Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
UninstalledAppCanary — एक कैनरी जो अनइंस्टॉल होने पर फायर करती है | Kitploit
उपकरण/GitHubGitHub/nccgroup/uninstalledappcanary
रक्षात्मक उपकरणघुसपैठ का पता लगानाघटना प्रतिक्रिया
GitHubnccgroup/uninstalledappcanary

UninstalledAppCanary

एक कैनरी जो अनइंस्टॉल होने पर फायर करती है

रिपॉजिटरी देखेंवेबसाइट
34815 साल पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

अनइंस्टॉल ऐप कैनरी

पूर्व कार्य

यह विंडोज़ सर्विस कैनरीज़ के आसपास के डिसेप्शन इंजीनियरिंग कार्य पर आधारित है। https://research.nccgroup.com/2021/03/04/deception-engineering-exploring-the-use-of-windows-service-canaries-against-ransomware/

सिद्धांत

कुछ थ्रेट एक्टर बाद के चरणों को ड्रॉप करने से पहले कई उत्पादों को अनइंस्टॉल कर देते हैं। हम कई कैनरी ऐप्स तैनात करते हैं जो प्रासंगिक नामों के साथ अनइंस्टॉल होने पर फायर करते हैं।

क्रिप्टो माइनर ट्रेडक्राफ्ट

2021 के Microsoft Exchange युद्धों के दौरान हमने निम्नलिखित ट्रेडक्राफ्ट देखा जो एक थ्रेट एक्टर द्वारा इस्तेमाल किया गया था

root@kitploit:~
cmd /c start /b wmic.exe product where "name like '%Eset%'" call uninstall /nointeractive
cmd /c start /b wmic.exe product where "name like '%%Kaspersky%%'" call uninstall /nointeractive
cmd /c start /b wmic.exe product where "name like '%avast%'" call uninstall /nointeractive
cmd /c start /b wmic.exe product where "name like '%avp%'" call uninstall /nointeractive
cmd /c start /b wmic.exe product where "name like '%Security%'" call uninstall /nointeractive
cmd /c start /b wmic.exe product where "name like '%AntiVirus%'" call uninstall /nointeractive
cmd /c start /b wmic.exe product where "name like '%Norton Security%'" call uninstall /nointeractive

कॉन्फ़िगरेशन

Security.vdproj संपादित करें और REPLACME को इसमें बदलें

root@kitploit:~
"Arguments" = "8:REPLACEME.canarytokens.com"

https://github.com/nccgroup/UninstalledAppCanary/blob/main/Security/Security.vdproj#L69

बिल्ड और इंस्टॉल करें

  • एक बिल्ड करें
  • इंस्टॉल करें
  • .. प्रतीक्षा करें
टूल डाउनलोड करें