1. dns request from C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache
2. disable dnscache REG add "HKLM\SYSTEM\CurrentControlSet\services\Dnscache" /v Start /t REG_DWORD /d 4 /f
3. source to C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s NcbService
4. NcbService (Network Connection Broker 允许 Windows 应用商店应用从 Internet 接收通知的代理连接。) ncbservice.dl
5. NcbService 依赖 连接设备平台服务(此服务用于连接设备平台方案)
6. 禁用 Network Connection Broker 服务
7. MsMpEng.exe ( Antimalware Service Executable )发出 dns 请求( C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MsMpEng.exe )
8. 关闭 windows defender ( reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender" /v "DisableAntiSpyware" /d 1 /t REG_DWORD /f )
9. C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Winmgmt(Windows Management Instrumentation) WMI 服务
10. wmi 相关文档 url
https://www.freebuf.com/articles/system/187792.html11. wmi 检测工具
https://www.slideshare.net/Hackerhurricane/detecting-wmi-exploitation-v11_______________________
以上是今天的进度,初步缩小范围至 wmi