ãŸã 挫ç»ãããæã ç¬ãããã
ãã®ãããæšæºã®ç£èŠããŒã«ã§ã¯äžååã«ãªãã€ã€ãããŸããããã«ã¯ããã€ãã®èŠå ããããŸãã
- 䟵害ã®ææšïŒããã·ã¥ãIPã¢ãã¬ã¹ãããã³ãã¡ã€ã³åïŒã¯ãæ»æè ã«ãšã£ãŠãç¹ã«APTã®å Žåãå€æŽã容æã§ããããã1åéãã®äœ¿çšã§ããããšããããããŸãã
- æ»æè ã¯ãæ£åœãªå®è¡å¯èœãã¡ã€ã«ãæšæºã®OSããŒã«ãªã©ã䜿çšããŸãã
- , ;
- , , ;
- .
æ»æãæ£åžžã«æ€åºããããšããŠãã質åã«æ確ã«çããã®ã«ååãªæ å ±ããããŸãããçŸåšã®ã€ã³ã·ãã³ãã䜿ãæããããŠããããä»ã®äœããã®å¯Ÿçãå¿ èŠã§ããçµå±ã®ãšãããã¬ãžã¹ããªã®æäœããã¡ã€ã«ã®äœæãã¡ã¢ãªãžã®ã¢ãžã¥ãŒã«ã®ããŒããäœæãããããã»ã¹ã®ã³ãã³ãã©ã€ã³ãªã©ãå€ãã®ã€ãã³ãã¯åçŽã«è¿œè·¡ãããŸããã
ãšã³ããã€ã³ãç£èŠã¯ãæ»æãæ€åºããã³é²æ¢ããæ©èœãå€§å¹ ã«æ¡åŒµããŸããããã«ãããããã·ã¥ãIPãããã³ãã¡ã€ã³ã®æ€åºããããã¹ãã¢ãŒãã£ãã¡ã¯ããããŒã«ãããã³TTPïŒã¯ãããŸãã«ãçã¿ã®ãã©ããããïŒã®æ€åºã«ç§»è¡ã§ããŸãã
å®éã«é »ç¹ã«ééãããã¹ãã®ç£èŠãªãã§ã¯æ€åºãããªãææ³ã®ããã€ãã®äŸïŒ
- DLLãã€ãžã£ãã¯
- åå°ãé¢ããŠæ®ãã
- Mimikatzã®äœ¿çš
è¿œå ã®ãšã³ããã€ã³ãç£èŠã¯ãçµã¿èŸŒã¿ã®OSããŒã«ïŒé«åºŠãªç£æ»ïŒãç¡æã®ãŠãŒãã£ãªãã£ïŒSysmonãªã©ïŒãããã³åçšãœãªã¥ãŒã·ã§ã³ïŒEDRã¯ã©ã¹ã®è£œåïŒã䜿çšããŠå®è¡ã§ããŸããäžèšã®ææ³ã®ããŸããŸãªããªãšãŒã·ã§ã³ãæ€åºããäŸã䜿çšããŠããããã®ã¢ãããŒãã®é·æãšçæãæ€èšããŠã¿ãŸãããã
é«åºŠãªç£æ»ãWindowsã€ãã³ããã°
çµã¿èŸŒã¿ã®ç£æ»ã«ã€ããŠã¯èª°ããç¥ã£ãŠããŸããå®è·µã瀺ãããã«ãã³ãã³ãã©ã€ã³ãšäžç·ã«ããã»ã¹äœæã€ãã³ãã®ã³ã¬ã¯ã·ã§ã³ã1ã€ã ãå«ããããšã§ãã€ã³ã·ãã³ãã®ç£èŠãšèª¿æ»ã®ããã»ã¹ãå€§å¹ ã«å®¹æã«ãªããŸãïŒãã¬ãŒãã®æ³åïŒã
é©åãªæ§æã§ãæšæºçãªã¢ãããŒãã®ããã€ãã®ã®ã£ãããåãã次ã®ããšã確èªããŸãã
- ã³ãã³ãã©ã€ã³ãšäžç·ã«ããã»ã¹ãéå§ããäºå®ã
- ãã³ãŒããããPowerShellã¹ã¯ãªããïŒã¹ã¯ãªãããããã¯ãã®ã³ã°ïŒ
- éšåçã«-ãã¡ã€ã«ãšã¬ãžã¹ããªãæäœããŸãã
- ã¢ã«ãŠã³ãã«é¢é£ããã¢ã¯ãã£ããã£ïŒãŠãŒã¶ãŒã®äœæ/åé€ãªã©ïŒã
æ°ãããã¯ããã¯ãèŠã€ããæ©äŒããããŸãã
- ç¹å®ã®ãã¹ã§ãã¡ã€ã«ãäœæããããã®ããã€ãã®DLLãã€ãžã£ãã¯ãªãã·ã§ã³ã
- ã³ãã³ãã©ã€ã³ã®ãã¿ãŒã³ã§LOLBinãšMimikatzã䜿çšããŸãã
ãã ããæ»æè ã¯äŸç¶ãšããŠæ€åºãåé¿ããããšãã§ããŸããLOLBinã®å Žåãããã¯ãã¡ã€ã«ãå¥ã®ååã§å¥ã®ãã©ã«ããŒã«ã³ããŒããã³ãã³ãã©ã€ã³ããããã«ããããå¯èœæ§ããããŸãããŸããMimikatzã¯ãã³ãã³ããšè¡ãå€æŽããŠåã³ã³ãã€ã«ã§ããŸããããã«ãããã³ãã³ãã©ã€ã³ã§ã®äœ¿çšãæ€åºã§ããªããªããŸãããŸããDLLãã€ãžã£ãã¯ã®å¯Ÿè±¡ãšãªãæ£åœãªãã€ããªãã¡ã€ã«ããã·ã³ã«é 眮ãããŠããå Žåããªãã·ã§ã³ã¯è¡šç€ºãããŸããã
è¡ãå€æŽãããMimikatzã³ãŒã
ãµãŒãããŒãã£ã®ãœãããŠã§ã¢ããã¬ã€ã³ã¹ããŒã«ããªããŠããä»»æã®ã·ã¹ãã ã§Windowsç£æ»ãèšå®ã§ããŸãããé倧ãªæ¬ ç¹ããã
ãŸãã1ãäžäŸ¿ã§æ¡åŒµæ§ã®äœãæ§æã
äŸïŒç¹å®ã®ã¬ãžã¹ããªãã©ã³ããç£èŠããã«ã¯ããã®ãã©ã³ãã®ACLãåå¥ã«æ§æããå¿ èŠããããŸããå®éã«ã¯ãäœããã®ã¢ã¯ã·ã§ã³ãå®è¡ããå¿ èŠããããšããäºå®ã¯ãç¹ã«å€§èŠæš¡ãªã€ã³ãã©ã¹ãã©ã¯ãã£ã®å Žåãåé¡ãšæéã®é 延ã«ã€ãªãããŸãããããç£èŠãæ¡åŒµããããã«è¡ãããå ŽåïŒããšãã°ãUACãã€ãã¹ã®äœããã®æ¹æ³ãæ€åºããããïŒãæéã¯éèŠã§ã¯ãããŸãããããããã€ã³ã·ãã³ãäžã«ãã®ãããªå¿ èŠãçããå Žåã察å¿ããã»ã¹ãè€éã«ãªããŸãã
2.ã³ã³ãããŒã«ã®æ¬ åŠã
ã€ãã³ãã䜿çšãããŠããç£èŠã·ã¹ãã ã®ç»é²ãŸãã¯å ¥åãåæ¢ããå Žåãéäžåãè¡ãããªãããããããæéå ã«ç解ã§ããªãå¯èœæ§ããããŸãã
3.å察ã®ããããã
ç緎床ã®äœãæ»æè ã§ãããæšæºçãªç£æ»ãã身ãé ãæ¹æ³ãç¥ã£ãŠããŸããå¯äžã®åé¡ã¯ã圌ããã©ãã ãå¹æçãã€ç®ã«èŠããªã圢ã§ãããè¡ãããšããããšã§ãã
ãã¯ããã¯ã®äŸïŒ
- ãã°ã®å®æçãªã¯ãªãŒãã³ã°ãã€ãã³ãå埩ãæåããå¯èœæ§ã¯ãã¯ãªãŒã³ã¢ããããã©ãã ãã®æéãçµéãããã«ãã£ãŠç°ãªããŸãã
- ç£æ»ãµãŒãã¹ã¹ã¬ãããäžæåæ¢ããŠãããæªæã®ããã¢ã¯ã·ã§ã³ãå®è¡ããããã€ãã³ããåé€ããŸãïŒããšãã°ãããŒã«github.com/QAX-A-Team/EventCleanerã䜿çšããŸãïŒã
- 察å¿ãã.evtxãã¡ã€ã«ã®æ§é ãå£ããŠã€ãã³ããé衚瀺ã«ããŸãã
- ã€ãã³ããäžæçã«å¥ã®ãã¡ã€ã«ã«ãªãã€ã¬ã¯ãããŸãããã®ææ³ã«ã€ããŠã¯ãååã®èšäºã§èª¬æããŸããã
4.ããèªäœã§ã¯ãç£æ»ãèšå®ããŠãç£èŠãæŽçããæ©äŒã¯æäŸãããŸããããŸããã€ãã³ãã®éäžã³ã¬ã¯ã·ã§ã³ã確ç«ããŠãããSIEMãªã©ã®è¿œå ããŒã«ã䜿çšããŠã€ãã³ããåæããå¿ èŠããããŸãã
5.ã€ãã³ãã®æ å ±éãå°ãªããèµ·åãããããã»ã¹ã®ããã·ã¥ãååŸããããããã»ã¹ã¡ã¢ãªãžã®ã©ã€ãã©ãªã®ããŒããç£èŠãããããããšã¯ã§ããŸããã
SysmonãšEDRã®é¡äŒŒç¹
Sysmonã¯ãã·ã¹ãã ã§ããã¢ã¯ãã£ããªã¢ã¯ã·ã§ã³ãå®è¡ããæ©èœããªããããå®å šãªEDRãœãªã¥ãŒã·ã§ã³ã§ã¯ãããŸããããã ããã€ãã³ããåéããã¡ã«ããºã ã¯ãåçšEDRã®å ŽåãšãŸã£ããåãã§ããã«ãŒãã«ã³ãŒã«ããã¯ãšETWã®2ã€ã®ãã¯ãããžã§æ©èœããŸãããããã«ã€ããŠã¯è©³ãã説æããŸãããã€ãã³ããã©ã®ããã«è¡šç€ºãããããããã³ã€ãã³ãã®äœæã®éå§è ã¯èª°ãã«ã€ããŠã®ã¿æ€èšããŸãã
â¢ã«ãŒãã«ã³ãŒã«ããã¯ãããšãã°ãPcreateProcessNotifyRoutineãPcreateThreadNotifyRoutineã§ãã
ãããããã³ãã®ä»ã®ã³ãŒã«ããã¯ãåŒã³åºãããå Žæãšæ¹æ³ã¯ã察å¿ããã«ãŒãã«é¢æ°ã§ç¢ºèªã§ããŸããããã»ã¹ã®äœææã«ã³ãŒã«ããã¯ãåŒã³åºãäŸã以äžã«ç€ºããŸã
ãCreateProcessWâNtCreateUserProcessâPspInsertThreadã®ã³ãŒã«ããã¯ã«ãŒããã€ãŸããCreateProcessãåŒã³åºãã芪ããã»ã¹ã¹ã¬ããã«ãã£ãŠãããã®ã³ãŒã«ããã¯ãåŒã³åºããŸãã
â¢ã€ãã³ããã¬ãŒã¹ãŠã£ã³ããŠïŒETWïŒã
ETWã¯ãã€ãã³ãã®çºçã«å¯ŸããŠåæ§ã«æ©èœããŸããããã»ã¹äœæã®äŸãããäžåºŠèŠãŠã¿ãŸããããCreateProcessWãåŒã³åºããããšã芪ããã»ã¹ã¹ã¬ããã¯æ¬¡ã®ã¢ã¯ã·ã§ã³ãå®è¡ããŸãïŒç°¡ç¥å³ïŒ
ãCreateProcessWïŒkernel32.dllïŒ
NtCreateUserProcessïŒntdll.dllãã«ãŒãã«ã¢ãŒãã«åãæ¿ãïŒ
NtCreateUserProcessïŒntoskrnl.exeãã«ãŒãã«ã¢ãŒãã§åäœïŒ
PspInsertThreadïŒã³ãŒã«ããã¯ãããã§åŒã³åºãããŸã ' iïŒ
EtwTraceProcess
EtwpPsProvTraceProcess
EtwWrite
ãããã£ãŠã芪ããã»ã¹ã¹ã¬ããã¯ETWã€ãã³ãã®çŽæ¥ã®ã€ãã·ãšãŒã¿ãŒã§ãããããã¯ãŒã¯ã€ãã³ããªã©ã®ä»ã®ã€ãã³ãã®èšé²ã¯ãã»ãŒåãããã«æ©èœããŸãã以äžã¯ããããã¯ãŒã¯ã¢ã¯ãã£ããã£ã«é¢é£ããã€ãã³ãã®äœæäŸã§ãã
EtwpNetProvTraceNetworkã³ã¢æ©èœ
äžèšãã2ã€ã®çµè«ãç¶ããŸãã
- SysmonãšEDRã¯ã©ã¡ããããã€ãã£ãã®Windowsæ©èœã®ã¿ã䜿çšããŠã€ãã³ããåéããä¿¡é Œæ§ã®é«ãæäœãä¿èšŒããŸãã
- æ»æè ã¯ãSysmonãšEDRã®äž¡æ¹ã«é©çšãããé£èªåææ³ã䜿çšããå¯èœæ§ããããŸããã«ãŒãã«ã³ãŒã«ããã¯ã¯ã眲åããããã©ã€ããŒã䜿çšããŠã«ãŒãã«ã¡ã¢ãªã«ããããã§ããŸãããŸãã説æãããŠããã€ãã³ããã®ã³ã°ã¡ã«ããºã ãç¥ã£ãŠãããšãSysmonããã³äžéšã®EDRãããã»ã¹ãžã®ç¹å®ã®æ³šå ¥æè¡ïŒããšãã°ãAPCã䜿çšïŒãŸãã¯PPIDã¹ããŒãã£ã³ã°ãæ€åºã§ããªãçç±ãç解ã§ããŸãã
Sysmon
Sysmonã䜿çšãããšãæšæºç£æ»ã®æ©èœãæ¡åŒµã§ããŸãããã®å Žåãã€ãã³ãã¯å¥ã®ãã°ã«èšé²ãããŸããWindows Auditingã«ã¯ãªãããSysmonã§å©çšã§ããæ å ±ã®äŸïŒ
- èµ·åãããå®è¡å¯èœãã¡ã€ã«ã«é¢ãããã詳现ãªæ å ±ïŒããã·ã¥ãå ã®ååãããžã¿ã«çœ²åãªã©ïŒã
- ãã©ã€ããšã©ã€ãã©ãªã®ããŒãã
- SysmonãµãŒãã¹ã®ã¹ããŒã¿ã¹ãå€æŽããã
- å¥ã®ããã»ã¹ã§ã¹ã¬ãããäœæããã
- ããã»ã¹ãžã®ã¢ã¯ã»ã¹ã
- 代æ¿ããŒã¿ã¹ããªãŒã ã§äœæããããã¡ã€ã«ã®ããã·ã¥ã
- ãã€ãã®äœæã
äžèšã®ããã»ã¹ãç£èŠããããšã®å©ç¹ã¯æããã§ãïŒãããªãã¯ãã¡ã€ã³ã§ããŸããŸãªææ³ãæ€åºãããããã¯ã«é¢ããå€ãã®ã«ãŒã«ãšèšäºããããŸãïŒãããã«ãããç¥ãããŠããææ³ã®æ°ããããªãšãŒã·ã§ã³ãæ€åºããããšãå¯èœã«ãªããŸãã
- å¥ã®ååã§LOLBinãã³ããŒããããšã¯ãããã»ã¹äœæã€ãã³ãã®OriginalFileNameãImageãããã³Hashesãã£ãŒã«ãã®å¯Ÿå¿ã«ãã£ãŠæ€åºã§ããŸãã
- 眲åãããŠããªãã©ã€ãã©ãªã®ããŒããæ€åºã§ããŸããããã«ãããDLLãã€ãžã£ãã¯ãæ€åºã§ããå ŽåããããŸãã
- äžèšã®ã¡ãœããã䜿çšããããlsass.exeããã»ã¹ãžã®ProcessAccessã€ãã³ãã«ãã£ãŠãMimikatzãæ€åºããå¯èœæ§ããããŸãã
ç£æ»ã¯æ§æãã¡ã€ã«ã䜿çšããŠæ§æãããŸããæ§æãã¡ã€ã«ã¯ããã¡ã€ã«äœæããã³ã¬ãžã¹ããªã€ãã³ãã®å ŽåãACLãèšå®ãããããã¯ããã«äŸ¿å©ã§ãã
ãã®å Žåã次ã®ç¹ãèæ ®ããå¿ èŠããããŸãã
- è¿œå ã®ããŒã«ã®å¿ èŠæ§ãé«åºŠãªWindowsç£æ»ã®å Žåãšåæ§ã«ãã€ãã³ãã¯ãã°ã«èšé²ããããããSysmonã¯ä»ã®ããŒã«ïŒSIEMãªã©ïŒãšçµã¿åãããŠäœ¿çšââããå¿ èŠããããŸãã
- . , Sysmon . .
, . - -. , . , Sysmon . : , , .
Sysmonã®äžéšã®æ©èœããã€ãã¹ããæ¹æ³ã«ã€ããŠã¯ãããããããããã³ããã§èªãããšãã§ããŸãã
ãšã³ããã€ã³ãã®æ€åºãšå¿ç
ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ãµã€ãºãšéèŠåºŠã倧ãããªãã«ã€ããŠãSysmonã®æ¬ é¥ã¯é倧ã«ãªããŸããé«å質ã®EDRã«ã¯ããã€ãã®å©ç¹ããããŸãïŒè£œååºæã®æ©èœã«ã€ããŠã¯èª¬æããŸããïŒ
ã1ïŒãã°ã«èšé²ãããã€ãã³ãã®æ¡åŒµã»ãã
ãã¹ãŠã¯ç¹å®ã®è£œåã«ãã£ãŠç°ãªããŸããããšãã°ãã³ãã³ãã©ã€ã³ãžã®ãã¹ãŠã®å¯Ÿè©±åå ¥åã®ãã°ããããŸããããã«ãããWindowsç£æ»ã§ãSysmonã§ã衚瀺ãããªãææ³ãæ€åºã§ããŸãã
調æ»äžã«èŠãMimikatzã®äœ¿çšäŸã説æãã䟡å€ããããŸãããªãœãŒã¹ã«æå·åãããMimikatzãå«ãå®è¡å¯èœãã¡ã€ã«ããããŸããæ£ãããã¹ã¯ãŒããšåæåãã¯ãã«ãã³ãã³ãã©ã€ã³ã§æž¡ããããšãMimikatzã¯æ£åžžã«åŸ©å·åããã€ã³ã¿ã©ã¯ãã£ãã³ãã³ãã©ã€ã³ã§ã³ãã³ããåãå ¥ããŸããåæã«ãããã»ã¹äœæã€ãã³ãã«ã³ãã³ãã¯è¡šç€ºãããŸããã
次ã«ãã€ã³ã¿ã©ã¯ãã£ãå ¥åããã°ã«èšé²ãããšãMimikatzãåã³ã³ãã€ã«ãããŠããªãå ŽåïŒãã®å Žåãè¡ã¯å€æŽãããŠããªãïŒããã®ãããªã±ãŒã¹ãæ€åºããã®ã«åœ¹ç«ã¡ãŸãã
2ïŒäžå åããã管çãšæ§æ
倧èŠæš¡ãªã€ã³ãã©ã¹ãã©ã¯ãã£ã§ã¯ããã«ã¹ãäžå çã«ãã§ãã¯ãããšãŒãžã§ã³ãèšå®ãå€æŽããæ©èœãéèŠã§ããããããªããšãå¿çãæ°æéãå Žåã«ãã£ãŠã¯æ°æ¥é ããããšããããŸãã
3ïŒèªçµŠèªè¶³
ã»ãšãã©ã®å ŽåãEDRã¯ç¬èªã®ã€ã³ã¿ãŒãã§ãŒã¹ãåããç¬ç«ãã補åã§ãããä»ã®ããŒã«ãšçµã¿åãããŠäœ¿çšââããã ãã§ãªããåå¥ã«äœ¿çšããããšãã§ããŸãã
ç¬èªã®æ€åºã«ãŒã«ãäœæã§ããå ŽåããããŸããå©çšå¯èœãªããŒã¿ã®ã»ããã¯AdvancedAuditingãŸãã¯Sysmonã®ããŒã¿ããã倧ãããããã¢ããªã¹ãã¯ããŸããŸãªæ»æãã¿ãŒã³ãæ€åºããæ©äŒãå€ããªããŸãã
4ïŒç©æ¥µçãªå¯Ÿå¿ã®å¯èœæ§
ã€ã³ã·ãã³ã察å¿äžãã»ãšãã©ã®å Žåãè€æ°ã®ã·ã¹ãã ã§ã¢ã¯ã·ã§ã³ãå®è¡ããå¿ èŠæ§ãåé¡ã«ãªããŸãã
EDRã䜿çšãããšã䟿å©ãªã€ã³ã¿ã©ã¯ãã£ã圢åŒã§å€ãã®ã¢ã¯ã·ã§ã³ãå®è¡ã§ããŸãã
- ãã¡ã€ã«ãšã¬ãžã¹ããªãæäœãã
- ãããã¯ãŒã¯æ¥ç¶ããããã¯ãã
- ããã»ã¹ãçµäºãã
- ã€ã©ã«ãŒã«ã§ã¹ãã£ã³
- ããã«åæããããã«ã¢ãŒãã£ãã¡ã¯ããåéããŸãïŒããšãã°ãã¡ã¢ãªã€ã¡ãŒãžïŒ
- äžèšã®ãã¹ãŠãããçšåºŠèªååãã
- ãšã¯ããã«ã
EDR補åã¯ã©ã¹ã¯å ã ããã¹ãã®ç£èŠãšå¿çãæäŸããããã«äœæãããããããã®åéã§ã®ãã®ãããªãœãªã¥ãŒã·ã§ã³ã®æ¬ ç¹ã¯å€§å¹ ã«å°ãªããªã£ãŠããŸããããã¯ãã¹ãŠãç¹å®ã®è£œåã®æ©èœã«äŸåããŸããæ»è§ããããŸããããšãã°ããããã¯ãŒã¯ã¢ã¯ãã£ããã£ã®è©³çŽ°ãªåæã¯ãããŸããïŒNTA / NDR補åã«ãã£ãŠæ£åžžã«è§£æ±ºãããåé¡ïŒã
å®è·µã«ããã°ãã€ã³ãã©ã¹ãã©ã¯ãã£ã«EDRãååšããããšã§ãè åšãç¹å®ããæ©èœãå€§å¹ ã«æ¡åŒµãããã ãã§ãªãã察å¿ãè¿ éåãããã€ã³ã·ãã³ãã®èª¿æ»ã容æã«ãªããã€ãã³ãã®æç³»åãããæ£ç¢ºã«åæ§ç¯ã§ããããã«ãªããŸããSysmonã¯äžéå端ãªæ段ãšããŠæ©èœãããã€ãã¹ããããæšæºç£æ»ã1ã€ãããªãå Žåã¯ãåã®èšäºã§èª¬æããç°åžžãªã¢ãŒãã£ãã¡ã¯ããªã©ãæ å ±éã®å°ãªãã¢ãŒãã£ãã¡ã¯ãã«æºè¶³ããå¿ èŠããããŸãã
JSOC CERTãã€ã³ã·ãã³ã調æ»éšéãã·ãã¢æè¡èª¿æ»ãšã³ãžãã¢ãAskerJamirzeã«ããæçš¿