<p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; font-weight: 700; color: rgb(0, 176, 80);">一旦我们<a href="http://www.52bug.cn/sort/Security" target="_blank" style="color: rgb(0, 175, 240);">渗透</a>进了内网，我们往往需要尽可能多的了解以及收集内网的信息，这将决定我们下一步的提权和渗透行为。而在内部侦察中，传统的方式是使用Windows内置命令（如net view，net user等）来获取主机和域的信息。但这些命令并不隐蔽，它们极有可能被管理人员和监控系统所发现。因此，为了避免这种情况，我们可以使用其它的方法。例如我们可以使用PowerShell和WMI，来进行态势感知躲避检测。</span></p><h2 style="margin-top: 30px; margin-bottom: 15px; font-size: 18px; font-family: 微软雅黑; box-sizing: border-box; line-height: 1.1; color: rgb(55, 56, 56);">PowerView</h2><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">PowerView是由<a href="https://twitter.com/harmj0y" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;">Will Schroeder</a>开发的PowerShell脚本，属于<a href="https://github.com/PowerShellMafia/PowerSploit" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;">PowerSploit</a>框架和Empire的一部分。该脚本完全依赖于PowerShell和WMI（Windows Management Instrumentation）查询。从现有的meterpreter会话中，可以使用以下命令加载和执行PowerView，以检索有关该域的信息：</p><pre style="margin-top: 0px; margin-bottom: 0px; padding: 0px; color: rgb(74, 74, 74); font-size: 14px; background-color: rgb(255, 255, 255); box-sizing: border-box; overflow: auto; font-family: Menlo, Monaco, Consolas, "font-size:13px;padding:9.5px;margin-top:0px;margin-bottom:15px;line-height:1.42857;color:#333333;word-break:break-all;word-wrap:break-word;background-color:#F3F3F3;border:1px solid #E4E4E4;border-radius:4px;"; position: relative;">load&nbsp;powershell
powershell_import&nbsp;/root/Desktop/PowerView.ps1
powershell_execute&nbsp;Get-NetDomain</pre><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="color: rgb(6, 154, 239);"><span style="background-image: initial; background-position: 0px 0px; background-size: initial; background-repeat: initial; background-attachment: initial; background-origin: initial; background-clip: initial; margin-right: auto; margin-left: auto;"><img alt="PowerView：一个可以帮助你躲避检测的内网信息收集脚本" src="http://image.3001.net/images/20180530/15276352967384.png!small" width="690" style="border: 0px; box-sizing: border-box; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></span></span></p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">PowerView有各种可以发现本地管理员的cmdlet。</p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><a href="http://image.3001.net/images/20180530/15276353137774.png" class="highslide-image" target="_blank" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;"><img alt="PowerView：一个可以帮助你躲避检测的内网信息收集脚本" src="http://image.3001.net/images/20180530/15276353137774.png!small" width="690" style="border: 0px; box-sizing: border-box; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">Invoke-UserHunter可以帮助扩展网络访问，因为它可以识别用户登录的系统，并验证当前用户是否具有对这些主机的本地管理员访问权限。</p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><a href="http://image.3001.net/images/20180530/15276353311888.png" class="highslide-image" target="_blank" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;"><img alt="PowerView：一个可以帮助你躲避检测的内网信息收集脚本" src="http://image.3001.net/images/20180530/15276353311888.png!small" width="690" style="border: 0px; box-sizing: border-box; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">由于PowerView包含多个cmdlet，因此还可以检索域信息。</p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><a href="http://image.3001.net/images/20180530/15276353493551.png" class="highslide-image" target="_blank" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;"><img alt="PowerView：一个可以帮助你躲避检测的内网信息收集脚本" src="http://image.3001.net/images/20180530/15276353493551.png!small" width="690" style="border: 0px; box-sizing: border-box; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">PowerView也在Empire内部实现。下图显示了网络的域策略。</p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><a href="http://image.3001.net/images/20180530/15276353692133.png" class="highslide-image" target="_blank" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;"><img alt="PowerView：一个可以帮助你躲避检测的内网信息收集脚本" src="http://image.3001.net/images/20180530/15276353692133.png!small" width="690" style="border: 0px; box-sizing: border-box; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">还有一些模块可以执行基于主机的枚举。</p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><a href="http://image.3001.net/images/20180530/15276353874276.png" class="highslide-image" target="_blank" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;"><img alt="PowerView：一个可以帮助你躲避检测的内网信息收集脚本" src="http://image.3001.net/images/20180530/15276353874276.png!small" width="690" style="border: 0px; box-sizing: border-box; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">另外还有一个PowerView的Python实现，如果提供了证书，它可以从不属于域的一部分的主机执行。</p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><a href="http://image.3001.net/images/20180530/15276354048194.png" class="highslide-image" target="_blank" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;"><img alt="PowerView：一个可以帮助你躲避检测的内网信息收集脚本" src="http://image.3001.net/images/20180530/15276354048194.png!small" width="690" style="border: 0px; box-sizing: border-box; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><h2 style="margin-top: 30px; margin-bottom: 15px; font-size: 18px; font-family: 微软雅黑; box-sizing: border-box; line-height: 1.1; color: rgb(55, 56, 56);">HostRecon</h2><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">还有一个PowerShell脚本，它可以自动实现主机中的态势感知任务。<a href="https://twitter.com/dafthack" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;">Beau Bullock</a>开发了<a href="https://github.com/dafthack/HostRecon" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;">HostRecon</a>，并可以使用PowerShell和WMI查询从主机检索各种信息以逃避检测。</p><pre style="margin-top: 0px; margin-bottom: 0px; padding: 0px; color: rgb(74, 74, 74); font-size: 14px; background-color: rgb(255, 255, 255); box-sizing: border-box; overflow: auto; font-family: Menlo, Monaco, Consolas, "font-size:13px;padding:9.5px;margin-top:0px;margin-bottom:15px;line-height:1.42857;color:#333333;word-break:break-all;word-wrap:break-word;background-color:#F3F3F3;border:1px solid #E4E4E4;border-radius:4px;"; position: relative;">powershell_import&nbsp;/root/Desktop/HostRecon.ps1
powershell_execute&nbsp;Invoke-HostRecon</pre><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><a href="http://image.3001.net/images/20180530/15276354223983.png" class="highslide-image" target="_blank" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;"><img alt="PowerView：一个可以帮助你躲避检测的内网信息收集脚本" src="http://image.3001.net/images/20180530/15276354223983.png!small" width="690" style="border: 0px; box-sizing: border-box; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">HostRecon可以枚举本地用户和主机的本地管理员。</p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><a href="http://image.3001.net/images/20180530/1527635441754.png" class="highslide-image" target="_blank" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;"><img alt="PowerView：一个可以帮助你躲避检测的内网信息收集脚本" src="http://image.3001.net/images/20180530/1527635441754.png!small" width="690" style="border: 0px; box-sizing: border-box; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">该脚本将执行一系列检查来确定防火墙状态，安装了反病毒解决方案，如果使用LAPS和应用程序白名单产品。</p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><a href="http://image.3001.net/images/20180530/15276354612068.png" class="highslide-image" target="_blank" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;"><img alt="PowerView：一个可以帮助你躲避检测的内网信息收集脚本" src="http://image.3001.net/images/20180530/15276354612068.png!small" width="690" style="border: 0px; box-sizing: border-box; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">该脚本还会尝试识别域名密码策略，域控制器和域管理员等域名信息。</p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><a href="http://image.3001.net/images/20180530/15276354819048.png" class="highslide-image" target="_blank" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;"><img alt="PowerView：一个可以帮助你躲避检测的内网信息收集脚本" src="http://image.3001.net/images/20180530/15276354819048.png!small" width="690" style="border: 0px; box-sizing: border-box; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><h2 style="margin-top: 30px; margin-bottom: 15px; font-size: 18px; font-family: 微软雅黑; box-sizing: border-box; line-height: 1.1; color: rgb(55, 56, 56);">HostEnum</h2><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">Andrew Chiles开发了一个类似的脚本HostRecon，该脚本在主机中执行时会提供详细信息。HostEnum既可以在本地执行，也可以从内存中执行，并且可以以HTML格式生成输出。</p><pre style="margin-top: 0px; margin-bottom: 0px; padding: 0px; color: rgb(74, 74, 74); font-size: 14px; background-color: rgb(255, 255, 255); box-sizing: border-box; overflow: auto; font-family: Menlo, Monaco, Consolas, "font-size:13px;padding:9.5px;margin-top:0px;margin-bottom:15px;line-height:1.42857;color:#333333;word-break:break-all;word-wrap:break-word;background-color:#F3F3F3;border:1px solid #E4E4E4;border-radius:4px;"; position: relative;">load&nbsp;powershell
powershell_import&nbsp;/root/Desktop/HostEnum.ps1
powershell_shell
Invoke-HostEnum&nbsp;-Local&nbsp;-Domain&nbsp;HostEnum</pre><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><a href="http://image.3001.net/images/20180530/15276354997073.png" class="highslide-image" target="_blank" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;"><img alt="PowerView：一个可以帮助你躲避检测的内网信息收集脚本" src="http://image.3001.net/images/20180530/15276354997073.png!small" width="690" style="border: 0px; box-sizing: border-box; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">参数<span style="box-sizing: border-box; font-weight: 700; word-wrap: break-word; word-break: break-word; line-height: 24px;">-Domain</span>将执行某些域检查，如检索域用户列表和其他域信息。</p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><a href="http://image.3001.net/images/20180530/15276355202170.png" class="highslide-image" target="_blank" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;"><img alt="PowerView：一个可以帮助你躲避检测的内网信息收集脚本" src="http://image.3001.net/images/20180530/15276355202170.png!small" width="690" style="border: 0px; box-sizing: border-box; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">域信息：</p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><a href="http://image.3001.net/images/20180530/15276355373645.png" class="highslide-image" target="_blank" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;"><img alt="PowerView：一个可以帮助你躲避检测的内网信息收集脚本" src="http://image.3001.net/images/20180530/15276355373645.png!small" width="690" style="border: 0px; box-sizing: border-box; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><h2 style="margin-top: 30px; margin-bottom: 15px; font-size: 18px; font-family: 微软雅黑; box-sizing: border-box; line-height: 1.1; color: rgb(55, 56, 56);">RemoteRecon</h2><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">在获得本地管理员凭证并将这些凭证共享到多个主机的情况下，可以利用WMI来执行远程主机上的态势感知。<a href="https://github.com/xorrior/RemoteRecon" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;">RemoteRecon</a>由<a href="https://twitter.com/xorrior" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;">Chris Ross</a>开发，其目的是让红队无需部署原始植入物的情况下即可进行侦察。该脚本可以捕获击键和屏幕截图，执行命令和shellcode，还可以加载PowerShell脚本以执行其他任务。</p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">在进行任何操作之前，需要使用本地管理员凭据将脚本首先远程安装到主机中，或者如果当前用户已经是目标主机上的本地管理员，则只需提供计算机名称。</p><pre style="margin-top: 0px; margin-bottom: 0px; padding: 0px; color: rgb(74, 74, 74); font-size: 14px; background-color: rgb(255, 255, 255); box-sizing: border-box; overflow: auto; font-family: Menlo, Monaco, Consolas, "font-size:13px;padding:9.5px;margin-top:0px;margin-bottom:15px;line-height:1.42857;color:#333333;word-break:break-all;word-wrap:break-word;background-color:#F3F3F3;border:1px solid #E4E4E4;border-radius:4px;"; position: relative;">Import-Module&nbsp;.\RemoteRecon.ps1&nbsp;Install-RemoteRecon&nbsp;-ComputerName&nbsp;&#39;WIN-2NE38K15TGH&#39;</pre><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><a href="http://image.3001.net/images/20180530/1527635565452.png" class="highslide-image" target="_blank" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;"><img alt="PowerView：一个可以帮助你躲避检测的内网信息收集脚本" src="http://image.3001.net/images/20180530/1527635565452.png!small" width="690" style="border: 0px; box-sizing: border-box; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;">通过脚本执行的命令输出可以使用Results参数进行检索。</p><pre style="margin-top: 0px; margin-bottom: 0px; padding: 0px; color: rgb(74, 74, 74); font-size: 14px; background-color: rgb(255, 255, 255); box-sizing: border-box; overflow: auto; font-family: Menlo, Monaco, Consolas, "font-size:13px;padding:9.5px;margin-top:0px;margin-bottom:15px;line-height:1.42857;color:#333333;word-break:break-all;word-wrap:break-word;background-color:#F3F3F3;border:1px solid #E4E4E4;border-radius:4px;"; position: relative;">Invoke-PowerShellCmd&nbsp;-ComputerName&nbsp;&#39;WIN-2NE38K15TGH&#39;&nbsp;-Cmd&nbsp;"ps&nbsp;-name&nbsp;exp"&nbsp;-Verbose
Invoke-PowerShellCmd&nbsp;-ComputerName&nbsp;&#39;WIN-2NE38K15TGH&#39;&nbsp;-Results</pre><h2 style="margin-top: 30px; margin-bottom: 15px; font-size: 18px; font-family: 微软雅黑; box-sizing: border-box; line-height: 1.1; color: rgb(55, 56, 56);"><a href="http://image.3001.net/images/20180530/15276355877942.png" class="highslide-image" target="_blank" style="outline: none; color: rgb(102, 102, 102); box-sizing: border-box; background: 0px 0px;"><img alt="PowerView：一个可以帮助你躲避检测的内网信息收集脚本" src="http://image.3001.net/images/20180530/15276355877942.png!small" width="690" style="border: 0px; box-sizing: border-box; vertical-align: middle; max-width: 100%; display: block; margin: 15px auto;"/></a></h2><h2 style="margin-top: 30px; margin-bottom: 15px; font-size: 18px; font-family: 微软雅黑; box-sizing: border-box; line-height: 1.1; color: rgb(55, 56, 56);">参考</h2><blockquote style="margin-bottom: 20px; padding: 10px 20px; quotes: none; font-size: 14px; box-sizing: border-box; border-left: 5px solid rgb(238, 238, 238); background: rgb(247, 247, 247); color: rgb(88, 88, 88); font-family: 微软雅黑;"><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word;"><a href="https://github.com/PowerShellMafia/PowerSploit/tree/master/Recon" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;">https://github.com/PowerShellMafia/PowerSploit/tree/master/Recon</a></p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word;"><a href="https://www.blackhillsinfosec.com/hostrecon-situational-awareness-tool/" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;">https://www.blackhillsinfosec.com/hostrecon-situational-awareness-tool/</a></p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word;"><a href="http://threatexpress.com/2017/05/invoke-hostenum/" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;">http://threatexpress.com/2017/05/invoke-hostenum/</a></p><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word;"><a href="https://github.com/dafthack/HostRecon" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;">https://github.com/dafthack/HostRecon</a></p><p style="margin-top: 0px; margin-bottom: 0px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word;"><a href="https://github.com/xorrior/RemoteRecon" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;">https://github.com/xorrior/RemoteRecon</a></p></blockquote><p style="margin-top: 0px; margin-bottom: 10px; box-sizing: border-box; font-size: 15px; line-height: 26px; word-break: break-word; color: rgb(88, 88, 88); font-family: 微软雅黑;"><span style="box-sizing: border-box; word-wrap: break-word; word-break: break-word; color: rgb(159, 163, 168);"><span style="box-sizing: border-box; font-weight: 700;">*参考来源：<a href="https://pentestlab.blog/2018/05/28/situational-awareness/" style="color: rgb(6, 154, 239); box-sizing: border-box; background: 0px 0px;">pentestlab</a>，FB小编 secist 编译，转自FreeBuf</span></span></p><p><br/></p>