´Ó BeijingCrypt¹¥»÷¿´Ìì«‘EDR·À»¤Êµ¼ù£¬£¬£¬ÐÞ½¨´úÂëÎó²îÖ®ÍâµÄÖÕ¶ËÇå¾²ÆÁÕÏ

Ðû²¼Ê±¼ä 2026-03-02

½üÆÚ£¬£¬£¬AnthropicÍÆ³öµÄClaude Code Security×÷Ϊһ¿î¼¯³ÉÓÚClaude CodeµÄAIÇå¾²¹¤¾ß£¬£¬£¬±¸ÊܹØ×¢¡£¡£¡£¡£Çø±ðÓÚÒÀÀµ¹æÔòÆ¥ÅäµÄ¹Å°å¾²Ì¬ÆÊÎö¹¤¾ß£¬£¬£¬ËüÄÜÄ£ÄâÇå¾²Ñо¿Ô±µÄÆÊÎöÂß¼­£¬£¬£¬Éî¶ÈÃ÷È·´úÂë½á¹¹£¬£¬£¬Í¨¹ý×é¼þ½»»¥ÓëÊý¾ÝÁ÷תÆÊÎö£¬£¬£¬¾«×¼Ê¶Íâ¹Å°åÊÖ¶ÎÒ×ÒÅ©µÄÖØ´óÎó²î¡£¡£¡£¡£È»¶ø£¬£¬£¬Claude Code SecurityµÄÄÜÁ¦½çÏßÔÚÓÚ¾²Ì¬´úÂëÆÊÎö£¬£¬£¬ÎÞ·¨´¥¼°¶¯Ì¬ÔËÐÐʱµÄÇå¾²·À»¤¡£¡£¡£¡£


ÔÚÏÖʵ¹¥»÷³¡¾°ÖУ¬£¬£¬´ó×Ú¹¥»÷·½·¨²¢·ÇʹÓôúÂëÎó²î£¬£¬£¬¶øÊÇͨ¹ýÔ¶³Ì×ÀÃæ±¬ÆÆ¡¢Êý¾Ý¿â¶Ë¿Ú¹¥»÷¡¢´¹ÂÚÓʼþµÈ·½·¨£¬£¬£¬Ö±½Ó¶ÔÖÕ¶Ë¡¢¶Ë¿Ú»òȨÏÞ¾ÙÐÐÍ»ÆÆ£¬£¬£¬½ø¶øÖ²Èë¶ñÒâ³ÌÐò»òÇÔÈ¡Êý¾Ý¡£¡£¡£¡£ÕâÀද̬¡¢ÊµÊ±ÖÕ¶ËÈëÇÖÐÐΪ£¬£¬£¬ÐèÒÀÀµÖն˲àµÄÈ«Á÷³ÌÐÐΪ¼à²âÓ뼴ʱ×èµ²£¬£¬£¬ÕâÕýÊÇEDR²úÆ·µÄ½¹µãÄÜÁ¦ËùÔÚ£¬£¬£¬Ò²ÊǾ²Ì¬AI¹¤¾ßµÄ·À»¤Ã¤Çø¡£¡£¡£¡£


BeijingCrypt±äÖÖÀÕË÷²¡¶¾¹¥»÷ÊÖ·¨ÆÊÎö


ÒÔ½üÆÚijÆóÒµÔâÓöµÄBeijingCrypt±äÖÖÀÕË÷²¡¶¾¹¥»÷ΪÀý£¬£¬£¬¸ÃÊÂÎñ¼´ÊôÓڵ䷶µÄÎÞ´úÂëÎó²îʹÓÃÐͶ¯Ì¬¹¥»÷¡£¡£¡£¡£¹¥»÷Á´Â·ÍêÈ«ÍÑÀë´úÂë²ãÃæ£¬£¬£¬´ÓÊÖÒÕÉÏÈÃClaude Code SecurityµÈAI´úÂ빤¾ßʧȥ·À»¤×÷Óᣡ£¡£¡£


? ÈëÇÖÁ´Â·Òþ²Ø×¨Òµ£º¹¥»÷Õßͨ¹ý±©Á¦ÆÆ½â¹¥ÆÆSQL ServerÊý¾Ý¿âÃÜÂ룬£¬£¬Íê³É³õÊ¼Í»ÆÆºóÁ¬Ã¦Ö´ÐÐPowerShell¶ñÒâÏÂÁ£¬£¬Ö²ÈëCobaltStrikeºóÃÅ£¬£¬£¬½ø¶øÏÂÔØÍøÂçɨÃ蹤¾ßÓëÀÕË÷³ÌÐòµÄ¶ñÒâÎļþ¡£¡£¡£¡£Õû¸öÀú³ÌÒÀÍÐÖÕ¶ËÀú³ÌÖð²ãÍÆ½ø£¬£¬£¬ÐÐΪÒþ²ØÇÒÖ±Ö¸½¹µãÊý¾Ý¿â¡£¡£¡£¡£

¼ÓÃÜÆÆËð¾ßÓÐɱ¾øÐÔ£º²¡¶¾ÀÖ³ÉÖ²Èëºó£¬£¬£¬Ëæ¼´¶ÔÊý¾Ý¿â±¸·Ý¡¢×°ÖóÌÐò¡¢°ì¹«ë¹¼þµÈ½¹µã×ʲú¾ÙÐиßÇ¿¶È¼ÓÃÜ£¬£¬£¬Îļþºó׺ͳһ¸ÄΪ.bixi£¬£¬£¬²¢ÁôÏÂÀÕË÷ÐÅ¡£¡£¡£¡£ÈôÆóÒµÎÞÓÐÓñ¸·Ý£¬£¬£¬½¹µãÊý¾Ý½«ÃæÁÙÓÀÊÀÐÔɥʧ£¬£¬£¬ÓªÒµÔËÐÐÔâÊÜÑÏÖØ¹¥»÷¡£¡£¡£¡£

¹¥»÷ÐÐΪ¾ß±¸ÆÕÊÊÐÔ£º¸Ã¹¥»÷ÎÞÐèʹÓÃÆóÒµ×ÔÑлò¿ªÔ´´úÂëµÄÎó²î£¬£¬£¬½öÕë¶ÔÖÕ¶Ë×°±¸¡¢Êý¾Ý¿âµÄ»ù´¡È¨ÏÞÓë¶Ë¿Ú·À»¤¶Ì°å£¬£¬£¬Èκα£´æÈõÃÜÂë¡¢¶Ë¿Ú̻¶¡¢ÐÐΪ¼à²âȱʧµÄÆóÒµ¶¼¿ÉÄܳÉΪĿµÄ¡£¡£¡£¡£


ͼƬ1.jpg

Îļþ±»¼ÓÃܺ󣬣¬£¬ºó׺¾ù±äΪ.bixi


ͼƬ2.png

BeijingCrypt±äÖÖÀÕË÷²¡¶¾µÄÀÕË÷ÐÅ


EDRÔËÐÐʱ·À»¤ ¶¯Ì¬¼à²â ¾«×¼×è»÷


ÃæÁٴ˴θßÄѶȶ¯Ì¬¹¥»÷£¬£¬£¬¼øºÚµ£±£ÍøÌì«‘EDRÒÀ¸½ÖÕ¶ËÐÐΪʵʱ¼à²â¡¢¹¥»÷Àú³ÌÊ÷ËÝÔ´¡¢¶ñÒâ³ÌÐò¾«×¼Ê¶±ðµÈ½¹µãÊÖÒÕ£¬£¬£¬ÊµÏÖÁ˶Թ¥»÷µÄÈ«Á÷³Ì×èµ²¡£¡£¡£¡£


Ò»¡¢ºÁÃë¼¶Òì³£ÐÐΪ¼ì²â


ͨ¹ý¶ÔÖÕ¶ËÀú³ÌµÄʵʱ¼à¿Ø£¬£¬£¬¾«×¼²¶»ñµ½SQLServerÀú³ÌÖ´ÐеĸßΣpowershell¶ñÒâÏÂÁ£¬£¬µÚһʱ¼äʶ±ð³öÒì³£Àú³ÌÐÐΪ£¬£¬£¬ÊµÏÖ¶Ô¹¥»÷ÐÐΪµÄÔçÆÚÔ¤¾¯£¬£¬£¬´Óʱ¼äά¶ÈѹËõ¹¥»÷ʵÑé¿Õ¼ä¡£¡£¡£¡£


ͼƬ3.png

SQLServerÀú³ÌÖ´ÐÐpowershellÏÂÁîÀú³ÌÊ÷


¶þ¡¢È«Á´Â·¹¥»÷ËÝÔ´


ͨ¹ý¹¹½¨¹¥»÷Àú³ÌÊ÷£¬£¬£¬ÇåÎú»¹Ô­ÁË´Ówininit.exeµ½services.exe£¬£¬£¬ÔÙµ½sqlservr.exe£¬£¬£¬×îÖÕ´¥·¢cmd.exeÓëpowershell.exeÖ´ÐжñÒâÏÂÁîµÄÍêÕûÀú³ÌÊ÷£¬£¬£¬ÎªÇå¾²´¦Öóͷ£Ìṩ¾«×¼µÄÊÖÒÕÒÀ¾Ý¡£¡£¡£¡£


ͼƬ4.png

Ö²ÈëCobaltStrikeºóÃÅÏÂÁî


Èý¡¢¶àά¶È¶ñÒâ³ÌÐòʶ±ð


»ùÓÚÌØÕ÷¿âÆ¥ÅäÓëÐÐΪÆÊÎöÏàÁ¬ÏµµÄÊÖÒÕÊֶΣ¬£¬£¬ÀÖ³Éʶ±ð²¢±ê¼ÇÁËCobaltStrikeºóÃÅ¡¢ÍøÂçɨÃ蹤¾ß¡¢ÀÕË÷³ÌÐòµÈÖÖÖÖ¶ñÒâ³ÌÐò£¬£¬£¬Ã÷È·ÖÖÖÖΣº¦µÄÊÖÒÕÀàÐÍÓë´¦Öóͷ£½¨Ò飬£¬£¬ÊµÏÖ¶Ô¶ñÒâ³ÌÐòµÄ¾«×¼×è¶Ï¡£¡£¡£¡£


ͼƬ5.png

Ìì«‘EDR²¡¶¾²éɱ¼ì²â³ö´ËÀÕË÷²¡¶¾Ïà¹ØÀú³Ì


ËÄ¡¢Öն˲ãÃæÈ«Á÷³Ì×èµ²


´Ó¶ñÒâÏÂÁîÖ´ÐС¢ºóÃÅÖ²Èëµ½¶ñÒâÎļþÏÂÔØ£¬£¬£¬ÔÚÖն˲ãÃæÓÐÓÃ×èµ²¹¥»÷¸÷»·½Ú£¬£¬£¬×èÖ¹²¡¶¾Èö²¥ÓëÎļþµÄ´ó¹æÄ£¼ÓÃÜ£¬£¬£¬ÎªÆóÒµ×°±¸ºÍÊý¾ÝÇå¾²ÖþÀÎÁËÖÕ¶ËÊÖÒÕ·ÀµØ¡£¡£¡£¡£


´Ë´ÎBeijingCryptÀÕË÷¹¥»÷ÊÂÎñÅú×¢£¬£¬£¬AIÊÖÒÕËäΪ´úÂëÎó²î·À»¤ÌṩÁËÓÐÓÃÊֶΣ¬£¬£¬µ«ÒÀÀµÎÞ´úÂëÎó²îµÄ¶¯Ì¬¹¥»÷²¢Î´ÏûÊÅ£¬£¬£¬·´¶øÒÔ¸üÒþ²ØµÄÊֶΡ¢¸üÆÕÊʵÄ·¾¶£¬£¬£¬³ÉΪÆóҵĿ½ñÃæÁÙµÄÖ÷ÒªÇå¾²Íþв¡£¡£¡£¡£´ÓÊÖÒÕÊôÐÔ¿´£¬£¬£¬EDRµÈ¶¯Ì¬ÔËÐÐʱ·À»¤²úÆ·¾Û½¹ÐÐΪ¼à²âÓëʵʱ×èµ²£¬£¬£¬Êܾ²Ì¬AI¹¤¾ßÓ°Ïì×îС£¡£¡£¡£¬£¬£¬ÊÇÓ¦¶Ô´ËÀ๥»÷µÄ½¹µãÊֶΣ¬£¬£¬Ò²ÊÇÍøÂçÇ徲ϵͳÖо߱¸¸ßÊÖÒÕ±ÚÀݵÄÒªº¦»·½Ú¡£¡£¡£¡£


ÍêÉÆµÄ´úÂë²¢²»µÈͬÓÚÔËÐÐʱµÄÇå¾²£¬£¬£¬½ñÊÀÂë¿ÉÓÉAIÌìÉú£¬£¬£¬·ÀÓùÄÜÁ¦Ò²±ØÐèÏòÖÇÄÜÌå½ø»¯¡£¡£¡£¡£¼øºÚµ£±£ÍøÒ»Á¬Éî¸ûEDRÖÕ¶ËÇå¾²ÁìÓò£¬£¬£¬½«AIÖÇÄÜÆÊÎöÓëEDRʵʱ·À»¤Éî¶ÈÈںϣ¬£¬£¬Í¨¹ýÒ»Á¬ÊÖÒÕÁ¢Òì´òÔìÈ«·½Î»µÄÖÕ¶ËÇå¾²½â¾ö¼Æ»®£¬£¬£¬ÎªÓû§ÖþÀΡ°ÔËÐÐʱ¡±Óë¡°AI¶Ô¿¹¡±Ë«ÖØ·ÀµØ¡£¡£¡£¡£