2024红队实战操作虚拟机制作.docx
设备摘要室内存16GB:序处理器86新CDDVD(SATA)自动检测IBUSB控制器存在匚显示器自动检测设备摘要里内存16GB处理器8©新CD/DVD(SATA)自动检测国USB控制器存在自动检测FD图形口加速3D图形监视器您将主机设贸用于监视器(V)O指定监视器设罡(5):监视器数量(N):任意监视窘的最大分辨率(M):红队实战操作虚拟机制作0x01虚拟机软件配置1 .使用当下最新版本VMWareWorkstationProe下载地址:https:WWW激活码:g。Ogle寻找2 .新建一个根据项目时间长短而定的硬件配置,例如:4核CPU、8G内存、60G硬盘,较长时间项目,可以参数加倍。将使用下列设置创建虚拟机:名称:Windows10×64位置:版本:Workstation17.5.x操作系统:Windows10×64硬盘:120GB,拆分内存:16384MB网络适配器:无其他设备:8个CPU内核,CD/DVD,USB控制器3 .卸载虚拟机上无关设备(声卡、摄像头、蓝牙以及系统完整完毕后的CD/DVD),并关闭加速3D图形硬件连接USB兼容性(0:USB3.1口显示所有USB愉入设备(三)I与虚拟机共享蓝牙设备(B)I44 .使用9H三USB有线网卡组网。通过虚拟机->可移动设备->xxxxx,来把USB网卡加载到指定虚拟机。5 .检杳虚拟机是否关闭共享文件夹、关闭时间同步、禁用Vne等选项。粘贴复制视情况而定。硬件选项设置摘要03常规Windows10×64A电源(3?共享文件夹已禁用3快照<5自动保护已禁用a客户机隔离访问控制未加密IFVMWareTools关闭时间同步三VNC连接已禁用ISBunity要设备视图出自动登录不可用国高级默认/默认Unity窗口效果口显示边框(B)口显示标志(八)在窗口边桩中使用自定义颜色(C)选择颜色(三)应用程序口启用应用程序菜单(E)设用摘要On常效Windows10x64A电源卬共享文件夹已禁用3快照<E)自动保护已禁用客户机隔离国启用拖放(Q)画启用复制粘贴(C)共享传感器输入口方向(Q)口动作(M)环境光(八)啕客户机隔高方访问控制未加密叵IVMwareTools关闭时间同步空VNe连接已禁用3Unity鳍设备视图为自动登录不可用回高级参认做认硬件选项0x02操作系统配置Win101 .镜像下载,自行选择版本,这里我选择的是:en2USWindoWSIOenterpriseItSC2021x64dvdd289cf96.isoISO:https:/massarave.dev/WindOWSItSClinks.html2 .在安装时选择:Windows10EnterpriseN1.TSC2021,原因如下:Windows10EnterpriseN1.TSC2021includesthesamefunctionalityasWindows10Enterprise1.TSC2021,exceptthatitdoesnotincludecertainmediarelatedtechnologies(e.g.,WindowsMediaPlayer,Camera,Music,Movies&TV)ortheSkypeapp.https:WWW.oo-O&OShutUplO+(Administrator)SearchFileActionsViewHelpCurrentUser1.ocalMachineSTATESCTTIhIGRECOMMENDeDPrivacyDisableandresetAdvertisingIDandinfoyesDisabletransmissionoftypinginformationyesDisablesuggestionsinthetimelineyesDisablesuggestionsinStartyesDisabletips,tricks,andsuggestionswhenusingWindowsyesDisableshowingsuggestedcontentintheSettingsappyesDisablethepossibilityofsuggestingtofinishthesetupofthedeviceyesDisableappnotificationslimitedDisableaccesstolocallanguageforbrowserslimitedDisabletextsuggestionswhentypingonthesoftwarekeyboardlimitedDisablesendingUR1.sfromappstoWindowsStorenoyes(三)OSOsoftwareDisablestorageofclipboardhistoryFindnewversionsathttps:/www.oo-software.m/https:QithU1.eDraaoX/Win-Debloat-ToolsSystemTweaksWinDebloatToolsv2023-11-22CustomizeSystemFeaturesSystemDebloatToolsWindowsUpdateEnableDarkThemeApplyTweaks EnableAutomaticWindowsUpdate EnableActivityHistoryUndoTweaks EnableBackgroundAppsRemoveMicrosoftEdgeOptionalFeaturesEnableClipboardHistoryRemoveOneOriveHyper-VRemoveXboxInternetExplorerEnableClipboardSyncAcrossDeViyEnableCortanaEnableHibernateEnable1.egacyContextMenurPrintins-PrintTopoFservices-FeoturesPrlntSnSXPSServkesfeaturesWindowsMediaPlayerWindowsSandboxEnableOldVolumeControlInstallSystemAppsTaskSchedulerEnableOnlineSpeechRecognitionEnablePhone1.inkEnablePhotoViewer EnableSearchAppforUnknownExt.DolbyAudioMicrosoftEdgeOneDhvePaint÷Paint3D FamilySafetyFeaturesServices WindowsSearchIndexingEnableTelemetryPhoneUnkWindowsCapabilitiesQuickAssistSoundRecorderPowerShellISETaskbarWidgetsMiscellaneousFeatures6.关闭杀软WindOWSdefender,组策略ComPUterconfiguration”Administrativetemplates»WindowsComponentsWindowsDefenderAntivirus,将TUITloffWindowsDefenderAntivirus设置为EnabledeJ1.ocWGroupPolicy(d<o<WeAcmmHdp*rm.Q?T.32jMDM2jMe*9ngJMi<rcwftaccountv二22Mt(MenderMClfltlnt*rfc:D*vcControlAEidutacm二MAPS:MactoeDcfnteEtplertGuerd二MP(C尹二NctMOrtcIrapectiOASytfem二QuMMtne_ReltnePrettction一ftemedt)onKcpctftF22Sc*»Ser<yIntcUt9enceUpdatesSfrem匚)Mkrowft(MendrApplicationGuard:MicrowftXtnd«rExploitGuardQJMcrowftEd9uMcretoftScondMyAUtfMrCFdo二Mcr«to<tUMrExpeh«nc«Vrtu4ttM>e二NtfMetbng2jNewsandinterests_2On<DfrrtZj0nkAsMU<e口OoetJPortaWeOptfMFSyrtem.Pr««rCft>onSettingsCJPUfhSie“I,Re11e<OnHcp$cwk«snRSSfMdt0MCPe代MCndef加XMuSTumoffMkrosoft(Mc*tfe<AMmRequrements:AtItMtWMovmVWUDe11pcc:Tbtspo*cyR9turnsoffKcwftXendefAAbfu.Kyowen>bkIMpc<*c>settingMkrMCiftDefendefAMraWusdoesnetrutK.ndwilnotu>nCCnllUtertform>reor(4h«fpc<ent>lunwarnedsc<twreWttan9_ClmIntW<c.:De*eControl二hchMomMAPS一MacrocAOafendttExp40tGuerd:Mp(ngr<一HtwoAlnpct>onSytlem二QurvX>ne一RMMePrctectMn二RefneM>ocRo<tM9fcn:Scur<yMfl9crUpdatesThreatsK>'ou的blthnpdk>>Mttm3Mroc*t04mtfeArtMmtwvrun,(9"改"VWc<befXistilledMilmtutp*oduc1.SUteIfyou8no<corjuretNsP«RySenm9WtMoATldtnMHymn9Mkrotoft(MndfAntninwWyouimuknothf*11tywspwwWtMo*4uto<nab<4ydMbtesMkfOKft(MndrAntninn.Oth4rMc,Mros<Odmde«An