Àú³ÌÊ÷ËÝÔ´¡¢¶ñÒâ³ÌÐò¾«×¼Ê¶±ðµÈ½¹µãÊÖÒÕ £¬£¬£¬£¬£¬ÊµÏÖÁ˶Թ¥»÷µÄÈ«Á÷³Ì×èµ²¡£¡£¡£¡£¡£


Ò»¡¢ºÁÃë¼¶Òì³£ÐÐΪ¼ì²â


ͨ¹ý¶ÔÖÕ¶ËÀú³ÌµÄʵʱ¼à¿Ø £¬£¬£¬£¬£¬¾«×¼²¶»ñµ½SQLServerÀú³ÌÖ´ÐеĸßΣpowershell¶ñÒâÏÂÁî £¬£¬£¬£¬£¬µÚһʱ¼äʶ±ð³öÒì³£Àú³ÌÐÐΪ £¬£¬£¬£¬£¬ÊµÏÖ¶Ô¹¥»÷ÐÐΪµÄÔçÆÚÔ¤¾¯ £¬£¬£¬£¬£¬´Óʱ¼äά¶ÈѹËõ¹¥»÷ʵÑé¿Õ¼ä¡£¡£¡£¡£¡£


ͼƬ3.png

SQLServerÀú³ÌÖ´ÐÐpowershellÏÂÁîÀú³ÌÊ÷


¶þ¡¢È«Á´Â·¹¥»÷ËÝÔ´


ͨ¹ý¹¹½¨¹¥»÷Àú³ÌÊ÷ £¬£¬£¬£¬£¬ÇåÎú»¹Ô­ÁË´Ówininit.exeµ½services.exe £¬£¬£¬£¬£¬ÔÙµ½sqlservr.exe £¬£¬£¬£¬£¬×îÖÕ´¥·¢cmd.exeÓëpowershell.exeÖ´ÐжñÒâÏÂÁîµÄÍêÕûÀú³ÌÊ÷ £¬£¬£¬£¬£¬ÎªÇå¾²´¦Öóͷ£Ìṩ¾«×¼µÄÊÖÒÕÒÀ¾Ý¡£¡£¡£¡£¡£


ͼƬ4.png

Ö²ÈëCobaltStrikeºóÃÅÏÂÁî


Èý¡¢¶àά¶È¶ñÒâ³ÌÐòʶ±ð


»ùÓÚÌØÕ÷¿âÆ¥ÅäÓëÐÐΪÆÊÎöÏàÁ¬ÏµµÄÊÖÒÕÊÖ¶Î £¬£¬£¬£¬£¬ÀÖ³Éʶ±ð²¢±ê¼ÇÁËCobaltStrikeºóÃÅ¡¢ÍøÂçɨÃ蹤¾ß¡¢ÀÕË÷³ÌÐòµÈÖÖÖÖ¶ñÒâ³ÌÐò £¬£¬£¬£¬£¬Ã÷È·ÖÖÖÖΣº¦µÄÊÖÒÕÀàÐÍÓë´¦Öóͷ£½¨Òé £¬£¬£¬£¬£¬ÊµÏÖ¶Ô¶ñÒâ³ÌÐòµÄ¾«×¼×è¶Ï¡£¡£¡£¡£¡£


ͼƬ5.png

Ìì«‘EDR²¡¶¾²éɱ¼ì²â³ö´ËÀÕË÷²¡¶¾Ïà¹ØÀú³Ì


ËÄ¡¢Öն˲ãÃæÈ«Á÷³Ì×èµ²


´Ó¶ñÒâÏÂÁîÖ´ÐС¢ºóÃÅÖ²Èëµ½¶ñÒâÎļþÏÂÔØ £¬£¬£¬£¬£¬ÔÚÖն˲ãÃæÓÐÓÃ×èµ²¹¥»÷¸÷»·½Ú £¬£¬£¬£¬£¬×èÖ¹²¡¶¾Èö²¥ÓëÎļþµÄ´ó¹æÄ£¼ÓÃÜ £¬£¬£¬£¬£¬ÎªÆóÒµ×°±¸ºÍÊý¾ÝÇå¾²ÖþÀÎÁËÖÕ¶ËÊÖÒÕ·ÀµØ¡£¡£¡£¡£¡£


´Ë´ÎBeijingCryptÀÕË÷¹¥»÷ÊÂÎñÅú×¢ £¬£¬£¬£¬£¬AIÊÖÒÕËäΪ´úÂëÎó²î·À»¤ÌṩÁËÓÐÓÃÊÖ¶Î £¬£¬£¬£¬£¬µ«ÒÀÀµÎÞ´úÂëÎó²îµÄ¶¯Ì¬¹¥»÷²¢Î´ÏûÊÅ £¬£¬£¬£¬£¬·´¶øÒÔ¸üÒþ²ØµÄÊֶΡ¢¸üÆÕÊʵÄ·¾¶ £¬£¬£¬£¬£¬³ÉΪÆóҵĿ½ñÃæÁÙµÄÖ÷ÒªÇå¾²Íþв¡£¡£¡£¡£¡£´ÓÊÖÒÕÊôÐÔ¿´ £¬£¬£¬£¬£¬EDRµÈ¶¯Ì¬ÔËÐÐʱ·À»¤²úÆ·¾Û½¹ÐÐΪ¼à²âÓëʵʱ×èµ² £¬£¬£¬£¬£¬Êܾ²Ì¬AI¹¤¾ßÓ°Ïì×îС £¬£¬£¬£¬£¬ÊÇÓ¦¶Ô´ËÀ๥»÷µÄ½¹µãÊÖ¶Î £¬£¬£¬£¬£¬Ò²ÊÇÍøÂçÇ徲ϵͳÖо߱¸¸ßÊÖÒÕ±ÚÀݵÄÒªº¦»·½Ú¡£¡£¡£¡£¡£


ÍêÉÆµÄ´úÂë²¢²»µÈͬÓÚÔËÐÐʱµÄÇå¾² £¬£¬£¬£¬£¬½ñÊÀÂë¿ÉÓÉAIÌìÉú £¬£¬£¬£¬£¬·ÀÓùÄÜÁ¦Ò²±ØÐèÏòÖÇÄÜÌå½ø»¯¡£¡£¡£¡£¡£°ÙÀÖ²©Ò»Á¬Éî¸ûEDRÖÕ¶ËÇå¾²ÁìÓò £¬£¬£¬£¬£¬½«AIÖÇÄÜÆÊÎöÓëEDRʵʱ·À»¤Éî¶ÈÈÚºÏ £¬£¬£¬£¬£¬Í¨¹ýÒ»Á¬ÊÖÒÕÁ¢Òì´òÔìÈ«·½Î»µÄÖÕ¶ËÇå¾²½â¾ö¼Æ»® £¬£¬£¬£¬£¬ÎªÓû§ÖþÀΡ°ÔËÐÐʱ¡±Óë¡°AI¶Ô¿¹¡±Ë«ÖØ·ÀµØ¡£¡£¡£¡£¡£