This article is a mirror article of machine translation, please click here to jump to the original article.

View: 40953|Reply: 20

Windows PowerShell to find the attacker's IP

[Copy link]
Posted on 12/22/2016 4:04:10 PM | | | |
Under Linux, we can use the following command to find the IP address connected to port 80 of our server, in descending order:





We can see the connection of all IPs and find out the malicious IP, that is, the attacker, but how to achieve it under Windows?

Knowing that there is PowerShell under Windows, I think it should be similar to the shell under Linux...

Before, I had never learned Powershell or Linux, I was learning and using it now.

The code may not be written well, please don't be surprised。。。。。 Please be considerate.



We can use PowerShell to find the IP connected to our port 80 and arrange it in descending order to find out the attacker...

The code is as follows:



$_. Count -ge 2 is to find the number of connections greater than or equal to 2, it is recommended that you set it to 50, according to your actual situation.

Alibaba Cloud's WINDOWS2008 log events are all 8 hours late

Attached is a script from the god, which is to read the IIS log and then seal the IP, which is much better than what I wrote.


Script download:

Tourists, if you want to see the hidden content of this post, pleaseReply





Previous:Percent sign "%" and question mark "?" in PowerShell.
Next:php Senior Programmer Architect Interview Questions
 Landlord| Posted on 12/22/2016 4:30:29 PM |
Also attach the lazy code you wrote



Posted on 3/20/2020 3:47:56 PM |
1. The master sends the scholar-official master to the third party
Posted on 8/3/2021 3:16:05 PM |
The code cannot be viewed, do you have to reply to see it?
Posted on 12/23/2016 9:58:22 AM |
It's fun, it's very interesting
Posted on 12/25/2016 11:29:54 AM |
The landlord has worked hard
Posted on 4/30/2017 12:17:12 PM |
Didn't I write this script?
Posted on 5/11/2017 8:53:25 AM |
This one is very practical.
Posted on 10/4/2017 10:16:18 PM |
Please read it, you need it
Posted on 11/7/2017 9:20:22 PM |
Thank you Daniel for sharing
Posted on 12/18/2017 3:42:01 PM |
It's fun, it's very interesting
Posted on 12/18/2017 3:46:43 PM |
Thank you to the owner for sharing!!!
Disclaimer:
All software, programming materials or articles published by Code Farmer Network are only for learning and research purposes; The above content shall not be used for commercial or illegal purposes, otherwise, users shall bear all consequences. The information on this site comes from the Internet, and copyright disputes have nothing to do with this site. You must completely delete the above content from your computer within 24 hours of downloading. If you like the program, please support genuine software, purchase registration, and get better genuine services. If there is any infringement, please contact us by email.

Mail To:help@itsvse.com