블로그 이미지
난넘

calendar

1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31

Notice

Tag

2016. 12. 21. 17:22 System

윈도우즈 자체 기능으로 침해사고 분석하기

Find A Windows Infection Quickly Without Tools

1) Startup find

wmic startup list full

2) dns cache

ipconfig /displaydns

3) wmic process list

wmic process get description,processid,parentprocessid,commandline /format:csv

4) wmic service list full | more

5) wmic service get name,processid,startmode,state,status,pathname /format:csv

6) wmic job list full



출처: ExploitWareLabs

posted by 난넘