ãã®èšäºã¯ãSysmonè åšåæã«é¢ããã·ãªãŒãºã®æåã®èšäºã§ããã·ãªãŒãºã®å šãŠã®ä»ã®éšåïŒ
ããŒã1.玹ä»SYSMONãã°åæïŒç§ãã¡ã¯ããã«ããïŒ
ã®è åšãèå¥ããããã«SYSMONã€ãã³ãããã®ããŒã¿ã䜿çšããŠã第2éš
ã°ã©ãã䜿çšããŠSYSMONã®è åšã®ç¬¬3éšã§ã®è©³çŽ°ãªåæã
ããŸãããæ å ±ã»ãã¥ãªãã£ã«åŸäºããŠããå Žåã¯ãããããããå¿ èŠãææ¡ãã°ãã°ãããé²è¡äžã®æ»æããã§ã«èšç·Žãããç®ãããå Žåã¯ãçã®çãã°ã§éæšæºã®ã¢ã¯ãã£ããã£ãæ€çŽ¢ã§ããŸã-ããšãã°ãDownloadStringã³ãã³ããå®è¡ããPowerShellã¹ã¯ãªãããŸãã¯ãWordãã¡ã€ã«ã®ãµããããVBSã¹ã¯ãªãã-Windowsã€ãã³ããã°ã®ææ°ã®ã¢ã¯ãã£ããã£ãåç §ããã ãã§ããããããããã¯æ¬åœã«å€§ããªé çã®çš®ã§ããããããããã€ã¯ããœããã¯æ»æåæãã¯ããã«ç°¡åã«ããããã«SysmonãäœæããŸããã
Sysmonãã°ã«è¡šç€ºãããè åšã®èåŸã«ããåºæ¬çãªèãæ¹ãç¥ãããã§ããïŒWMIã€ãã³ãã¬ã€ããã¹ãã€ããŒã«ãšããŠããŠã³ããŒããããšãå éšé¢ä¿è ãä»ã®åŸæ¥å¡ãéãã«ç£èŠããæ¹æ³ãç解ã§ããŸãã Windowsã€ãã³ããã°ã®æäœã«é¢ããäž»ãªåé¡ã¯ã芪ããã»ã¹ã«é¢ããæ å ±ã®äžè¶³ã§ããããããããã»ã¹ã®éå±€ãç解ããããšã¯ã§ããŸãããå¯Ÿç §çã«ãSysmonãã°ãšã³ããªã«ã¯ã芪ã®ããã»ã¹IDãååãããã³å®è¡ããã³ãã³ãã©ã€ã³ãå«ãŸããŠããŸãããã€ã¯ããœããã«æè¬ããŸãã
ã·ãªãŒãºã®ç¬¬1éšã§ã¯ãSysmonããã®åºæ¬æ å ±ã§äœãã§ããããèŠãŠãããŸããããŒã2ã§ã¯ãåè²ãŠæ å ±ãæ倧éã«æŽ»çšããŠãè åšã°ã©ããšåŒã°ããããè€éãªé©åæ§é ãäœæããŸãã3çªç®ã®éšåã§ã¯ãè åšã°ã©ããã¹ãã£ã³ããŠãã°ã©ãã®ãéã¿ãã®åæãéããŠéæšæºã®ã¢ã¯ãã£ããã£ãæ€çŽ¢ããåçŽãªã¢ã«ãŽãªãºã ãæ€èšããŸãããããŠæåŸã«ãå ±é ¬ãšããŠãè åšãæ€åºããæ£ç¢ºãªïŒãããŠç解å¯èœãªïŒç¢ºçè«çæ¹æ³ãèŠã€ããŸãã
ããŒã1ïŒSysmonãã°åæã®çŽ¹ä»
ã€ãã³ããã°ã®è€éããç解ããã®ã«åœ¹ç«ã€ãã®ã¯äœã§ãããæçµçã«-SIEMãã€ãã³ããæ£èŠåãããã®åŸã®åæãç°¡çŽ åããŸããããããå°ãªããšãæåã¯ããã»ã©é ãã«è¡ãå¿ èŠã¯ãããŸãããæåã«ãSIEMã®åçãç解ããã«ã¯ããã°ãããç¡æã®ãŠãŒãã£ãªãã£Sysmonãè©Šãã ãã§ååã§ãããããŠãé©ãã»ã©ç°¡åã«æäœã§ããŸããé 匵ãããã€ã¯ããœããïŒ
Sysmonã«ã¯ã©ã®ãããªæ©èœããããŸããïŒ
ç°¡åã«èšãã°ãããã»ã¹ã«é¢ããæçšã§èªã¿ãããæ å ±ã§ãïŒä»¥äžã®å³ãåç §ïŒãWindowsã€ãã³ããã°ã«ã¯ãªãå€ãã®äŸ¿å©ãªè©³çŽ°ãèŠã€ãããŸãããæãéèŠãªã®ã¯æ¬¡ã®ãã£ãŒã«ãã§ãã
- ããã»ã¹IDïŒ16é²æ°ã§ã¯ãªã10é²æ°ïŒïŒ
- 芪ããã»ã¹ID
- ã³ãã³ãã©ã€ã³ãåŠçãã
- 芪ããã»ã¹ã®ã³ãã³ãã©ã€ã³
- ãã¡ã€ã«ç»åããã·ã¥
- ãã¡ã€ã«ã€ã¡ãŒãžå
Sysmonã¯ãããã€ã¹ãã©ã€ããŒãšãµãŒãã¹ã®äž¡æ¹ãšããŠã€ã³ã¹ããŒã«ãããŸã-詳现ã¯ãã¡ãããã®äž»ãªå©ç¹ã¯ãè€æ°ã®ãœãŒã¹ããã®ãã°ãåæããæ å ±ãé¢é£ä»ããçµæã®å€ããã¹Microsoft-> Windows-> Sysmon-> Operationalã«ãã1ã€ã®ã€ãã³ããã°ãã©ã«ããŒã«è¡šç€ºã§ããããšã§ããç§ã®é«ªã®æ¯ãéç«ãããWindowsãã°ã®ç§èªèº«ã®èª¿æ»ã§ã¯ãããšãã°PowerShellãã°ãã©ã«ããŒãšSecurityãã©ã«ããŒã絶ããåãæ¿ããã€ãã³ããã°ãã²ã£ããè¿ããŠããããã®éã®å€ãäœããã®åœ¢ã§æ¯èŒãããšãã倧èãªè©Šã¿ãããªããã°ãªããŸããã§ãããããã¯æ±ºããŠç°¡åãªäœæ¥ã§ã¯ãããŸãããåŸã§æ°ã¥ããããã«ãããã«ã¢ã¹ããªã³ãè£å ããæ¹ãè¯ãã§ãããã
ãŸããSysmonã¯ãåºç€ãšãªãããã»ã¹ã®ç解ã«åœ¹ç«ã€æçšãªïŒãŸãã¯ãã³ããŒãèšã£ãŠããããã«ãå¹æçãªïŒæ å ±ãæäŸããããšã«ãããé£èºçãªé²æ©ãéããŠããŸããããšãã°ããããã¯ãŒã¯å ã®ã¹ããŒãã€ã³ãµã€ããŒã®åããã·ãã¥ã¬ãŒãããç§å¯ã®wmiexecã»ãã·ã§ã³ãéå§ããŸããã Windowsã€ãã³ããã°ã«è¡šç€ºãããå 容ã¯æ¬¡ã®ãšããã§ãã
ããã»ã¹ã«é¢ããäžéšã®æ å ±ã¯Windowsãã°ã«è¡šç€ºãããŸãããã»ãšãã©åœ¹ã«ç«ã¡ãŸããããã©ã¹16é²æ°ã®ããã»ã¹ID ???
ãããã³ã°ã®åºæ¬ãç解ããŠããããã®ITãããã§ãã·ã§ãã«ã¯ãã³ãã³ãã©ã€ã³ã«çããæã€å¿ èŠããããŸãã cmd.exeã䜿çšããŠå¥ã®ã³ãã³ããå®è¡ããå¥åŠãªååã®ãã¡ã€ã«ã«åºåããªãã€ã¬ã¯ãããããšã¯ãã³ãã³ãã¢ã³ãã³ã³ãããŒã«ïŒC2ïŒãœãããŠã§ã¢ã®ã¢ã¯ã·ã§ã³ãšæããã«äŒŒãŠããŸãããã®ããã«ãWMIãµãŒãã¹ã䜿çšããŠç䌌ã·ã§ã«ãäœæãããŸãã
ããã§ãSysmonãšã³ããªã«çžåœãããã®ãèŠãŠã¿ãŸããããããã«ãããè¿œå æ å ±ãã©ã®çšåºŠåŸãããããããããŸãã
Opportunities Sysmon one screenshotïŒ
ã³ãã³ãã©ã€ã³ã ãã§ãªãããã¡ã€ã«åãWindowsãèªèããŠããå®è¡å¯èœã¢ããªã±ãŒã·ã§ã³ãžã®ãã¹ïŒ "Windowsã³ãã³ãããã»ããµ"ïŒã芪ããã»ã¹ã®ID ãã³ãã³ãã©ã€ã³ã芪ã§ãããèªã¿åãå¯èœãªåœ¢åŒã®ããã»ã¹ã«é¢ãã詳现æ å ±ããã«ãããcmdã·ã§ã«ãšèŠªããã»ã¹ã®å®éã®ãã¡ã€ã«åãèµ·åãããŸãããã€ãã«ããã¹ãŠäžç®æã«ïŒ
Sysmonãã°ãããé«ã確çã§ããçã®ããã°ã«è¡šç€ºããããã®çãããã³ãã³ãã©ã€ã³ã¯ãåŸæ¥å¡ã®éåžžã®äœæ¥ã®çµæã§ã¯ãªããšçµè«ä»ããããšãã§ããŸããããã©ããããããã¯C2ã®ãããªããã»ã¹ïŒåè¿°ã®wmiexecïŒã«ãã£ãŠçæããããµãŒãã¹WMIããã»ã¹ïŒWmiPrvSeïŒã«ãã£ãŠçŽæ¥çæãããŸãããããã§ããªã¢ãŒãã®æ»æè ãŸãã¯å éšé¢ä¿è ãäŒæ¥ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã«æ¯ãã€ããããšããŠããããšãããããŸãã
Get-Sysmonlogsã®çŽ¹ä»
ãã¡ãããSysmonã®ãã°ã1ãæã«ããã®ã¯çŽ æŽãããããšã§ããããããããšãã°PowerShellã³ãã³ãã䜿çšããŠãããã°ã©ã ã§åã ã®ãã°ãã£ãŒã«ãã«ã¢ã¯ã»ã¹ã§ããã°ãããã«è¯ãã§ãããããã®å Žåãæœåšçãªè åšã®æ€çŽ¢ãèªååããå°ããªPowerShellã¹ã¯ãªãããäœæã§ããŸãã
ããã¯ç§ã®æåã®ã¢ã€ãã¢ã§ã¯ãããŸããã§ããããããŠãããã€ãã®ãã©ãŒã©ã æçš¿ãšGitHub ãããžã§ã¯ãããPowerShellã䜿çšããŠSysmonãã°ã解æããæ¹æ³ããã§ã«èª¬æããŠããã®ã¯è¯ãããšã§ããç§ã®å ŽåãSysmonãã£ãŒã«ãããšã«åå¥ã®è§£æã¹ã¯ãªããè¡ãèšè¿°ããå¿ èŠããªãããã«ããŸããããã®ãããæ æ°ãªäººéã®åçã䜿çšãããã®çµæãèå³æ·±ããã®ãæãã€ããŸããã
æåã®éèŠãªãã€ã³ãã¯ãããŒã ã®èœåã§ãGet-WinEventã¯ã次ã®ããã«Sysmonãã°ãèªã¿åããå¿ èŠãªã€ãã³ãããã£ã«ã¿ãªã³ã°ããŠãçµæãPSå€æ°ã«åºåããŸãã
$events = Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational" | where { $_.id -eq 1 -or $_.id -eq 11}
ã³ãã³ããèªåã§ãã¹ããããå Žåã¯ã$ã€ãã³ãé åã®æåã®èŠçŽ $ events [0] .Messageã«ã³ã³ãã³ãã衚瀺ããããšã§ãéåžžã«åçŽãªåœ¢åŒã®äžé£ã®ããã¹ãæååãååŸã§ããŸããSysmonãã£ãŒã«ãã®ååãã³ãã³ããããŠå€èªäœã§ãã
ãã£ããŒïŒ JSON察å¿ãã©ãŒããããžã®Sysmonãã°åºå
ç§ãšåãããšãèããŠããŸããïŒããå°ãåªåããŠãåºåãJSON圢åŒã®æååã«å€æãã匷åãªConvertFrom-Jsonã³ãã³ãã䜿çšããŠãããçŽæ¥PSãªããžã§ã¯ãã«ããŒãã§ããŸãã
次ã®ããŒãã§ã¯ãå€æçšã®PowerShellã³ãŒãã瀺ããŸããããã¯éåžžã«ç°¡åã§ãããããŸã§ã®éãç§ãPSã¢ãžã¥ãŒã«ãšããŠã€ã³ã¹ããŒã«ããget-sysmonlogsãšããæ°ããã³ãã³ãã§äœãã§ããããèŠãŠã¿ãŸãããã
äžäŸ¿ãªã€ãã³ããã°ã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠSysmonãã°åæã«é£ã³èŸŒã代ããã«ãPowerShellã»ãã·ã§ã³ããçŽæ¥ã€ã³ã¯ãªã¡ã³ã¿ã«ã¢ã¯ãã£ããã£ãç°¡åã«æ€çŽ¢ããPS whereã³ãã³ãïŒãšã€ãªã¢ã¹ "ïŒ"ïŒã䜿çšããŠåºåãççž®ã§ããŸãã
WMIãä»ããŠèµ·åãããcmdã·ã§ã«ã®ãªã¹ããç¬èªã®Get-SysmonlogsããŒã ã«ããè åšåæ
ãããŒã¿ããŒã¹ã®ããã«Sysmonãã°ããŒãªã³ã°ããŒã«ãäœæããŸãããEQLã«é¢ããèšäºã§ã¯ãæ£åŒã«ã¯ãŸã æ¬ç©ã®SQLã«äŒŒãã€ã³ã¿ãŒãã§ãŒã¹ã䜿çšããŠããŸããããã®é¢æ°ã¯ããã®é¢æ°ã§èª¬æãããŠããã¯ãŒã«ãªãŠãŒãã£ãªãã£ã«ãã£ãŠå®è¡ãããããšã«æ³šæããŠãã ãããã¯ããEQL ã¯ãšã¬ã¬ã³ãã§ããã3çªç®ã®éšåã§è§ŠããŸãã
Sysmonããã³ã°ã©ãåæ
æœè±¡åããŠãä»äœæãããã®ã«ã€ããŠèããŠã¿ãŸããããåºæ¬çã«ãPowerShellãéããŠWindowsã€ãã³ãããŒã¿ããŒã¹ãå©çšã§ããããã«ãªããŸãããåè¿°ã®ããã«ãParentProcessIdãä»ããã¬ã³ãŒãéã®æ¥ç¶ãŸãã¯æ¥ç¶ããããããããã»ã¹ã®å®å šãªéå±€ãååŸã§ããŸãããšããã©ããã®ãªããã«ãŠã§ã¢
ã®åéºã·ãªãŒãºãèªãã ããšãããã°ãããã«ãŒã¯è€éãªãã«ãã¹ããŒãžæ»æãäœæããã®ã倧奜ãã§ãåããã»ã¹ãç¬èªã®å°ããªåœ¹å²ãæããã次ã®ã¹ããããžã®èžã¿å°ãæºåããããšãç¥ã£ãŠããŸãããã®ãããªããšã¯ããçã®ããã°ããã ãã§ã¯éåžžã«å°é£ã§ãã
ããããGet-SysmonlogsããŒã ãšãããã¹ãã§åŸã§èª¬æããè¿œå ã®ããŒã¿æ§é ïŒãã¡ãããããã¯ã°ã©ãã§ãïŒã䜿çšãããšãé ç¹ãæ£ç¢ºã«æ€çŽ¢ããã ãã§è åšãæ€åºããå®çšçãªæ¹æ³ãåŸãããŸãã
ãã€ãã®DYIããã°ãããžã§ã¯ããšåæ§ã«ãå°èŠæš¡ãªè åšã®è©³çŽ°åæã«åãçµãã»ã©ãçµç¹ã¬ãã«ã§è åšãæ€åºããããšãããã«å°é£ã§ããããç解ã§ããŸãããããŠããã®æèã¯éåžžã«éèŠãªãã€ã³ãã§ãã
èšäºã®ç¬¬2éšã§ã¯ãæåã®èå³æ·±ãå䜵çã«ééããŸããããã§ã¯ãSysmonã€ãã³ããããè€éãªæ§é ã§çžäºã«ãªã³ã¯ãå§ããŸãã