目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-59287 PoC — Microsoft Windows Server 代码问题漏洞

来源
关联漏洞
标题: Microsoft Windows Server 代码问题漏洞 (CVE-2025-59287)
Description:Microsoft Windows Server是美国微软(Microsoft)公司的一套服务器操作系统。 Microsoft Windows Server存在代码问题漏洞,该漏洞源于攻击者利用该漏洞可以远程执行代码。
Description
Defensive PoC decoy for CVE-2025-59287 (WSUS) - emulates WSUS endpoints, captures request bodies and metadata, saves evidence for forensic analysis, and provides validation harness and detection rules.
介绍
# wsus-decoy

Defensive proof of concept decoy for CVE-2025-59287 (WSUS). The decoy emulates WSUS web endpoints on ports 8530 and 8531, captures full HTTP request bodies and headers, stores evidence for forensic analysis, and includes a Windows test harness to validate endpoint, file and process telemetry. It also includes example detection rules (KQL and Suricata) and a Sentinel playbook template.

> IMPORTANT: This project is strictly defensive. It contains no exploit code. Run only in isolated lab or segmented test environment. Do not expose the decoy to production networks unless you understand the risks and have monitoring in place.

## Repo contents
- nginx config to proxy WSUS-like endpoints to a capture service
- Flask-based capture service that writes request bodies and metadata to disk
- Windows PowerShell harness to create the log file and spawn cmd.exe -> powershell -EncodedCommand for detection validation
- Suricata rules to detect suspicious WSUS POSTs
- KQL queries for high-confidence and early-warning detection in Microsoft Sentinel [(From @0x534c Steven Lim on X)](https://x.com/0x534c/status/1982034763805581524)
- Deployment and testing guides

## Quickstart (local lab)
1. Clone this repo.
2. In `capture/` create a Python venv, then `pip install -r requirements.txt`.
3. Update `nginx/nginx.conf` if needed and run nginx on the decoy host listening on 8530.
4. Start the Flask capture service (systemd unit provided).
5. On a Windows test VM with EDR enabled, run `windows-harness/wsus_test_harness.ps1`.
6. Generate a POST to `http://<decoy-ip>:8530/ReportWebService/ReportWebService.asmx` to test capture.
7. Ingest evidence artifacts into your SIEM or Log Analytics workspace and run the provided KQL queries to validate.

See `docs/deployment.md` and `docs/testing.md` for full instructions.

## For Enterprise

- Visit lupovis.io 

## License and attribution

This project is licensed under the MIT License. See the `LICENSE` file for full license text.

**Copyright (c) 2025 Lupovis**

Attribution: Created by `Lupovis`  
Repository: https://github.com/Lupovis/Honeypot-for-CVE-2025-59287-WSUS/

## Safety note
Always run this in an isolated lab or segmented test network. Do not use real exploit payloads. The intent is to capture and analyze attacker activity in a safe way.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →