前言:最近好几个应急中毒事件,都不知道这群人上班在干什么。分享一个windows快速排查取证的小脚本。
@echo off
mkdir C:ProgramDataquzheng
net user C:ProgramDataquzhenguser.txt
tasklistC:ProgramDataquzhengtasklist.txt
netstat -anoC:ProgramDataquzhengport.txt
SCHTASKSC:ProgramDataquzhengrenwujihua.txt
sc queryC:ProgramDataquzhengsercives.txt
dir /s /b C:ProgramDataquzhengdirs.txt
reg query HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionrun /sC:ProgramDataquzhengreg.txt
reg query HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionrun /sC:ProgramDataquzhengreg.txt
reg query HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerrun /sC:ProgramDataquzhengreg.txt
reg query HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorerrun /sC:ProgramDataquzhengreg.txt
reg query HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunServices /s C:ProgramDataquzhengreg.txt
reg query HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunServices /sC:ProgramDataquzhengreg.txt
reg query HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunOnce /sC:ProgramDataquzhengreg.txt
reg query HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunOnce /sC:ProgramDataquzhengreg.txt
reg query HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunServicesOnce /s C:ProgramDataquzhengreg.txt
reg query HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunServicesOnce /sC:ProgramDataquzhengreg.txt
reg query HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsNTCurrentVersionWinlogonUserinit /sC:ProgramDataquzhengreg.txt
reg query HKEY_LOCAL_MACHINESOFTWAREWow6432NodeMicrosoftWindowsCurrentVersionRun /sC:ProgramDataquzhengreg.txt
reg query HKEY_CURRENT_USERSOFTWAREWow6432NodeMicrosoftWindowsCurrentVersionRun /s C:ProgramDataquzhengreg.txt
wevtutil epl System C:ProgramDataquzhengsystem.evtx
wevtutil epl Application C:ProgramDataquzhengApplication.evtx
wevtutil epl Security C:ProgramDataquzhengSecurity.evtx
wevtutil epl Windows PowerShell C:ProgramDataquzhengpowershell.evtx
wevtutil epl Microsoft-Windows-WMI-Activity/Operational C:ProgramDataquzhengWMI.evtx
echo "查鲁特 帅哥" C:ProgramDataquzhengxroot_shuaige.txt
echo "查鲁特 真帅" C:ProgramDataquzhengxroot_shuaige.txt
echo "查鲁特 帅到掉渣" C:ProgramDataquzhengxroot_shuaige.txt
。:.゚ヽ(。◕‿◕。)ノ゚.:。+゚防盗专用。:.゚ヽ(。◕‿◕。)ノ゚.:。+゚
^_^文章来源:微信公众号(边界骇客) ^_^ ^_^
推荐站内搜索:最好用的开发软件、免费开源系统、渗透测试工具云盘下载、最新渗透测试资料、最新黑客工具下载……
还没有评论,来说两句吧...