edrhunt 扫描 windows 服务、驱动程序、进程、注册表以查找已安装的 edr(端点检测和响应)。

go install github.com/FourCoreLabs/EDRHunt/cmd/EDRHunt@master用法查找已安装的 EDR代码语言:javascript代码运行次数:0运行复制<code class="javascript">$ .\EDRHunt.exe scan[EDR]Detected EDR: Windows DefenderDetected EDR: Kaspersky Security</code>
<code class="javascript">$ .\EDRHunt.exe allRunning in user mode, escalate to admin for more details.Scanning processes, services, drivers, and registry...[PROCESSES]Suspicious Process Name: MsMpEng.exeDescription: MsMpEng.exeCaption: MsMpEng.exeBinary:ProcessID: 6764Parent Process: 1148Process CmdLine :File Metadata:Matched Keyword: [msmpeng]Suspicious Process Name: NisSrv.exeDescription: NisSrv.exeCaption: NisSrv.exeBinary:ProcessID: 9840Parent Process: 1148Process CmdLine :File Metadata:Matched Keyword: [nissrv]...</code>
<code class="javascript"> __________ ____ __ ____ ___ ________ / ____/ __ \/ __ \ / / / / / / / | / /_ __/ / __/ / / / / /_/ / / /_/ / / / / |/ / / / / /___/ /_/ / _, _/ / __ / /_/ / /| / / //_____/_____/_/ |_| /_/ /_/\____/_/ |_/ /_/FourCore Labs (https://fourcore.vision) | Version: 1.1Running in user mode, escalate to admin for more details.[DRIVERS]Suspicious Driver Module: WdFilter.sysDriver FilePath: c:\windows\system32\drivers\wd\wdfilter.sysDriver File Metadata: ProductName: Microsoft® Windows® Operating System OriginalFileName: WdFilter.sys InternalFileName: WdFilter Company Name: Microsoft Corporation FileDescription: Microsoft antimalware file system filter driver ProductVersion: 4.18.2109.6 Comments: LegalCopyright: © Microsoft Corporation. All rights reserved. LegalTrademarks:Matched Keyword: [antimalware malware]Suspicious Driver Module: hvsifltr.sysDriver FilePath: c:\windows\system32\drivers\hvsifltr.sysDriver File Metadata: ProductName: Microsoft® Windows® Operating System OriginalFileName: hvsifltr.sys.mui InternalFileName: hvsifltr.sys Company Name: Microsoft Corporation FileDescription: Microsoft Defender Application Guard Filter Driver ProductVersion: 10.0.19041.1 Comments: LegalCopyright: © Microsoft Corporation. All rights reserved. LegalTrademarks:Matched Keyword: [defender]Suspicious Driver Module: WdNisDrv.sysDriver FilePath: c:\windows\system32\drivers\wd\wdnisdrv.sysDriver File Metadata: ProductName: Microsoft® Windows® Operating System OriginalFileName: wdnisdrv.sys InternalFileName: wdnisdrv.sys Company Name: Microsoft Corporation FileDescription: Windows Defender Network Stream Filter ProductVersion: 4.18.2109.6 Comments: LegalCopyright: © Microsoft Corporation. All rights reserved. LegalTrademarks:Matched Keyword: [defender]...</code>
<code class="javascript">$ .\EDRHunt.exe -s</code>
<code class="javascript">$ .\EDRHunt.exe -d</code>
<code class="javascript">$ .\EDRHunt.exe -r</code>
目前可用的 EDR 检测:
Windows DefenderKaspersky SecuritySymantec SecurityCrowdstrike SecurityMcafee SecurityCylance SecurityCarbon BlackSentinelOneFireEyehttps://github.com/FourCoreLabs/EDRHunt
以上就是神兵利器 - EDRHunt的详细内容,更多请关注php中文网其它相关文章!
每个人都需要一台速度更快、更稳定的 PC。随着时间的推移,垃圾文件、旧注册表数据和不必要的后台进程会占用资源并降低性能。幸运的是,许多工具可以让 Windows 保持平稳运行。
Copyright 2014-2025 https://www.php.cn/ All Rights Reserved | php.cn | 湘ICP备2023035733号