关闭Win10/Win11的自动更新 – 绿盟科技技术博客
Tags
attack-pattern: Software - T1592.002
Common Information
Type Value
UUID a77f4a5a-0979-4d67-b571-a249e74f46c7
Fingerprint 97af6865d80ba032
Analysis status DONE
Considered CTI value 0
Text language
Published July 21, 2023, 7:08 p.m.
Added to db July 21, 2023, 1:29 p.m.
Last updated Nov. 17, 2024, 6:55 p.m.
Headline 关闭Win10/Win11的自动更新
Title 关闭Win10/Win11的自动更新 – 绿盟科技技术博客
Detected Hints/Tags/Attributes 14/1/35
Source URLs
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 5 绿盟科技技术博客 http://blog.nsfocus.net/feed/ 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 5
www.52pojie.cn
Details Domain 67
microsoft.windows
Details Domain 3
datetime.date
Details File 1
thread-1809122-1-1.html
Details File 1
disableautoupdate.reg
Details File 165
reg.exe
Details File 1
enableautoupdate.reg
Details File 1
该值在musupdatehandlers.dll
Details File 82
kernelbase.dll
Details File 20
c:\windows\system32\kernelbase.dll
Details File 2
updatepolicy.dll
Details File 3
c:\windows\system32\updatepolicy.dll
Details File 1
waasassessment.dll
Details File 1
c:\windows\system32\waasassessment.dll
Details File 1
usosvc.dll
Details File 1
c:\windows\system32\usosvc.dll
Details File 41
rpcrt4.dll
Details File 6
c:\windows\system32\rpcrt4.dll
Details File 1
z:\green\windows kits\10\x64\debuggers\x64\tlist.exe
Details File 1
z:\green\windows kits\10\x64\debuggers\x64\cdb.exe
Details File 1
用ida反汇编updatepolicy.dll
Details File 1
musupdatehandlers.dll
Details File 1
c:\windows\system32\musupdatehandlers.dll
Details File 10
shcore.dll
Details File 1
c:\windows\system32\shcore.dll
Details File 15
ucrtbase.dll
Details File 8
c:\windows\system32\ucrtbase.dll
Details File 49
c:\windows\immersivecontrolpanel\systemsettings.exe
Details File 1
用ida反汇编musupdatehandlers.dll
Details File 36
datetime.dat
Details File 1
-datetime.dat
Details Url 1
https://www.52pojie.cn/thread-1809122-1-1.html
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings
Details Windows Registry Key 1
HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings
Details Windows Registry Key 1
HKLMValueExists