<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0"><channel><title>EVTX | baozongwi's blog</title><link>https://baozongwi.xyz/tags/evtx/</link><description>Currently exploring Java security and internal network penetration, with CTFs as a hobby.</description><generator>Hugo</generator><language>zh-cn</language><item><title>玄机第五章</title><link>https://baozongwi.xyz/p/xuanji-chapter-5/</link><pubDate>Tue, 08 Apr 2025 20:50:06 +0000</pubDate><guid>https://baozongwi.xyz/p/xuanji-chapter-5/</guid><description>第五章 Windows 实战-evtx 文件分析 附件题，样本不能在本地运行，我掏出了很早之前装的ctfos虚拟机，放这里面来分析，密码为hello-ctf.com，有三个extx文件，根本不知道怎么来的，看peterpan的文章偷点东西过来， .evtx 文件简介 .evtx 文件是 Windows 事件日志文件，存 …</description></item><item><title>玄机第四章</title><link>https://baozongwi.xyz/p/xuanji-chapter-4/</link><pubDate>Mon, 07 Apr 2025 17:56:28 +0000</pubDate><guid>https://baozongwi.xyz/p/xuanji-chapter-4/</guid><description>闲着没有事，做做玄机吧 第四章 windows实战-emlog 首先看到步骤说什么RDP啥啥的，我连RDP是什么都不知道，一搜原来是远程桌面链接啊，这个我知道，那直接在搜索框里面远程桌面，第一个就是打开之后可以进行靶机的链接 flag1 进来之后发现有个phpstudy，这个是可以起网站的，我们直接把www目录打包带走 …</description></item></channel></rss>