一份全面、研究级别的 Windows COM 攻击安全知识库,涵盖基础、横向移动、权限提升、UAC 绕过、持久化、执行/防御规避、检测工程和零日研究方法论。

Stars

134

7 天增长

+6

Fork 数

20

开放 Issue

0

开源协议

暂无数据

最近更新

2026-07-20

AI 仓库情报摘要
FR-AI / ANALYSIS

为什么值得关注

它是一站式结构化资源,从 COM 基础知识到高级零日狩猎,包含 28 张图表、可运行的实验代码、每种技术的检测指南以及每个攻击章节末尾的可重复研究实验室方法。

适合谁使用

  • 几乎没有 COM 背景的红队成员
  • 寻找 COM 零日漏洞的安全研究人员
  • 需要实用攻击技术的渗透测试人员
  • 构建 COM 遥测和检测规则的检测工程师

典型使用场景

  • 学习进攻性安全所需的 COM 基础知识
  • 在授权测试中执行 DCOM 横向移动或 COM 权限提升
  • 通过 COM 劫持识别并绕过 UAC
  • 使用提供的研发管道寻找新的 COM 漏洞

项目优势

  • 覆盖从 COM 基础到对 SYSTEM COM 服务器进行 NDR 缓冲区模糊测试的完整范围
  • 包含 28 张高分辨率技术图表和联系表供快速参考
  • 提供 Sysmon/Security/ETW 遥测入门和分层覆盖矩阵的检测工程指导
  • 每个攻击章节末尾都有可重复的研究实验室部分(假设→枚举→模糊测试→武器化)

使用前须知

  • 内容由 AI 生成(Kimi K3 Swarms),可能存在不准确、幻觉或过时信息;所有技术细节必须经过验证
  • Windows 行为因构建版本而异;CLSID 和补丁状态必须在特定目标版本上重新验证
  • 需要动手实验验证;标记为“(verify in lab)”的声明未经基础研究来源双重确认

README 快速开始

Offensive COM (Component Object Model)

[!WARNING] ⚠️ AI-generated slop ahead. These notes were generated by Kimi K3 Swarms and may contain inaccuracies, hallucinations, or outdated information. Treat them as a starting point for research—not as an authoritative reference. Verify all technical details before relying on them.

A complete, research-grade knowledge base on Windows COM (Component Object Model) offensive security, built for red teamers who start with little or no COM background and want to end up able to hunt for zero-days on their own.

Every chapter goes from "what is a CLSID" to "here is how to fuzz marshaled NDR buffers against a SYSTEM COM server" — with exact CLSIDs, registry paths, API signatures, runnable lab snippets, 28 purpose-built technical diagrams, per-technique detection guidance, and a Research Lab at the end of every attack category that turns the chapter into a repeatable hunting methodology.

Legal: This material is for authorized security testing, research, and defense only. Every technique here is published defensive knowledge drawn from the public research record (Project Zero, vendor advisories, conference talks, vendor blogs). Running any of it against systems you do not own or lack written authorization to test is illegal in most jurisdictions. You are responsible for your own lab.

Provenance: All facts, CLSIDs, CVEs, code snippets, and URLs in these chapters come from six cross-verified research briefs (kept in research/). Anything the sources could not double-confirm is explicitly marked "(verify in lab)" or carries a confidence label. Nothing is invented.

Powered By 🤖 Kimi K3 Max Swarm


How to use this knowledge base

If you are new to COM (the "zero to hero" path): Read 01 cover to cover first. It defines every term, walks the registry layout, activation, marshaling, apartments, monikers, and the security model. Then read the attack chapters in order — each one re-explains what it needs before going deep.

If you are an operator preparing for an engagement: Jump straight to the attack chapter you need. Each technique follows a fixed template: mechanics → prerequisites table → proof of concept → OpSec & detection → mitigations. Check 07 (Detection Engineering) against your target's likely telemetry before choosing a technique.

**If you wa

项目描述

Research notes on Windows Component Object Model (COM) attack surface for offensive security and vulnerability research. Covers COM hijacking, elevation of privilege, DCOM lateral movement, and persistence primitives with exploitation steps. Notes were generated by Kimi K3 Swarm may contain inaccuracies.

相关仓库与替代方案

根据分类、Topic 和编程语言匹配的相似项目。

lopopolo
精选
lopopolo GitHub avatar

harness-engineering

Harness Engineering is a methodology for improving coding agent outputs by carefully crafting the environment around them—providing curated context, tools, and executable constraints that encode an organization’s nonfunctional requirements and cumulative lessons.

AI 与机器学习AI 智能体
2,390
slvDev
精选
slvDev GitHub avatar

esp32-ai

A 28.9 million parameter language model runs on an $8 ESP32-S3 microcontroller entirely on-device, generating simple stories at about 9.5 tokens per second.

AI 与机器学习大语言模型
1,960
littledivy
精选
littledivy GitHub avatar

mimic

mimic captures traffic from any iOS or web app and automatically generates a Python client library that lets you call the app's API like a regular library.

AI 与机器学习
1,482