×ðÁú¿­Ê±

֤ȯ¼ò³Æ£º×ðÁú¿­Ê± ֤ȯ´úÂ룺002212
È«Ììºò7x24Сʱ·þÎñ£º 400-777-0777

¾«×¼¶¨Î» £¬¾ÛÁ¦³ö»÷£¡×ðÁú¿­Ê±¶à¿î²úÆ·Áª¶¯·ÀÓùSymbiote

¾«×¼²éɱSymbiote£¡×ðÁú¿­Ê±EDR¡¢×Ô˳ӦÇå¾²·ÀÓùϵͳ¡¢¹ýÂËÍø¹ØÏµÍ³¡¢½©Ä¾ÈäϵͳµÈ¶à¿î²úÆ·¾ù¿É¾«×¼¼ì²â²¢²éɱ¸Ã¶ñÒâÈí¼þ £¬×¥½ôÉý¼¶Å¶

¾«×¼¶¨Î» £¬¾ÛÁ¦³ö»÷£¡×ðÁú¿­Ê±¶à¿î²úÆ·Áª¶¯·ÀÓùSymbiote

Ðû²¼Ê±¼ä£º2022-09-19
ä¯ÀÀ´ÎÊý£º4716
·ÖÏí£º

SymbioteÏÈÈÝ

SymbioteÊÇÖ÷ÒªÕë¶ÔLinuxϵͳµÄ¶ñÒâÈí¼þ £¬ÔÚ2021Äê11ÔÂÊ״α»·¢Ã÷ £¬Ö÷ÒªÕë¶ÔÀ­¶¡ÃÀÖ޵ĽðÈÚ²¿·Ö £¬Òµ½çÆÕ±éÐÎò¡°ÏÕЩ²»¿ÉÄܱ»¼ì²âµ½¡±¡£¸Ã¶ñÒâÈí¼þ¿Éͨ¹ý¡°¼ÄÉúѬȾ¡±ÏµÍ³Ñ¬È¾ËùÓÐÕýÔÚÔËÐеÄÀú³Ì £¬²¢ÎªÍþв¼ÓÈëÕßÌṩrootkit¹¦Ð§¡¢Ô¶³Ì»á¼ûµÈ¡£

ÓÉÓÚSymbioteÒþ²ØÁËËùÓÐÎļþ¡¢Àú³Ì £¬Òò´ËÔÚÊÜѬȾµÄ»úеÉÏÖ´ÐÐʵʱȡ֤¿ÉÄܲ»»á·¢Ã÷ÈκÎÎÊÌâ¡£³ýÁËRootkitÖ®Íâ £¬Symbiote»¹Îª¹¥»÷ÕßÌṩÁËÒ»¸öºóÃÅ £¬¹¥»÷Õß¿ÉÒÔʹÓÃÓ²±àÂëÃÜÂëÒÔ»úеÉϵÄÈκÎÓû§Éí·ÝµÇ¼ £¬²¢ÒÔ×î¸ßȨÏÞÖ´ÐÐÏÂÁî¡£ÏÖÔÚ £¬×ðÁú¿­Ê±EDR¡¢×Ô˳ӦÇå¾²·ÀÓùϵͳ¡¢¹ýÂËÍø¹ØÏµÍ³¡¢½©Ê¬ÍøÂçľÂíºÍÈ䳿¼à²âÓë´¦Öóͷ£ÏµÍ³ £¬ÒÔ¼°Ð°汾µÄÈëÇÖ¼ì²âϵͳ¡¢ÈëÇÖ·ÀÓùϵͳµÈ²úÆ·¾ù¿É¾«×¼¼ì²â²¢²éɱ¸Ã¶ñÒâÈí¼þ £¬±ÜÃâÍþвÊÂÎñ±¬·¢ £¬Ìá¸ßÖÕ¶ËÇéÐÎÇå¾²¡£

½ÓÏÂÀ´ £¬Ò»Æð½ÒÏþSymbioteÊÇÔõÑùÒþ²Ø×Ô¼ºµÄ~

ÑùÌìÖ°Îö

¾²Ì¬ÑùÌìÖ°Îö

SymbioteÊÇÒ»ÖÖÒÉËÆÕë¶ÔÀ­¶¡ÃÀÖÞ½ðÈÚ²¿·ÖµÄLinuxƽ̨rootkit £¬ÆäʹÓÃÁ˶àÖÖhookÊÖÒÕÒþ²Ø×ÔÉíÐÐΪ £¬¾ßÓнϺõÄÃâɱÐÔ £¬Ö÷Òª¹¦Ð§ÊÇÇÔÈ¡µÇ¼ƾ֤²¢ÔÚÊÜѬȾ»úеÉÏÖ²ÈëºóÃÅ¡£

ÂÄÀú³¤Ê±ÆÚµÄ¿ª·¢Ñݽø £¬ÏÖÔÚSymbiote½Ïеİ汾ÊÇÃûΪsearch.soµÄ64λELF¹²ÏíÄ¿µÄÎļþ¡£

Ëüͨ¹ýÉèÖÃLD_PRELOADÇéÐαäÁ¿µÄÖµ £¬ÔÚ³ÌÐòÔËÐÐǰÓÅÏȼÓÔØ¶ñÒ⶯̬Á´½Ó¿âsearch.so £¬search.soÔÚµ¼³öº¯ÊýÖÐÐ®ÖÆÁ˶à¸ö¿âº¯Êý¡£

SymbioteʹÓÃRC4Ëã·¨¼ÓÃÜËùÓÐ×Ö·û´® £¬ÃÜԿΪHEXÊýÖµ¡°030F1513081609061C0A1A0D120217¡± £¬Ó²±àÂëÔÚELFµÄÀο¿Î»ÖÃÖС£

ËùÓб»RC4¼ÓÃܵÄ×Ö·û´®µÄ½âÃÜpython3´úÂëÈçÏ£º

DEFAULT_KEY = "\x03\x0f\x15\x13\x08\x16\x09\x06\x1c\x0a\x1a\x0d\x12\x02\x17"

def rc4(data, key=DEFAULT_KEY, skip=0):

x = 0

box = list(range(256))

x = 0

for i in list(range(256)):

x = (x + box[i] + ord(key[i % len(key)])) % 256

tmp = box[i]

tmp2 = box[x]

box[i] = box[x]

box[x] = tmp

x = 0

y = 0

out = []

if skip > 0:

for i in list(range(skip)):

x = (x + 1) % 256

y = (y + box[x]) % 256

box[x], box[y] = box[y], box[x]

for char in data:

x = (x + 1) % 256

y = (y + box[x]) % 256

box[x], box[y] = box[y], box[x]

k = box[(box[x] + box[y]) % 256]

out.append(chr(ord(char) ^ k))

return ''.join(out)

if __name__ == '__main__':

data = "\x24\xa3\x8a\x5a\xe7\x58\x82\x82\xf7\x2c\x44\xf1\x20\x67"

result = rc4(data, DEFAULT_KEY, 0)

print(result)

¶¯Ì¬µ÷ÊÔÆÊÎö

µ±Å²Óñ»search.soÎļþhookµÄº¯Êýʱ £¬ÄÚ´æÖвŻᶯ̬¼ÓÔØ¶ñÒâsoÎļþ £¬Ã»Óб»hookµÄÇéÐÎÏ»áÔÚlibc-2.13.soÖÐÁ¬Ã¦Ìî³äϵͳŲÓúžÙÐÐsyscallϵͳŲÓà £¬¶øhookÖ®ºóµÄÔ­ELF¾ÙÐÐAPIŲÓÃʱ»áͨ¹ýÒ»Ìõjmp»ã±àÖ¸ÁîÌø×ªµ½search.soµÄµ¼³öº¯ÊýÖÐÖ´ÐС£

ÐèÒª×èµ²µÄÀú³ÌÃû³ÆÁбíºÍÎļþÃû³ÆÁÐ±í»®·Ö´æ´¢ÔÚpthºÍfth±äÁ¿Ö¸ÏòµÄÆ«ÒÆ £¬Ê¹ÓÃRC4Ëã·¨ÔÚ¶¯Ì¬ÔËÐÐÖнâÃܲ¢Ä¥Á·¡£

ÈçÏÂͼËùʾÊÇsearch.so±»¼ÓÔØÊ±¶¯Ì¬½âÃܳöµÄÒþ²ØÎļþÃû³Æ £¬Ä¾ÂíÒþ²ØµÄËùÓÐÀú³ÌÁбíºÍÎļþÁбí¼û¸½Â¼²¿·Ö¡£

¹æ±ÜÊÖÒÕÆÊÎö

µ±Ê¹ÓÃlddÏÂÁîÏÔʾÈí¼þµÄÒÀÀµÏîʱ £¬ÇéÐαäÁ¿LD_TRACE_LOADED_OBJECTS»á±»ÉèÖÃΪ1 £¬¶ñÒâÈí¼þ¹Ò¹³execveº¯Êý²¢Í¨¹ý¼ì²âLD_TRACE_LOADED_OBJECTSµÄÖµÊÇ·ñΪ1 £¬½ø¶ø¾öÒéÊÇ·ñÖ´ÐÐ×èµ²lddÏÂÁîµÄ´úÂë £¬´Ó¶øÔÚÈí¼þµÄÒÀÀµÏîÖн«×ÔÉíÈ¥³ýµÖ´ïÒþ²ØÄ¿µÄ¡£

SymbioteÔÚreaddirºÍreaddir64ÖÐʵÏÖÁËÒþ²ØÎļþºÍÒþ²ØÀú³Ì £¬Ö®ºóÓ붯̬¼ÓÔØÖØ¶¨Ïòµ½pthµÄÄÚ´æÖд洢µÄÀú³ÌÃû³ÆÁбí¾ÙÐнÏÁ¿ £¬ÈôÊDZ£´æÁбíÖеÄÀú³ÌÃû×Ö £¬ÄÇôreaddirºÍreaddir64º¯Êý»áÖ±½Ó·µ»Ø¡£µ±¹ÜÀíÔËάְԱʹÓÃlsÏÂÁîʱ £¬ÎÞ·¨Éó²éµ½¶ñÒâsoÎļþ £¬µ«ÈôÊÇÖªµÀÎļþÃû³Æ¿ÉÒÔʹÓÃfindÏÂÁî̻¶ÆäλÖá£

ÔÚreaddirºÍreaddir64ÖÐͬÑùʵÏÖÁË·´¸ú×Ù¡£ÈôÊÇÔÚÀú³ÌÖеÄcmdlineÖз¢Ã÷°üÀ¨sh -c strace»òÕßstrace -sµÈÓëstraceÓйصÄÏÂÁî²ÎÊý £¬¼´ÆôÓÃÁË×·×Ù¹¦Ð§ £¬º¯ÊýÖ±½Ó·µ»Ø0¡£

ͨ¹ýhookһЩLinux¿É²åÈëÉí·ÝÑé֤ģ¿é(PAM)µÄº¯ÊýÈçpam_authenticate¡¢pam_set_itemºÍpam_acct_mgmtʵÏÖ¶Ô±»Ñ¬È¾»úеµÄÔ¶³Ì»á¼û¡£µ±Óû§ÊµÑéʹÓÃPAM·þÎñ£¨ºÃ±ÈSSHÔ¶³Ì·þÎñ£©¾ÙÐÐÉí·ÝÑé֤ʱ £¬¶ñÒâÈí¼þ»áÅжÏÌṩµÄÃÜÂëÊÇ·ñΪӲ±àÂëµÄÊýÖµ¶øÑ¡Ôñ¶ÔÓ¦µÄ´¦Öóͷ£·½·¨¡£

Òþ²ØÁ÷Á¿µÄµÚÒ»ÖÖÒªÁ죺hook fopenºÍfopen64º¯Êý¡£

µ±Ó¦ÓóÌÐòʵÑé·­¿ª/proc/net/tcpÎļþʱ £¬¶ñÒâÈí¼þ½¨ÉèÒ»¸öÔÝʱÎļþ £¬¶ÁÈ¡ÎļþÄÚÈÝʱ»á°´ÐÐÆ¥ÅäÊÇ·ñ±£´æÌض¨¶Ë¿Ú£º43253¡¢43753¡¢63424¡¢26424¡£ÈôÊÇÆ¥Åäµ½¾Í»áÌø¹ý £¬²»È» £¬¸ÃÐÐÄÚÈݻᱻдÈëÔÝʱÎļþ¡£µ±Îļþ±»É¨Ãè´¦Öóͷ£Íêʱ £¬¶ñÒâÈí¼þ¾Í»á¹Ø±ÕÔÝʱÎļþ¾ä±ú²¢½«ÔÝʱÎļþµÄÎļþÐÎò·û×÷Ϊ·µ»ØÐ§¹û¡£´ÓʵÖÊÉϽ² £¬ÕâÑùʵÏÖÁËͨ¹ýhook fopen»òfopen64µÄŲÓÃÀú³Ì £¬Òþ²ØÁ˶ñÒâÈí¼þÏëÒªÒþ²ØµÄËùÓÐÍøÂç¶Ë¿ÚµÄÅþÁ¬ÌõÄ¿¡£

Òþ²ØÁ÷Á¿µÄµÚ¶þÖÖÒªÁ죺hookº¯Êýpcap_loopºÍpcap_stats¡£

Symbioteͨ¹ýhookº¯Êýpcap_loopºÍpcap_statsÀ´Íê³ÉÕâ¸öʹÃü,¹ýÂË͵»»Ã¶¾Ù±íÖÐÓòÃû×Ó×Ö·û´®µÄUDPÁ÷Á¿¡£¸ÃÒªÁìÓÃÓÚ¹ýÂ˵ô UDP Êý¾Ý°ü £¬¶øÒÔϵÄeBPF»úÖÆÐ´×Ö½ÚÂëµÄÒªÁìÓÃÓÚ¹ýÂ˵ô TCP Êý¾Ý°ü¡£

Òþ²ØÁ÷Á¿µÄµÚÈýÖÖÒªÁ죺eBPF»úÖÆ¡£

eBPF£¨extended Berkeley Packet Filter£©ÆðÔ´ÓÚBPF £¬ËüÌṩÁËÄں˵ÄÊý¾Ý°ü¹ýÂË»úÖÆ¡£BPFµÄ»ù±¾Í·ÄÔÊǶÔÓû§ÌṩÁ½ÖÖSOCKETÑ¡ÏSO_ATTACH_FILTERºÍSO_ATTACH_BPF £¬ÔÊÐíÓû§ÔÚsokcetÉÏÌí¼Ó×Ô½ç˵µÄfilter £¬Ö»ÓÐÖª×ã¸ÃfilterÖ¸¶¨Ìõ¼þµÄÊý¾Ý°ü²Å»áÉÏ·¢µ½Óû§¿Õ¼ä¡£SO_ATTACH_FILTER²åÈëµÄÊÇcBPF´úÂë £¬SO_ATTACH_BPF²åÈëµÄÊÇeBPF´úÂë¡£eBPFÊǶÔcBPFµÄÔöÇ¿ £¬ÏÖÔÚÓû§¶ËµÄtcpdumpµÈ³ÌÐòÕÕ¾ÉÓõÄcBPF°æ±¾ £¬Æä¼ÓÔØµ½ÄÚºËÖкó»á±»ÄÚºË×Ô¶¯µÄת±äΪeBPF¡£Linux 3.15 ×îÏÈÒýÈëeBPF¡£ÆäÀ©³äÁËBPFµÄ¹¦Ð§ £¬¸»ºñÁËÖ¸Á¡£ËüÔÚÄÚºËÌṩÁËÒ»¸öÐéÄâ»ú £¬Óû§Ì¬½«¹ýÂ˹æÔòÒÔÐéÄâ»úÖ¸ÁîµÄÐÎʽת´ïµ½ÄÚºË £¬ÓÉÄÚºËÆ¾Ö¤ÕâЩָÁîÀ´¹ýÂËÍøÂçÊý¾Ý°ü¡£

ÈçÏÂΪÔÚÄں˱àÒëºóµÄ eBPF»ã±à´úÂ룺

ÈçÏÂΪÒÔÌ«ÍøÖ¡ÃûÌÃÊý¾Ý¡£Õý³£ÇéÐÎÏÂÊý¾ÝÖ¡ÊÇ´ÓDST×îÏÈËãÆð £¬12¸ö×Ö½Ú£¨0xc£©ºó¼´Êdz¤¶È»òÀàÐÍ £¬ldabsh 0xc»ã±àÖ¸Áî¼´Êǽ«Êý¾ÝÖ¡µÄÀàÐÍ×ֶμÓÔØµ½¼Ä´æÆ÷ÖС£½ÓÏÂÀ´jeq r0,0x86dd¼´ÅжÏЭÒéÀàÐÍÊÇ·ñΪIPv6¡£

×îºóÍŽáIPv6ºÍIPv4µÄÊý¾Ý±¨ÃûÌà £¬ÎÒÃÇ¿ÉÒÔµÃÖª £¬ eBPF»ã±à³ÌÐòµÄ×îÖÕÄ¿µÄÊÇҪͨ¹ýУÑéÊý¾ÝÖ¡ÖÐIPЭÒéµÄÔ´¶Ë¿ÚºÍÄ¿µÄ¶Ë¿ÚÊÇ·ñΪ43253¡¢43753¡¢63424¡¢26424Ö®Ò» £¬ÓеϰÔò¹ýÂËЧ¹ûÌØÊâ´¦Öóͷ£¡£

Symbioteͨ¹ýʹÓÃËùÓÐÕâÈýÖÖÒªÁì £¬¶ñÒâÈí¼þ¿ÉÈ·±£Òþ²ØËùÓÐÁ÷Á¿¡£

×ÛÉÏËùÊö £¬SymbioteµÄrootkitÒþ²ØÊÖÒÕµã¿ÉÒÔ¹éÄÉÈçÏ£º

×·ËݹØÁª

ÔÚ»¥ÁªÍøÉÏ¿ÉÒÔ·¢Ã÷֮ǰ×÷ÕßÔÚ¿ª·¢µÄSymbiote¾É°æ±¾Îļþ £¬Ãû³Æ»®·ÖΪkerneldev.so.bkp¡¢mt64_.so¡£ÆäÖÐÉÐÓÐÒ»¸öÃûΪcertbotx64ÊÇ¿ªÔ´µÄDNSËíµÀ¹¤¾ßÏîÄ¿dnscat±àÒë³öµÄ¿Í»§¶Ë £¬Ê¹ÓÃCÓïÑÔ±àд¡£dnscat±àÒëµÄ·þÎñÆ÷ʹÓÃRubyÓïÑÔ±àд £¬ÔËÐÐʱÒÀÀµRubyºÍGemÇéÐΡ£

Ñù±¾IOCsÁбí

¸½Â¼

·À»¤½¨Òé

ʵʱ¸üÐÂÈí¼þºÍϵͳÒÔ¼°´òÎó²î²¹¶¡ £¬½µµÍ±»Symbiote²¡¶¾Í¨¹ýÎó²îÈëÇÖµÄΣº¦¡£

ÔöÇ¿»á¼û¿ØÖÆ £¬¹Ø±Õ²»ÐëÒªµÄ¶Ë¿Ú £¬½ûÓò»ÐëÒªµÄÅþÁ¬ £¬½µµÍ×ʲúΣº¦Ì»Â¶Ãæ¡£

¸ü¸Äϵͳ¼°Ó¦ÓÃʹÓõÄĬÈÏÃÜÂë £¬ÉèÖøßÇ¿¶ÈÃÜÂëÈÏÖ¤ £¬²¢°´ÆÚ¸üÐÂÃÜÂë £¬±ÜÃâÈõ¿ÚÁî¹¥»÷¡£

¿É×°ÖÃ×ðÁú¿­Ê±Çå¾²²úÆ·ÔöÇ¿·À»¤ £¬×ðÁú¿­Ê±EDRϵͳ¡¢×Ô˳ӦÇå¾²·ÀÓùϵͳ¡¢¹ýÂËÍø¹ØÏµÍ³¡¢½©Ê¬ÍøÂçľÂíºÍÈ䳿¼à²âÓë´¦Öóͷ£ÏµÍ³ £¬ÒÔ¼°Ð°汾µÄÈëÇÖ¼ì²âϵͳ¡¢ÈëÇÖ·ÀÓùϵͳµÈ²úÆ·¾ù¿É׼ȷ¼ì²â²¢²éɱ¸Ã¶ñÒâÈí¼þ¡£

# ×ðÁú¿­Ê±EDRϵͳ·ÀÓùÉèÖÃ

1¡¢¿ªÆôÎļþʵʱ¼à¿Ø¹¦Ð§ £¬ÓÐÓÃÔ¤·ÀºÍ²éɱ¸Ã¶ñÒâÈí¼þ£»

2¡¢Í¨¹ýʹÃüÖÜÆÚÐÔ²éɱ £¬×è¶Ï¶ñÒâ¹¥»÷ÐÐΪ £¬·À»¤²¡¶¾¹¥»÷Íþв£»

3¡¢Í¨¹ýÄÚÖõÄWebshellºóÃſ⠣¬¶ÔÍøÕ¾ºóÃÅרÏî²éɱ £¬½µµÍºáÏòÈö²¥Î£º¦¡£

# ×ðÁú¿­Ê±×Ô˳ӦÇå¾²·ÀÓùϵͳ·ÀÓùÉèÖÃ

1¡¢¿ªÆô²¡¶¾ÊµÊ±¼à¿Ø¹¦Ð§ £¬¿ÉÓÐÓÃÔ¤·ÀºÍ²éɱ¸Ã¶ñÒâÈí¼þ£»

2¡¢Ö§³Ö¾«×¼¶¨Î»ÏµÍ³Îó²î £¬ÊÂǰʵʱÐÞ²¹ £¬½µµÍºáÏòѬȾΣº¦£»

3¡¢Í¨¹ýΣº¦·¢Ã÷¹¦Ð§É¨ÃèϵͳÈõ¿ÚÁî £¬½µµÍÇ徲Σº¦¡¢ïÔÌ­×ʲú̻¶¡£

# ×ðÁú¿­Ê±¹ýÂËÍø¹Ø·ÀÓùÉèÖÃ

1¡¢Éý¼¶µ½×îв¡¶¾ÌØÕ÷¿â£»

2¡¢¿ªÆôHTTP¡¢POP3¡¢SMTP¡¢FTP¡¢IMAPµÈЭÒéµÄ²¡¶¾É¨Ãè¼ì²â£»

3¡¢ÉèÖò¡¶¾¼ì²â´¦Öóͷ£Õ½ÂÔ;

4¡¢¿ªÆôÈÕÖ¾¼Í¼ºÍ±¨¾¯¹¦Ð§¡£

# ×ðÁú¿­Ê±½©Ê¬ÍøÂçľÂíºÍÈ䳿¼à²âÓë´¦Öóͷ£ÏµÍ³¼ì²âÉèÖÃ

1¡¢Éý¼¶ÍþвÇ鱨¿â°æ±¾£»

2¡¢¿ªÆôÍþвÇ鱨-¶ñÒâÎļþ¼ì²â¹¦Ð§ £¬¿ÉÓÐÓüì²â¸Ã¶ñÒâÈí¼þ¡£

# ×ðÁú¿­Ê±ÈëÇÖ¼ì²âϵͳа汾¼ì²âÉèÖÃ

1¡¢¹ºÖÃÍþвÇ鱨¿â¹¦Ð§Ä£¿é£»

2¡¢¿ªÆôÍþвÇ鱨-¶ñÒâÎļþ¼ì²â¹¦Ð§ £¬¿ÉÓÐÓüì²â¸Ã¶ñÒâÈí¼þ¡£

# ×ðÁú¿­Ê±ÈëÇÖ·ÀÓùϵͳа汾·À»¤ÉèÖÃ

1¡¢¹ºÖÃÍþвÇ鱨¿â¹¦Ð§Ä£¿é£»

2¡¢¿ªÆôÍþвÇ鱨-¶ñÒâÎļþ¼ì²â¹¦Ð§ £¬¿ÉÓÐÓ÷ÀÓù¸Ã¶ñÒâÈí¼þ¡£

²úÆ·»ñÈ¡·½·¨

¡ñ ×ðÁú¿­Ê±EDRϵͳÆóÒµ°æ¡¢×ðÁú¿­Ê±×Ô˳ӦÇå¾²·ÀÓùϵͳ¡¢×ðÁú¿­Ê±¹ýÂËÍø¹Ø¡¢×ðÁú¿­Ê±½©Ê¬ÍøÂçľÂíºÍÈ䳿¼à²âÓë´¦Öóͷ£ÏµÍ³¡¢×ðÁú¿­Ê±ÈëÇÖ¼ì²âϵͳ¡¢×ðÁú¿­Ê±ÈëÇÖ·ÀÓùϵͳÊÔÓ㺿Éͨ¹ý×ðÁú¿­Ê±ÌìÏ·ÖÖ§»ú¹¹»ñÈ¡£¨ÅÌÎÊÍøÖ·£º

http://www.topsec.com.cn/contact/£©

¡ñ ×ðÁú¿­Ê±EDRϵͳµ¥»ú°æÏÂÔØµØÖ·£ºhttp://edr.topsec.com.cn

¡ñ ×ðÁú¿­Ê±¹ýÂËÍø¹ØÏµÍ³²¡¶¾¿âÏÂÔØµØÖ·£ºftp://ftp.topsec.com.cn/·À²¡¶¾Íø¹Ø(Top-Filter)/²¡¶¾¿âÍÑ»úÉý¼¶°ü/

¡ñ ×ðÁú¿­Ê±ÍþвÇ鱨¿âÏÂÔØµØÖ·£ºftp://ftp.topsec.com.cn/×ðÁú¿­Ê±ÏÂÒ»´úÈëÇÖ·ÀÓùϵͳ(NGIDP)/ÍþвÇ鱨¿â/ ti-v2022.09.05.005.tor

TOPSEC

¶ñÒâÈí¼þÓ°ÏìÊý¾Ý¼°³ÌÐòµÄÇå¾²ÐÔ £¬¶Ô¸÷ÕþÆóµ¥Î»ÍøÂçÇå¾²¼°Éç»áÖÈÐòÔì³ÉÑÏÖØÎ£º¦¡£×÷ΪÖйúÍøÂçÇå¾²¡¢´óÊý¾ÝÓëÔÆ·þÎñÌṩÉÌ £¬×ðÁú¿­Ê±¶àÄêÉî¸ûÍøÂçÇå¾²·À»¤ÁìÓò £¬»ýµí¸»ºñµÄÊÖÒÕÓë²úÆ·ÄÜÁ¦ £¬²¢Ò»Ö±ÍƳ³öР£¬Ò»Á¬ÖúÁ¦¹ú¼ÒÍøÂçÇå¾²¿µ½¡Éú³¤¡£

×ðÁú¿­Ê±ÚÐÌýʵÑéÊÒ

ÚÐÌýʵÑéÊÒÊÇ×ðÁú¿­Ê±µÄ²¡¶¾ÆÊÎöºÍÏìÓ¦ÍÅ¶Ó £¬»ã¾Ûרҵ²¡¶¾ÆÊÎöÓëÑо¿Ö°Ô± £¬ÖÂÁ¦ÓÚÖն˶ñÒâ´úÂëµÄÄæÏòÆÊÎö¡¢ÍþвԤ¾¯¡¢×·±¾ËÝÔ´¡¢·´²¡¶¾ÊÖÒÕµÈÇå¾²Ñо¿ºÍÍþв·¢Ã÷ £¬Îª¼¯ÍÅȫϵ²úÆ·ÌṩÖÜÈ«µÄÊÖÒÕÖ§³ÖºÍÎó²îÆÊÎöÏìÓ¦¡£

Òªº¦´Ê±êÇ©£º
×ðÁú¿­Ê±EDR ×Ô˳ӦÇå¾²·ÀÓùϵͳ ¹ýÂËÍø¹ØÏµÍ³ ½©Ä¾Èäϵͳ ¾«×¼²éɱSymbiote
¿Í»§·þÎñÈÈÏß

400-777-0777
7*24Сʱ·þÎñ

ÁªÏµÓÊÏä

servicing@topsec.com.cn

ɨÂë¹Ø×¢
ÍøÕ¾µØÍ¼