
Ps-Tools, مجموعة أدوات متقدمة لمراقبة العمليات للعمليات الهجومية
إن امتلاك فهم تقني جيد للأنظمة التي نصل إليها أثناء المهمة هو شرط أساسي لتحديد الخطوة التالية في العملية. جمع وتحليل بيانات العمليات الجارية من الأنظمة المخترقة يمنحنا ثروة من المعلومات ويساعدنا على فهم أفضل لكيفية إعداد البنية التحتية لتقنية المعلومات في المؤسسة المستهدفة. علاوة على ذلك، فإن الاستعلام الدوري عن بيانات العمليات يسمح لنا بالتفاعل مع التغييرات في البيئة أو توفير محفزات عند حدوث تحقيق.
لمزيد من المعلومات حول الأدوات والتقنيات المستخدمة، يمكنك الاطلاع على المدونة التالية: https://outflank.nl/blog/2020/03/11/red-team-tactics-advanced-process-monitoring-techniques-in-offensive-operations/
Psx: Shows a detailed list of all processes running on the system.
Psk: Shows detailed kernel information including loaded driver modules.
Psc: Shows a detailed list of all processes with Established TCP connections.
Psm: Show detailed module information from a specific process id (loaded modules, network connections e.g.).
Psh: Show detailed handle information from a specific process id (object handles, network connections e.g.).
Psw: Show Window titles from processes with active Windows.
Download the Outflank-Ps-Tools folder and load the Ps-Tools.cna script within the Cobalt Strike Script Manager.
Use the Beacon help command to display syntax information.
This project is written in C/C++
You can use Visual Studio to compile the reflective dll's from source.
المؤلف: Cornelis de Plaa (@Cneelis) / Outflank
تحية خاصة إلى: Stan Hegt (@StanHacked) وجميع زملائي الرائعين الآخرين في Outflank