공격(AD)

exchage → ad 공격(hydra) PM 5:07:26 (대입)

Untitled

rdp-ad connect 10:19 rdp-ad로그온10:25

Untitled

Untitled

17:10:24 NTLM인증을 이용한 접속 시도

Untitled

방화벽+디펜더 11:08 실패 11:23 성공

Untitled

Untitled

  1. 이전 값: Default\\Real-Time Protection\\DisableScriptScanning = 0x0
  2. 새 값: HKLM\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableScriptScanning = 0x1

Untitled