ãããŠãæ奜家ã®ã°ã«ãŒãã2é±éã®ã¹ããªã³ããæé ããããšã決ããããšãç¥ããŸããSIEMã·ã¹ãã ã®ã«ãŒã«ãèšè¿°ããããã®çµ±äžããããã©ãŒããããéçºããããã«äœæããã140人以äžã®åå è ã«ãã£ãŠãµããŒããããŠããSigmaãããžã§ã¯ãã®ã«ãŒã«ã®èšè¿°ã«ã€ããŠãç§ãã¡ã¯ãSIEMãã³ããŒãšããŠã³ãã¥ããã£ã®çºå±ã泚ææ·±ããã©ããŒããŠãããããã€ãã³ãã«é¢ãããã¥ãŒã¹ã«èå³ãæã£ãŠããŸããã
äž»å¬è ããé£çµ¡ããããPT Expert Security CenterããŒã ã«ã¹ããªã³ããžã®åå ãæåŸ ãããšãã®é©ããæ³åããŠã¿ãŠãã ãããã€ãã³ãã®åå è ã¯ãOpen Security Collaborative DevelopmentïŒOSCDïŒã圢æããŸãããããã¯ãç¥èã®æ®åãšã³ã³ãã¥ãŒã¿ã»ãã¥ãªãã£å šè¬ã®æ¹åãç®çãšããæ å ±ã»ãã¥ãªãã£ã¹ãã·ã£ãªã¹ãã«ããåœéçãªåãçµã¿ã§ããç§ãã¡ã¯ãå ±éã®å®å šã®ããã«ç§ãã¡ã®çµéšãå¿çšããããã«åå ããããšã«åãã§åæããŸããã
ãã®èšäºãçãŸããçµç·¯
ã«ãŒã«ãæžãå§ãããšããç¹ã«ãã·ã¢èªã§ã¯ãã·ã°ãã«ãŒã«ã®æ§æã®å æ¬çãªèª¬æããªãããšã«æ°ã¥ããŸãããç¥èã®äž»ãªæ å ±æºã¯ãGitHubãšå人çãªçµéšã§ããããã€ãã®åªããèšäºïŒãã·ã¢èªãšè±èªïŒããããŸããããããã®çŠç¹ã¯ãã«ãŒã«ã®æ§æããã·ã°ãã«ãŒã«ã®é©çšç¯å²ã®åæãŸãã¯ç¹å®ã®ã«ãŒã«ã®äœæã«ç§»ã£ãŠããŸããç§ãã¡ã¯ãåå¿è ãSigmaãããžã§ã¯ãã«æ £ããç§ãã¡èªèº«ã®çµéšãå ±æãããã®äœ¿çšã®æ§æãšæ©èœã«é¢ããæ å ±ã1ãæã«åéããããããããšã«ããŸããããããŠãã¡ããããããOSCDã€ãã·ã¢ãããæ¡å€§ããå°æ¥çã«å€§ããªã³ãã¥ããã£ãäœæããã®ã«åœ¹ç«ã€ããšãé¡ã£ãŠããŸãã
倧éã®è³æããã£ãããã3ã€ã®ã·ãªãŒãºã®èšäºã§èª¬æãå ¬éããããšã«ããŸããã
- , ( ).
- . , .
- (, , , , ) .
Sigma
ã·ã°ãã¯ããã°ã®ããŒã¿ã«åºã¥ããŠæ€åºã«ãŒã«ãèšè¿°ããããã®çµ±äžããã圢åŒã§ããã«ãŒã«ã¯åå¥ã®YAMLãã¡ã€ã«ã«ä¿åãããŸããSigmaã§ã¯ãçµ±äžãããæ§æã䜿çšããŠã«ãŒã«ã1åèšè¿°ãã次ã«ç¹å¥ãªã³ã³ããŒã¿ãŒã䜿çšããŠããµããŒããããŠããSIEMã·ã¹ãã ã®æ§æã§ã«ãŒã«ãååŸã§ããŸããããŸããŸãªSIEMã·ã¹ãã ã®ã¯ãšãªã®æ§æã«å ããŠã次ã®ã¿ã€ãã®ã¯ãšãªã®äœæããµããŒããããŠããŸãã
- Elasticsearch Queryã
- å¿ èŠãªãã©ã¡ãŒã¿ãå«ãgrepãŠãŒãã£ãªãã£èµ·åã©ã€ã³
- Windowsç£æ»ãã°PowerShellæååã
æåŸã®2ã€ã®ã¿ã€ãã¯ããã°ãåæããããã®è¿œå ã®ãœãããŠã§ã¢ãå¿ èŠãšããªããšããäºå®ã§æ³šç®ã«å€ããŸããgrepãŠãŒãã£ãªãã£ãšPowerShellã€ã³ã¿ãŒããªã¿ãŒã¯ãããããLinuxãšWindowsã§ãã®ãŸãŸäœ¿çšã§ããŸãã
ãã°ã«åºã¥ããŠæ€åºãèšè¿°ããããã®çµ±äžããã圢åŒã®ååšã«ãããç¥èã®å ±æããªãŒãã³ãœãŒã¹ã»ãã¥ãªãã£ã®éçºã容æã«ãªããæ å ±ã»ãã¥ãªãã£ã³ãã¥ããã£ãæ°ããªè åšãšæŠãã®ã«åœ¹ç«ã¡ãŸãã
äžè¬çãªæ§æ
ãŸã第äžã«ãã«ãŒã«ã®å¿ é éšåãšãªãã·ã§ã³éšåããããšããããšã§ããããã¯GitHub ã®å ¬åŒwikiã«èšèŒãããŠããŸããã«ãŒã«ã®æŠèŠïŒãœãŒã¹ïŒå ¬åŒWikiïŒã以äžã«ç€ºããŸãã
ã»ãšãã©ãã¹ãŠã®ã«ãŒã«ã¯ã倧ãã3ã€ã®éšåã«åããããšãã§ããŸãã
- ã«ãŒã«ã説æããå±æ§ïŒã¡ã¿æ å ±ïŒ;
- ããŒã¿ãœãŒã¹ã説æããå±æ§ã
- ã«ãŒã«ãããªã¬ãŒããããã®æ¡ä»¶ã説æããå±æ§ã
åéšåã¯ãã¿ã€ãã«ïŒã¿ã€ãã«ã«å ããŠãæåŸã®ã°ã«ãŒãã«ã¯ä»ã®ãªãã·ã§ã³ã®é«ã¬ãã«å±æ§ãå«ãŸããŸãïŒããã°ãœãŒã¹ãããã³æ€åºã®å¿ é ã®é«ã¬ãã«å±æ§ã«å¯Ÿå¿ããŠããŸãã
話ã䟡å€ã®ããã«ãŒã«æ§é ã®ãã1ã€ã®æ©èœããããŸããã«ãŒã«ã¯YAMLããŒã¯ã¢ããèšèªã§èšè¿°ãããŠãããããYAML圢åŒã§ã¯è€æ°ã®YAMLããã¥ã¡ã³ãã1ã€ã®ãã¡ã€ã«ã«é 眮ã§ãããããSigmaã®éçºè ã¯ãããããã€ãã®çšéã«äœ¿çšããŠããŸãããããŠSigmaã®å Žå-1ã€ã®ãã¡ã€ã«ã«çµã¿åãããããã€ãã®ã«ãŒã«ãã€ãŸããã«ãŒã«ã³ã¬ã¯ã·ã§ã³ããäœæããŸãããã®ã¢ãããŒãã¯ãæ»æãæ€åºããæ¹æ³ãããã€ãããã説æéšåãè€è£œããããªãå Žåã«äŸ¿å©ã§ãïŒå¯Ÿå¿ããã»ã¯ã·ã§ã³ã§èª¬æããããã«ãã«ãŒã«ã®èª¬æéšåã ãã§ãªãè€è£œããããšãã§ããŸãïŒã
ãã®å Žåãã«ãŒã«ã¯éåžž2ã€ã®éšåã«åããããŸãã
- ã³ã¬ã¯ã·ã§ã³ã¢ã€ãã ã®äžè¬çãªå±æ§ãæã€ããŒãïŒéåžžããã°ãœãŒã¹ãšæ€åºã»ã¯ã·ã§ã³ãé€ããã¹ãŠã®ãã£ãŒã«ãïŒã
- æ€åºã説æãã1ã€ãŸãã¯ããã€ãã®éšåïŒã»ã¯ã·ã§ã³ãã°ãœãŒã¹ãšæ€åºïŒã
ãã¡ã€ã«ã«åäžã®ã«ãŒã«ãå«ãŸããŠããå Žåã1ã€ã®ã«ãŒã«ããçž®éããã³ã¬ã¯ã·ã§ã³ãååŸããŠããããããã®ã¹ããŒãã¡ã³ããåœãŠã¯ãŸããŸããã«ãŒã«ã®ã³ã¬ã¯ã·ã§ã³ã«ã€ããŠã¯ããã®ã·ãªãŒãºã®ç¬¬3éšã§è©³ãã説æããŸãã
次ã«ãæ¶ç©ºã®ã«ãŒã«ã®äŸãèŠãŠã¿ãŸãããããã®ãã©ãŒã ã®ã³ã¡ã³ãã¯éåžžãã«ãŒã«ã§ã¯äœ¿çšãããªãããšã«æ³šæããŠãã ãããããã§ã¯ããã£ãŒã«ãã説æããããã ãã®ãã®ã§ãã
å žåçãªã«ãŒã«ã®èª¬æ
ã·ã°ãã«ãŒã«ã®äœæäŸ
æ§æã®è©³çŽ°ã説æããã·ã°ãã«ãŒã«ã®æ©èœã«ã€ããŠèª¬æããåã«ãå®éã«ããããŸãã¯ãããã®å±æ§å€ãã©ãããæ¥ãã®ããæ確ã«ããããã«ããã®ãããªã«ãŒã«ãäœæããå°ããªäŸãèããŠã¿ãŸãããããã®ãããã¯ã«ã€ããŠã®è¯ãèšäºã¯è±èªã§ããç¬èªã®ã«ãŒã«ãäœæããŠãYAMLãã¡ã€ã«ã®å±æ§ã§æå®ããå¿ èŠã®ããããŒã¿ãããã£ãŠããå Žåã¯ãã€ãã³ããœãŒã¹ã»ã¯ã·ã§ã³ã®è©³çŽ°ãªèª¬æãå«ã次ã®ã»ã¯ã·ã§ã³ã«é²ãããšãã§ããŸãïŒãã®ã»ã¯ã·ã§ã³ããã°ãœãŒã¹ãšãåŒã³ãŸãïŒã
SettingSyncHost.exeã®äœ¿çšãLiving Off The Land BinaryïŒLOLBinïŒãšããŠæ€åºããã«ãŒã«ãäœæããæ¹æ³ã説æããŸããããã«ãŒã«ã®äœæã«ã¯éåžžã3ã€ã®æ®µéããããŸãã
- æ»æãå®è¡ããå¿ èŠãªãã°ãåéãã
- ååãšããŠæ€åºã®èª¬æã
- äœæããã«ãŒã«ã確èªããŸãã
æ»æãè¡ã
ã«ãŒã«ã®ã¢ã€ãã¢ã¯ããããµã³ãŒã³ã®ããã°ã«è©³ããèšèŒãããŠããŸãã泚ææ·±ãèªãã åŸãèšäºã«èšèŒãããŠããçµæãç¹°ãè¿ãããã«å¿ èŠãªæé ãæããã«ãªããŸãã
- å®è¡ããããã°ã©ã ãæžã蟌ã¿å¯èœãªãã£ã¬ã¯ããªã«ã³ããŒããŸããèšäºã§ã¯ïŒ TEMPïŒ ãéžæããããšãæšå¥šããŠããŸãããä»»æã®ãã¹ãéžæã§ããŸããæé 4ã§æå®ããååã®ãµããã£ã¬ã¯ããªããã®ãã£ã¬ã¯ããªã«äœæãããããšãæ€èšãã䟡å€ããããŸãã
- , , , (wevtutil.exe, makecab.exe, reg.exe, ipconfig.exe, settingsynchost.exe, tracelog.exe). , findstr.exe. , SettingSyncHost.exe Binary Search Order Hijacking (MITRE ATT&CK ID: T1574.008).
- , ( settingsynchost.exe cmd PowerShell,
cd < >
). - :
c:\windows\system32\SettingSyncHost.exe -LoadAndRunDiagScript <___>
- SettingSyncHost.exe.
Sysmonã¯ãsysmon-modularãããžã§ã¯ãã®æ§æãã¡ã€ã«ãšå ±ã«ã·ã¹ãã ã« ã€ã³ã¹ããŒã«ãããŸãããããã£ãŠããã°ã®åéã¯èªåçã«å®è¡ãããŸãããã«ãŒã«ã®äœæäžã«ãæ€åºã®äœæã«åœ¹ç«ã€ãã°ã®çš®é¡ã衚瀺ãããŸãã
ã·ã°ãã«ãŒã«ã®åœ¢åŒã§ã®æ€åºã®èª¬æ
ãã®ã¹ãããã§ã¯ã2ã€ã®ã¢ãããŒããå¯èœã§ããæ€åºããžãã¯ã§æãè¿ãæ¢åã®ã«ãŒã«ãèŠã€ããŠããŒãºã«åãããŠå€æŽããããã«ãŒã«ãæåããäœæããŸããåæ段éã§ã¯ãæåã®ã¢ãããŒãã«åºå·ããããšããå§ãããŸããæ確ã«ããããã«ã2çªç®ã®ã¢ãããŒãã䜿çšããŠã«ãŒã«ãèšè¿°ããŸãã
æ°ãããã¡ã€ã«ãäœæãããã®æ¬è³ªãååã§ç°¡æœãã€ç°¡æœã«èª¬æããŸããããã§ã¯ãæ¢åã®ã«ãŒã«ã®ã¹ã¿ã€ã«ãéµå®ããå¿ èŠããããŸãããã®äŸã§ã¯ãwin_using_settingsynchost_to_run_hijacked_binary.ymlãšããååãéžæããŸããã次ã«ãã³ã³ãã³ããå ¥åãå§ããŸããã«ãŒã«ã®å§ãã«ã¡ã¿æ å ±ãå ¥åããããšããå§ããŸããããããã«å¿ èŠãªãã¹ãŠã®ããŒã¿ããã§ã«ãããŸãã
ã«ãŒã«ããã£ãŒã«ãã§æ€åºããæ»æã®çš®é¡ã«ã€ããŠç°¡åã«èª¬æããŸã
title
ããã詳现ãªèª¬æ-説æãã£ãŒã«ãã§ã¯ãæ°ããã«ãŒã«ã®å Žåãã¹ããŒã¿ã¹ãèšå®ããã®ãæ
£äŸã§ãïŒè©Šéšçãäžæã®èå¥åã¯ããŸããŸãªæ¹æ³ã§çæã§ããŸããWindowsã§ã¯ãPowerShellã€ã³ã¿ãŒããªã¿ãŒã§æ¬¡ã®ã³ãŒããå®è¡ããã®ãæãç°¡åãªæ¹æ³ã§ãã
PS C:\> "id: $(New-Guid)"
id: b2ddd389-f676-4ac4-845a-e00781a48e5f
æ®ãã®ãã£ãŒã«ãã¯èªæã§ãããæ»æã®ç解ã«åœ¹ç«ã€ãœãŒã¹ãžã®ãªã³ã¯ãæäŸããããšããå§ãããŸããããã¯ããã®ã«ãŒã«ãããã«ç解ãã人ã ã«åœ¹ç«ã¡ãŸãããŸããæ»æã説æããããã«å ã®ç 究ã®èè ãè¡ã£ãåªåãžã®è³èŸã§ããããŸãã
ãã®æ®µéã§ã®ã«ãŒã«ã¯æ¬¡ã®ãšããã§ãã
次ã«ããã°ã®ãœãŒã¹ã説æããå¿ èŠããããŸããäžèšã®ããã«ãSysmonãã°ã«äŸåããŸãããäžè¬çãªã«ããŽãªã®ç»å Žã«ãããprocess_creationã«ããŽãªã䜿çšããŠããã»ã¹ãäœæããã®ãæ £ç¿ãšãªã£ãŠããŸããäžè¬åãããã«ããŽãªã«ã€ããŠã¯ã以äžã§è©³ãã説æããŸãã Sysmonæ§ææ©èœãªã©ãå®çŸ©ãã£ãŒã«ãã§ã®ãœãŒã¹ã®æ§æã«é¢ããã³ã¡ã³ããšã¢ããã€ã¹ãæžãã®ãæ £äŸã§ããããšã«æ³šæããŠãã ããã
次ã«ãæ€åºããžãã¯ã説æããå¿ èŠããããŸããããã¯æãæéããããéšåã§ãããã®æ»æã¯å€ãã®åºæºã§æ€åºã§ããŸãããã®äŸã§ã¯ãå¯èœãªãã¹ãŠã®æ€åºæ¹æ³ãç¶²çŸ ããŠããããã§ã¯ãªããããå¯èœãªãªãã·ã§ã³ã®1ã€ã«ã€ããŠèª¬æããŸãã
çºçããã€ãã³ããèŠããšã次ã®ãã§ãŒã³ãæ§ç¯ã§ããŸãã
ãŸããããã»ã¹ïŒPIDïŒ4712ïŒãéå§è¡cïŒ\ windows \ system32 \ SettingSyncHost.exe -LoadAndRunDiagScript join_oscdã§éå§ããŸãããããã»ã¹
ã®çŸåšã®äœæ¥ãã£ã¬ã¯ããªã¯ãŠãŒã¶ãŒã®TEMPãã£ã¬ã¯ããªã§ããããšã«æ³šæããŠãã ããã
次ã«ãå®è¡äžã®ããã»ã¹ãããããã¡ã€ã«ãäœæãããã®å®è¡ãéå§ããŸãã
ïŒåœä»€ã®ããããã¡ã€ã«ãå®è¡ããããã»ã¹ã«ã¯ãåºæã®ã·ã¹ãã ãã¡ã€ã«ãšã¡ã¿ãå«ãŸããŠããŸããPlusã®äžæãã¡ã€ã«ãšãã©ã«ãã«ããæã¡äžãIPCONFIG.EXEãã¡ã€ã«ãåç §ã€ãã³ãã®èå¥å7076.ãããªãåæãåãã
ããšã¯ãæ»æã®èµ·åããã»ã¹ã®å åãšèããããšãææ¡ãããåãããªãå®è¡ãã¡ã€ã«ãã·ã¹ãã ãã£ã¬ã¯ããªïŒCïŒ\ Windows \ System32ïŒã«ãããŸãããŸãã芪ããã»ã¹ã®ã¹ã¿ãŒãã¢ããè¡ã«ãµãã¹ããªã³ã°ãcmd.exe / cãããRoamDiag.cmdããããã³ã-outputpathããå«ãŸããŠããå Žåãåæ§ã§ãããããã·ã°ãæ§æã§èšè¿°ããŠãæçµçãªèŠåãååŸããŸãããïŒæ€åºããžãã¯ãèšè¿°ããããã«äœ¿çšã§ããæ§é ã®è©³çŽ°ãªåæã¯ãã·ã°ãã«é¢ããäžé£ã®èšäºã®æ¬¡ã®ããŒãã§èª¬æãããŸãïŒã
ã«ãŒã«ãæ©èœããããšã確èªãã
ã³ã³ããŒã¿ãŒãPowerShellã¯ãšãªã«èµ·åããŸãã
ãã®å Žåãé€å€ãã£ã«ã¿ãŒã¯èŠªããã»ã¹ã®å®è¡å¯èœãã¡ã€ã«ã€ã¡ãŒãžãžã®ãã¹ãæ€åºããããããã®ã¯ãšãªã§ã¯ç®çã®çµæãåŸãããŸããããããã£ãŠãåã«Imageãšããåèªã®åã«æåtããã£ãŠã¯ãªããªãããšã瀺ãã ãã§ããã€ãŸããåèªã®çµããã§ãã芪ïŒ
ã€ãã³ããèŠã€ãããŸãããã«ãŒã«ã¯æ©èœããŸãã
ãããå®éã«Sigmaã«ãŒã«ãäœæãããæ¹æ³ã§ãã次ã«ãæ€åºãæ åœãããã£ãŒã«ããã€ãŸããã°ãœãŒã¹ã®èª¬æã«ã€ããŠè©³ãã説æããŸãã
説æãæ€åº
ã«ãŒã«ã®äž»èŠãªéšåã¯æ€åºã®èª¬æã§ããããã¯ãæ»æã®å åãæ¢ãå Žæãšæ¹æ³ã«é¢ããæ å ±ãå«ãŸããå Žæã ããã§ãããã®æ å ±ã¯ããã°ãœãŒã¹ïŒå ŽæïŒããã³æ€åºïŒæ¹æ³ïŒå±æ§ã®ãã£ãŒã«ãã«å«ãŸããŠããŸãããã®èšäºã§ã¯ããã°ãœãŒã¹ã»ã¯ã·ã§ã³ã詳ããèŠãŠãããã·ãªãŒãºã®æ¬¡ã®ããŒãã§æ€åºã»ã¯ã·ã§ã³ã«ã€ããŠèª¬æããŸãã
ã€ãã³ããœãŒã¹ã»ã¯ã·ã§ã³ã®èª¬æïŒlogsourceå±æ§ïŒ
ã€ãã³ããœãŒã¹ã®èª¬æã¯ãlogsourceãã£ãŒã«ãã®å€ã«å«ãŸããŠããŸãããã®ã»ã¯ã·ã§ã³ã§ã¯ãæ€åºã»ã¯ã·ã§ã³ã®ã€ãã³ããé ä¿¡ãããããŒã¿ãœãŒã¹ã«ã€ããŠèª¬æããŸãïŒæ€åºå±æ§ã«ã€ããŠã¯æ¬¡ã®ã»ã¯ã·ã§ã³ã§èª¬æããŸãïŒããã®ã»ã¯ã·ã§ã³ã§ã¯ãæ€åºã«å¿ èŠãªãœãŒã¹èªäœããã©ãããã©ãŒã ãããã³ã¢ããªã±ãŒã·ã§ã³ã«ã€ããŠèª¬æããŸããã³ã³ããŒã¿ãŒã«ãã£ãŠèªåçã«åŠçããã3ã€ã®å±æ§ãšãä»»æã®æ°ã®ãªãã·ã§ã³èŠçŽ ãå«ããããšãã§ããŸããåºæ¬çãªãã£ãŒã«ãïŒ
- ã«ããŽãª -補åã®ã¯ã©ã¹ã説æããŸãããã®ãã£ãŒã«ãã®å€ã®äŸïŒãã¡ã€ã¢ãŠã©ãŒã«ããŠã§ãããŠã€ã«ã¹å¯ŸçããŸãããã£ãŒã«ãã«ã¯ã以äžã§èª¬æããäžè¬åãããã«ããŽãªãå«ããããšãã§ããŸãã
- 補åã¯ããã°ãäœæãããœãããŠã§ã¢è£œåãŸãã¯ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ãã
- ãµãŒãã¹ -ãã°ãç¹å®ã®ãµãŒãã¹ã®ãµãã»ããã«å¶éããŸããããšãã°ãLinuxã®å Žåã¯ãsshdããWindowsã®å Žåã¯ãã»ãã¥ãªãã£ãã§ãã
- å®çŸ© -ãœãŒã¹ã®æ©èœã説æããããã®è¿œå ãã£ãŒã«ããããšãã°ãç£æ»ãã»ããã¢ããããããã®èŠä»¶ïŒãŸãã«äœ¿çšãããŸãããã®ãã£ãŒã«ãã®ã«ãŒã«ã®äŸã¯GitHubã«ãããŸãïŒããœãŒã¹ã«è©³çŽ°ãããå Žåã¯ããã®å±æ§ã䜿çšããããšããå§ãããŸãã
â
GitHub ã®å ¬åŒwiki ã¯ãã«ãŒã«ãã¯ãã¹ãããã¯ãã«ãªãããã«äœ¿çšããå¿ èŠãããäžé£ã®ãã£ãŒã«ããå®çŸ©ããŠããŸãããããã®ãã£ãŒã«ãã以äžã®è¡šã«ãŸãšããŸãã
ã«ããŽãªãŒ | 補å | ãµãŒãã¹ |
---|---|---|
ãŠã£ã³ããŠãº | å®å¿ | |
ã·ã¹ãã | ||
sysmon | ||
ã¿ã¹ã¯ã¹ã±ãžã¥ãŒã© | ||
wmi | ||
å¿çš | ||
DNSãµãŒã㌠| ||
ãã©ã€ããŒãã¬ãŒã ã¯ãŒã¯ | ||
ãã¯ãŒã·ã§ã« | ||
powershell-classic | ||
Linux | auth | |
ç£æ» | ||
ã¯ã©ãã | ||
ã¢ããã | ã¢ã¯ã»ã¹ | |
ãšã©ãŒ | ||
process_creation | ãŠã£ã³ããŠãº | |
代ç | ||
ãã¡ã€ã¢ãŠã©ãŒã« | ||
ãŠã§ããµãŒã㌠| ||
DNS |
次ã«ã䜿çšãããã€ãã³ããã£ãŒã«ãã瀺ããã°ã®ããã€ãã®ãœãŒã¹ããã詳现ã«èª¬æãããããã®ãã£ãŒã«ãã䜿çšãããã«ãŒã«ã®äŸã瀺ããŸãã
ãããã·ã«ããŽãªã®ã€ãã³ããã£ãŒã«ã
ã«ããŽãªãŒ | 補å/ãµãŒãã¹ | ç°ç | äŸ |
---|---|---|---|
代ç | c-uri | proxy_ursnif_malware.yml | |
c-uri-extension | proxy_download_susp_tlds_blacklist.yml | ||
c-uri-query | proxy_susp_flash_download_loc.yml | ||
c-uri-stem | proxy_susp_flash_download_loc.yml | ||
c-useragent | proxy_powershell_ua.yml | ||
cs-bytes | - | ||
cs-cookie | proxy_cobalt_amazon.yml | ||
cs-host | proxy_cobalt_ocsp.yml | ||
csã¡ãœãã | proxy_downloadcradle_webdav.yml | ||
r-dns | proxy_apt40.yml | ||
cs-referrer | - | ||
cs-ããŒãžã§ã³ | - | ||
scãã€ã | - | ||
sc-status | proxy_ursnif_malware.yml | ||
src_ip | - | ||
dst_ip | - |
ãã®ãœãŒã¹ã®ã€ãã³ããã£ãŒã«ãã®èª¬æ
-------------------------------------------------- ------------- c-uri - URI, c-uri-extension - URI. c-uri-query - URI, c-uri-stem - URL ( :) . URIstem - c-useragent - UserAgent HTTP- cs-bytes - , cs-cookie - cookie, cs-host - Host HTTP- cs-method - HTTP- r-dns - DNS- cs-referrer - Referrer HTTP- cs-version - HTTP, sc-bytes - , sc-status - HTTP- src_ip - IP- dst_ip - IP-
ãã¡ã€ã¢ãŠã©ãŒã«ã€ãã³ããã£ãŒã«ã
ã«ããŽãªãŒ | 補å/ãµãŒãã¹ | ç°ç | äŸ |
---|---|---|---|
ãã¡ã€ã¢ãŠã©ãŒã« | src_ip | - | |
src_port | - | ||
dst_ip | - | ||
dst_port | net_high_dns_bytes_out.yml | ||
ãŠãŒã¶ãŒå | - |
ãã®ãœãŒã¹ã®ã€ãã³ããã£ãŒã«ãã®èª¬æ
--------------------------------------------------------------- src_ip - IP- src_port - , dst_ip - IP- dst_port - , username - ,
WebãµãŒããŒã«ããŽãªã®ã€ãã³ããã£ãŒã«ã
ã«ããŽãªãŒ | 補å/ãµãŒãã¹ | ç°ç | äŸ |
---|---|---|---|
ãŠã§ããµãŒã㌠| c-uri | web_cve_2020_0688_msexchange.yml | |
c-uri-extension | - | ||
c-uri-query | - | ||
c-uri-stem | - | ||
c-useragent | - | ||
cs-bytes | - | ||
cs-cookie | - | ||
cs-host | - | ||
csã¡ãœãã | web_cve_2020_0688_msexchange.yml | ||
r-dns | - | ||
cs-referrer | - | ||
cs-ããŒãžã§ã³ | - | ||
scãã€ã | - | ||
sc-status | - | ||
src_ip | - | ||
dst_ip | - |
ãã®ãœãŒã¹ã®ã€ãã³ããã£ãŒã«ãã®èª¬æ
--------------------------------------------------------------- c-uri - URI, c-uri-extension - URI. c-uri-query - URI, c-uri-stem - URI ( :) . URI stem - c-useragent - UserAgent HTTP- cs-bytes - , cs-cookie - cookie, cs-host - Host HTTP- cs-method - HTTP- r-dns - DNS- cs-referrer - Referrer HTTP- cs-version - HTTP, sc-bytes - , sc-status - HTTP- src_ip - IP- dst_ip - IP-
äžè¬åãããã«ããŽãª
ã·ã°ãã¯ãã°ããŒã¹ã®æ€åºã«ãŒã«ãèšè¿°ããããã®äžè¬çãªåœ¢åŒã§ããããããã®ãããªã«ãŒã«ã®æ§æã¯ãããŸããŸãªã·ã¹ãã ã®æ€åºããžãã¯ãèšè¿°ã§ããã¯ãã§ããäžéšã®ã·ã¹ãã ã§ã¯ãã€ãã³ãã§ã¯ãªãéèšããŒã¿ãå«ãããŒãã«ã䜿çšããããŸããŸãªãœãŒã¹ããã®ããŒã¿ãåãç¶æ³ã説æããããã«å ¥åãããå ŽåããããŸããæ§æãçµ±äžããåæ§ã®åé¡ã解決ããããã«ãäžè¬çãªãã°ãœãŒã¹ã¡ã«ããºã ãå°å ¥ãããŸãããçŸåšããã®ãããªã«ããŽãªã®1ã€ãäœæãããŠããŸã-process_creationã詳现ã«ã€ããŠã¯ãpatzke.orgããã°ãã芧ãã ããããã®ã«ããŽãªã®ãã£ãŒã«ãã®ãªã¹ãã¯ãåé¡ã®ããŒãžã«ãããŸãïŒãã®ããŒãžã§ã¯ããµããŒããããŠããä»ã®ã«ããŽãªã«ã€ããŠã説æããŠããŸãïŒã
äžè¬åãããã«ããŽãªã€ãã³ããã£ãŒã«ãprocess_creation
ã«ããŽãªãŒ | 補å | ç°ç | äŸ |
---|---|---|---|
process_creation | ãŠã£ã³ããŠãº | UtcTime | - |
ProcessGuid | - | ||
ProcessId | sysmon_raw_disk_access_using_illegitimate_tools.yml | ||
ç»å | win_susp_regsvr32_anomalies.yml | ||
FileVersion | sysmon_susp_file_characteristics.yml | ||
説æ | sysmon_susp_file_characteristics.yml | ||
補å | sysmon_susp_file_characteristics.yml | ||
äŒç€Ÿ | sysmon_susp_file_characteristics.yml | ||
ã³ãã³ãã©ã€ã³ | win_meterpreter_or_cobaltstrike_getsystem_service_start.yml | ||
ã«ã¬ã³ããã£ã¬ã¯ã㪠| win_susp_powershell_parent_combo.yml | ||
ãŠãŒã¶ãŒ | win_susp_schtask_creation.yml | ||
LogonGuid | - | ||
LogonId | - | ||
TerminalSessionId | - | ||
IntegrityLevel | - | ||
ã€ã³ããã·ã¥ | win_renamed_paââexec.yml | ||
md5 | - | ||
sha256 | - | ||
ParentProcessGuid | - | ||
ParentProcessId | - | ||
ParentImage | win_meterpreter_or_cobaltstrike_getsystem_service_start.yml | ||
ParentCommandLine | win_cmstp_com_object_access.yml |
ãã®ãœãŒã¹ã®ã€ãã³ããã£ãŒã«ãã®èª¬æ
--------------------------------------------------------------- UtcTime - UTC ProcessGuid - GUID ProcessId - PID Image - FileVersion - , Description - , Product - , Company - â , CommandLine - CurrentDirectory - User - , LogonGuid - GUID LogonId - TerminalSessionId - IntegrityLevel - , imphash - - md5 - MD5- , sha256 - SHA256- , ParentProcessGuid - GUID ParentProcessId - PID ParentImage - ParentCommandLine -
æŽæ°
ãã®èšäºã®æºåãšããŠãæ°ããäžè¬çãªã«ããŽãªãè¿œå ãããŸããã
- network_connectionïŒäŸsysmon_powershell_network_connectionïŒ
- dns_queryïŒäŸsysmon_regsvr32_network_activityïŒ
- registry_eventïŒsysmon_rdp_settings_hijackã®äŸïŒ
- file_creation
- process_accessïŒsysmon_lsass_memdumpã®äŸïŒ
- image_loadïŒäŸsysmon_mimikatz_inmemory_detectionïŒ
- process_terminated
ãããã¯ãã¹ãŠãWindowsãã°ã€ãã³ããšSysmonãã°ã€ãã³ãã®éè€ããæ å ±ã«é¢ä¿ããŠããŸããã«ãŒã«ãäœæãããšãã¯ãæ¢åã®äžè¬åãããã«ããŽãªã䜿çšããããšããå§ãããŸãããããžã§ã¯ãã¯æŽ»çºã«éçºãããŠãããããæ°ããã«ããŽãªã®åºçŸã«è¿œåŸãããããªãé©æ°ã«åŸã£ãŠã«ãŒã«ãæŽæ°ããããšããå§ãããŸãã
æ¢åã®ã«ãŒã«ã®ã€ãã³ããœãŒã¹äœ¿çšçµ±èš
以äžã®è¡šã¯ããã°ãœãŒã¹ãèšè¿°ããããã®æãäžè¬çãªæ§æã瀺ããŠããŸããã»ãšãã©ã®å Žåãããªãã¯ãããã®äžã§ããªãã®ã«ãŒã«ã«åã£ããã®ãèŠã€ããã§ãããã
æãäžè¬çãªãœãŒã¹ã®ããã€ãã«ã€ããŠã®èª¬æãã£ãŒã«ãã®çµã¿åããã®äœ¿çšã«é¢ããçµ±èšïŒããã·ã¥ã¯ãã®ãã£ãŒã«ãããªãããšãæå³ããŸãïŒïŒ
ã«ãŒã«æ° | ã«ããŽãªãŒ | 補å | ãµãŒãã¹ | æ§æã®äŸ | ã³ã¡ã³ã |
---|---|---|---|---|---|
197 | process_creation | ãŠã£ã³ããŠãº | - | logsourceïŒ
ã«ããŽãªãŒïŒprocess_creation 補åïŒWindows |
Windowsã·ã¹ãã ã§ã®ããã»ã¹äœæãã°ã®äžè¬åãããã«ããŽãªãSysmon
ã€ãã³ã
ID = 1 ããã³Windowsã»ãã¥ãªãã£ã€ãã³ããã°ã€ãã³ã ID = 4688ãå«ã |
68 | - | ãŠã£ã³ããŠãº | sysmon | ãã°ãœãŒã¹ïŒ
補åïŒWindows ãµãŒãã¹ïŒsysmon |
Sysmonã€ãã³ã |
48 | -
|
ãŠã£ã³ããŠãº | å®å¿ | logsource:
product: windows service: security |
Windows Security Event Log |
24 | proxy | â | â | logsource:
category: proxy |
- |
15 | â | windows | system | logsource:
product: windows service: system |
Windows System Event Log |
12 | accounting | cisco | aaa | logsource:
category: accounting product: cisco service: aaa |
Cisco AAA Security Services |
10 | â | windows | powershell | logsource:
product: windows service: powershell |
Microsoft Windows PowerShell Event Log |
9 | â | linux | â | logsource:
product: linux |
Linux |
8 | â | linux | auditd | ãã°ãœãŒã¹ïŒ
補åïŒLinux ãµãŒãã¹ïŒauditd |
Linuxã€ãã³ããç¹å®ã®ãµãŒãã¹ïŒAuditDãµãã·ã¹ãã ïŒã®ãã°ã®èª¬æ |
ã«ãŒã«ãæžãããã®ãã³ã
æ°ããã«ãŒã«ãäœæããå Žåã次ã®ç¶æ³ãèããããŸãã
- æ£ããã€ãã³ããœãŒã¹ã¯ãæ¢åã®ã«ãŒã«ã§æ¢ã«äœ¿çšãããŠããŸãã
- ãã®ã€ãã³ããœãŒã¹ã䜿çšããåäžã®ã«ãŒã«ããªããžããªã«ãããŸããã
æåã®ã±ãŒã¹ã«çŽé¢ããå Žåã¯ãæ¢åã®ã«ãŒã«ã®1ã€ããã³ãã¬ãŒããšããŠäœ¿çšããŸãããããããå¿ èŠãªãã°ãœãŒã¹ãä»ã®ã«ãŒã«ã§ãã§ã«äœ¿çšãããŠããå¯èœæ§ããããŸããããã¯ãããŸããŸãªSIEMã·ã¹ãã ã®ãã©ã°ã€ã³ïŒããã¯ãšã³ãã³ã³ããŒã¿ãŒïŒã®äœæè ãããããããããã³ã°ã§ãããèæ ®ã«å ¥ããŠãããã«ãŒã«ãããã«æ£ããåŠçãããããšãæå³ããŸãã
2çªç®ã®ç¶æ³ã§ã¯ãæ¢åã®ã«ãŒã«ã®äŸã䜿çšããŠãã«ããŽãªãŒã補åãããã³ãµãŒãã¹IDãæ£ãã䜿çšããæ¹æ³ãç解ããå¿ èŠããããŸããç¬èªã®ãã°ãœãŒã¹ãäœæããå Žåãæ¢åã®ããã¯ãšã³ãã®ãã¹ãŠã®ãããã³ã°ã«è¿œå ããããšããå§ãããŸããä»ã®è²¢ç®è ãéçºè ã§ãããããè¡ãããšãã§ããŸãããäž»ãªããšã¯ãã®ãããªå¿ èŠæ§ã«ã€ããŠç¥ãããããšã§ãã
æ¢åã®ã«ãŒã«ã®ãã°ãœãŒã¹ã®èª¬æãã£ãŒã«ãã®çµã¿åããã®èŠèŠåãäœæããŸããã
ãã°ãœãŒã¹ã®é åž
ãã°ãœãŒã¹å±æ§ãµããã£ãŒã«ãã®çµã¿åããã«çµ±èšã䜿çšãã
ãã®èšäºã§ã¯ãåçŽãªã«ãŒã«ãäœæããäŸã瀺ããã€ãã³ããœãŒã¹ã®èª¬æã«ã€ããŠèª¬æããŸãããããã§ãåŸãããç¥èãé©çšããSigmaãªããžããªã®ã«ãŒã«ã確èªããŠãç¹å®ã®ã«ãŒã«ã§äœ¿çšãããŠãããœãŒã¹ãç¹å®ã§ããŸããç§ãã¡ã®åºçç©ã«åŸã£ãŠãã ããã次ã®éšåã§ã¯ãã·ã°ãã«ãŒã«ã®æãé£ããéšåãã€ãŸãæ€åºããžãã¯ã説æããã»ã¯ã·ã§ã³ãèŠãŠãããŸãã
èè ïŒAnton Kutepovããšãã¹ããŒããµãŒãã¹éšéãšããžãã£ããã¯ãããžãŒéçºã®ã¹ãã·ã£ãªã¹ãïŒPT Expert Security CenterïŒ