楼主: vaedzy
收起左侧

[技术原创] 【终章,基于微软评估实验室的测试】专业治疗杀软综合征

  [复制链接]
a27573
发表于 2022-1-1 14:17:28 | 显示全部楼层
本帖最后由 a27573 于 2022-1-1 14:24 编辑

HitmanPro.Alert
安装后经过一次重启


由于HMPA不会被识别未杀软,故关闭MD的防护进行测试

除了凭据窃取有警报之外,都是无声无息地被过(除时间外毫无变化的图我就不传了)


(上面两个警报是重测时产生的)

警报的详细内容
  1. Mitigation   MalwareBlocked
  2. Timestamp    2021-12-31T12:00:47

  3. Platform     10.0.19043/x64 v923 06_55*
  4. PID          6688
  5. Application  C:\Windows\Temp\sb-sim-temp-c_2jyxtu\sb_167664_bs_ljxph1h9\llac.exe
  6. Created      2021-12-31T12:00:47
  7. Description  Mal/Generic-R + Troj/Mimkatz-T


  8. Process Trace
  9. 1  C:\Windows\System32\cmd.exe [6688]
  10.    C:\Windows\system32\cmd.exe /c "echo sb_167664_bs >NUL & C:\Windows\TEMP\sb-sim-temp-c_2jyxtu\sb_167664_bs_ljxph1h9\llac.exe privilege::debug sekurlsa::logonpasswords exit sb_167664_bs & exit"
  11. 2  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167664_bs_142951.exe [888]
  12.    "C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167664_bs_142951.exe" 65004 413486659185822387 sb_167664_bs
  13. 3  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  14. 4  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\service\sbsimulator_service.exe [3388]
  15. 5  C:\Windows\System32\services.exe [828]
  16. 6  C:\Windows\System32\wininit.exe [696]
  17.    wininit.exe

  18. Services
  19. 3388  SBSimulator

  20. Dropped Files
  21. 1  C:\Windows\TEMP\sb-sim-temp-c_2jyxtu\sb_167664_bs_ljxph1h9\llac.exe
  22.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167664_bs_142951.exe [888]
  23.         Read by \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  24. 1  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167657_bs_142944.exe
  25.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  26.         Read by \Device\HarddiskVolume2\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1500]
  27.                 \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe [3312]
  28.                 \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  29.                 \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167657_bs_142944.exe [4660]
  30. 2  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167657_bs_142944.exe.manifest
  31.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  32. 3  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\resources\sbsimulator.db-journal
  33.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  34. 4  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167658_bs_142945.exe
  35.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  36.         Read by \Device\HarddiskVolume2\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1500]
  37.                 \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe [3312]
  38.                 \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  39.                 \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167658_bs_142945.exe [9640]
  40. 5  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167658_bs_142945.exe.manifest
  41.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  42. 6  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167659_bs_142946.exe
  43.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  44.         Read by \Device\HarddiskVolume2\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1500]
  45.                 \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe [3312]
  46.                 \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  47.                 \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167659_bs_142946.exe [2976]
  48. 7  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167659_bs_142946.exe.manifest
  49.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  50. 8  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167660_bs_142947.exe
  51.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  52.         Read by \Device\HarddiskVolume2\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1500]
  53.                 \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe [3312]
  54.                 \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  55.                 \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167660_bs_142947.exe [7748]
  56. 9  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167660_bs_142947.exe.manifest
  57.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  58. 10 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167661_bs_142948.exe
  59.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  60.         Read by \Device\HarddiskVolume2\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1500]
  61.                 \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe [3312]
  62.                 \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  63.                 \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167661_bs_142948.exe [10184]
  64. 11 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167661_bs_142948.exe.manifest
  65.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  66. 12 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167662_bs_142949.exe
  67.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  68.         Read by \Device\HarddiskVolume2\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1500]
  69.                 \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe [3312]
  70.                 \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  71.                 \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167662_bs_142949.exe [8852]
  72. 13 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167662_bs_142949.exe.manifest
  73.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  74. 14 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167663_bs_142950.exe
  75.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  76.         Read by \Device\HarddiskVolume2\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1500]
  77.                 \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe [3312]
  78.                 \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  79.                 \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167663_bs_142950.exe [6604]
  80. 15 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167663_bs_142950.exe.manifest
  81.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  82. 16 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167664_bs_142951.exe
  83.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  84.         Read by \Device\HarddiskVolume2\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1500]
  85.                 \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe [3312]
  86.                 \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  87.                 \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167664_bs_142951.exe [888]
  88. 17 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167664_bs_142951.exe.manifest
  89.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]

  90. Thumbprints
  91. 8b1c149c6bc445730979d1aedb0a6925819b1b8c95d28c833fbf94cf0229f40f
复制代码
  1. Mitigation   CredGuard
  2. Timestamp    2021-12-31T12:00:51

  3. Platform     10.0.19043/x64 v923 06_55*
  4. PID          2060
  5. Feature      007D0A30000000A6
  6. Application  C:\Windows\System32\reg.exe
  7. Created      2021-12-10T13:10:26
  8. Description  Registry Console Tool 10

  9. \REGISTRY\MACHINE\SAM

  10. Process Trace
  11. 1  C:\Windows\System32\reg.exe [2060]
  12.    reg.exe  query HKLM /f password /t REG_SZ /s
  13. 2  C:\Windows\System32\cmd.exe [9140]
  14.    C:\Windows\system32\cmd.exe /c "echo sb_167665_bs >NUL & reg.exe query HKLM /f password /t REG_SZ /s & exit"
  15. 3  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167665_bs_142952.exe [3444]
  16.    "C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167665_bs_142952.exe" 65004 413484882501789137 sb_167665_bs
  17. 4  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  18. 5  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\service\sbsimulator_service.exe [3388]
  19. 6  C:\Windows\System32\services.exe [828]
  20. 7  C:\Windows\System32\wininit.exe [696]
  21.    wininit.exe

  22. Services
  23. 3388  SBSimulator

  24. Dropped Files
  25. 1  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167657_bs_142944.exe
  26.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  27.         Read by \Device\HarddiskVolume2\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1500]
  28.                 \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe [3312]
  29.                 \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  30.                 \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167657_bs_142944.exe [4660]
  31. 2  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167657_bs_142944.exe.manifest
  32.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  33. 3  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\resources\sbsimulator.db-journal
  34.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  35. 4  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167658_bs_142945.exe
  36.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  37.         Read by \Device\HarddiskVolume2\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1500]
  38.                 \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe [3312]
  39.                 \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  40.                 \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167658_bs_142945.exe [9640]
  41. 5  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167658_bs_142945.exe.manifest
  42.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  43. 6  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167659_bs_142946.exe
  44.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  45.         Read by \Device\HarddiskVolume2\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1500]
  46.                 \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe [3312]
  47.                 \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  48.                 \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167659_bs_142946.exe [2976]
  49. 7  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167659_bs_142946.exe.manifest
  50.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  51. 8  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167660_bs_142947.exe
  52.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  53.         Read by \Device\HarddiskVolume2\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1500]
  54.                 \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe [3312]
  55.                 \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  56.                 \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167660_bs_142947.exe [7748]
  57. 9  C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167660_bs_142947.exe.manifest
  58.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  59. 10 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167661_bs_142948.exe
  60.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  61.         Read by \Device\HarddiskVolume2\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1500]
  62.                 \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe [3312]
  63.                 \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  64.                 \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167661_bs_142948.exe [10184]
  65. 11 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167661_bs_142948.exe.manifest
  66.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  67. 12 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167662_bs_142949.exe
  68.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  69.         Read by \Device\HarddiskVolume2\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1500]
  70.                 \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe [3312]
  71.                 \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  72.                 \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167662_bs_142949.exe [8852]
  73. 13 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167662_bs_142949.exe.manifest
  74.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  75. 14 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167663_bs_142950.exe
  76.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  77.         Read by \Device\HarddiskVolume2\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1500]
  78.                 \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe [3312]
  79.                 \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  80.                 \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167663_bs_142950.exe [6604]
  81. 15 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167663_bs_142950.exe.manifest
  82.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  83. 16 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167664_bs_142951.exe
  84.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  85.         Read by \Device\HarddiskVolume2\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1500]
  86.                 \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe [3312]
  87.                 \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  88.                 \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167664_bs_142951.exe [888]
  89. 17 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167664_bs_142951.exe.manifest
  90.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  91. 18 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167665_bs_142952.exe
  92.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]
  93.         Read by \Device\HarddiskVolume2\Program Files (x86)\HitmanPro.Alert\hmpalert.exe [1500]
  94.                 \Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe [3312]
  95.                 \Device\HarddiskVolume2\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3476]
  96.                 \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167665_bs_142952.exe [3444]
  97. 19 C:\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulation\sbsimulation_sb_167665_bs_142952.exe.manifest
  98.      Dropped by \Device\HarddiskVolume2\Program Files\SafeBreach\SafeBreach Endpoint Simulator\app\21.2.4\simulator\sbsimulator.exe [3972]

  99. Thumbprints
  100. c56ba9fe137105a138904a814f5717b03f7c8a71338797364283f1e1862e2138
复制代码



“已知的勒索软件感染”中,经确认勒索样本未实际运行,只能说明HMPA的静态扫描被过

“OS 配置更改”项未测试

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x

评分

参与人数 1人气 +3 收起 理由
vaedzy + 3

查看全部评分

Kawarrui
发表于 2022-1-7 11:59:52 | 显示全部楼层
00006666 发表于 2021-12-31 12:05
那这样的话,勒索测试应该是只测试监控,没有测试主防吧。

MDE相当于第二层防护,只有测试的杀软漏掉之后MDE才会提醒
虚无混沌
发表于 2022-1-8 12:30:27 | 显示全部楼层
vaedzy 发表于 2021-12-31 12:03
有这种日志,我知道正常人懒得看,都丢上来就是看图大会了。需要的话我发给你,你看看

看着这个,有种打网络攻防的感觉,仿佛自己也是高手了……
虚无混沌
发表于 2022-1-8 12:31:52 | 显示全部楼层
几位大佬辛苦,看起来表现上卡巴斯基确实值得信赖。反而在上一章测试中表现良好的BD,在BDTS版本,该次测试条件下表现没那么亮眼了。
虚无混沌
发表于 2022-1-8 12:32:36 | 显示全部楼层
本帖最后由 虚无混沌 于 2022-1-8 12:36 编辑
swizzer 发表于 2021-12-31 13:24
确实···
我怀疑智量缺少测试岗···就算是3.03,也还是有不少小问题

立即应聘测试去……(不是)
vaedzy
头像被屏蔽
 楼主| 发表于 2022-1-8 12:32:51 | 显示全部楼层
虚无混沌 发表于 2022-1-8 12:31
几位大佬辛苦,看起来表现上卡巴斯基确实值得信赖。反而在上一章测试中表现良好的BD,在BDTS版本,该次测试 ...

卡巴斯基 智量 还有个谁来着 大蜘蛛 都是抱着模拟器的 就是把攻击用的模拟器破坏了 导致无法正常执行。
虚无混沌
发表于 2022-1-8 12:39:09 | 显示全部楼层
vaedzy 发表于 2022-1-8 12:32
卡巴斯基 智量 还有个谁来着 大蜘蛛 都是抱着模拟器的 就是把攻击用的模拟器破坏了 导致无法正常执行。

啊,可能我看的太快看漏了。反正这么几天和以前经历,我还是信赖卡巴(陆续用了有四五年),BD(大概加起来一年,以前个人版用一段时间就被更新问题和卡机器烦的卸载,这次的BDT反而流畅的让我难以相信这是BD,并且在我的使用条件下误报很少“近乎没有”,让我对BD大为改观。PS:严重怀疑大佬住在卡饭了。
vaedzy
头像被屏蔽
 楼主| 发表于 2022-1-8 12:41:11 | 显示全部楼层
虚无混沌 发表于 2022-1-8 12:39
啊,可能我看的太快看漏了。反正这么几天和以前经历,我还是信赖卡巴(陆续用了有四五年),BD(大概加起 ...

中午嘛 没啥事干 就水一水 看到回复了就回一下
虚无混沌
发表于 2022-1-8 12:44:01 | 显示全部楼层
swizzer 发表于 2021-12-31 15:14
主防之前拦截模拟器本体了吗···

如果拦截了,那么自动机就会直接拉黑相应文件(就好像卡巴主 ...

其实这样测试就朝向某一功能的测试了,一般而言可以认为,在攻击开始前直接把发起程序做掉,应该算是成功防御了。
vaedzy
头像被屏蔽
 楼主| 发表于 2022-1-8 12:46:01 | 显示全部楼层
虚无混沌 发表于 2022-1-8 12:44
其实这样测试就朝向某一功能的测试了,一般而言可以认为,在攻击开始前直接把发起程序做掉,应该算是成功 ...

我们是这么认为的 但私下也讨论过 直接抱着模拟器杀 算不算是作弊 毕竟真正的攻击还没开始
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-17 00:36 , Processed in 0.097926 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表