ã¡ã¿æ å ±ãæã€å±æ§
ã¿ã€ãã«ïŒã¿ã€ãã«å±æ§ïŒ
ã¿ã€ãã«ã¯ãã«ãŒã«ã®æ¬è³ªãç°¡åã«èª¬æããŠããŸãããã®ããã¹ããã£ãŒã«ãã®é·ãã¯æå€§256æåã§ããããã§ã¯ãæçã§æã容éã®å€§ãã説æãå ¥åããå¿ èŠããããŸããæ¬¡ã®ã¬ã€ãã©ã€ã³ã«åŸã£ãŠãã ããã
- ãDetects ...ãã®ãããªæ§æèŠçŽ ãèŠåºããšããŠäœ¿çšããªãã§ãã ããããããŠããããªããã°ãã«ãŒã«ãäœããæ€åºããããšã¯æããã§ãã
- 50æå以å ã®å®¹éã®ããã¿ã€ãã«ã䜿çšããŠãã ããã
- 説æãã£ãŒã«ãã«èª¬æãšéèŠãªã³ã¡ã³ããèšå ¥ããŸãïŒããã«æ€èšããŸãïŒã
ã«ãŒã«ã®è©³çްãªèª¬æãšè¿œå ã®èª¬æïŒèª¬æå±æ§ïŒ
ã¿ã€ãã«ã«ãã®ç®çã®äžè¬çãªçè§£ã®ããã«ã«ãŒã«ã®ç°¡åãªèª¬æãå«ãŸããŠããå Žåã説æãã£ãŒã«ãã§ãäœæè ããã®ã«ãŒã«ã«å ¥ãããã¹ãŠã®ãã¥ã¢ã³ã¹ãšæ©èœãæå®ã§ããŸãããŸãããã®ã«ãŒã«ã䜿çšããŠæ€åºããããšãææ¡ãããŠããæ»æã«ã€ããŠãç°¡åã«èª¬æããŸãããã®ãã£ãŒã«ãã®æå€§é·ã¯65,535æåã§ãã
ã«ãŒã«ã®äžæã®èå¥åãšé¢é£ããã«ãŒã«ã®èå¥åïŒidãrelativeïŒ
ã¿ã€ãã«å±æ§ãšèª¬æå±æ§ã®ç¹å®ã®å€ã¯ä»»æã§ããå¯èœæ§ãããã2ã€ã®ç°ãªãã«ãŒã«ã®å Žåãåãã§ããããïŒããã¯çµ¶å¯Ÿã«è¡ããªãã§ãã ããïŒãã«ãŒã«ãäžæã«èå¥ããã®ã«ã¯é©ããŠããŸãããããæ£åŒã§äžæã®èå¥åãå¿ èŠã§ãããã®åé¡ã解決ããããã«ãã»ãšãã©ã®è£œåã§ãŠãããŒãµã«äžæèå¥åïŒUUIDïŒã䜿çšãããŠããŸãã Sigmaã®äœæè ã¯ãã«ãŒã«éçºè ã«åããã¹ã«åŸãããã«ã¢ããã€ã¹ããŠããŸããããã©ã€ããŒãã«ãŒã«ã«ã¯ä»»æã®èå¥åçæã¹ããŒã ã䜿çšã§ããŸãããããªãã¯ãªããžããªã§ã¯ãåè¿°ã®UUIDãèå¥åãäœæããããã®ã¹ããŒã ãšããŠéžæãããŠããŸããèšäºã®æåã®éšåã®ã«ãŒã«äŸã§ãåãã¢ãããŒãã«åŸããŸãããå°æ¥çã«ã«ãŒã«ãå ¬éããããå ¬åŒãªããžããªã«è¿œå ãããªã¯ãšã¹ããéä¿¡ãããããå Žåã¯ã次ã«ãã«ãŒã«èå¥åãäœæããããã«åãã¹ããŒã ã«åŸãããšããå§ãããŸãã
äžæã®èå¥åã¯ããŸããŸãªæ¹æ³ã§çæã§ããŸããWindowsã§ã¯ã次ã®PowerShellã³ãŒããå®è¡ããã®ãæãç°¡åãªæ¹æ³ã§ãã
PS C:\> "id: $(New-Guid)"
id: b2ddd389-f676-4ac4-845a-e00781a48e5f
Linuxã«ãŒãã«ããŒã¹ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ã¯ãuuidgenãŠãŒãã£ãªãã£ã䜿çšã§ããŸãã
$ echo âid: `uuidgen`â
id: b2ddd389-f676-4ac4-845a-e00781a48e5f
ã«ãŒã«ã«å€§å¹ ãªå€æŽãå ããå Žåã¯ããã®èå¥åã倿Žããå¿ èŠããããŸããæ°ããèå¥åãäœæããç¶æ³ïŒ
- ã«ãŒã«ã®ããžãã¯ã倿Žããã
- å ã®ã«ãŒã«ãä¿æããªããæ¢åã®ã«ãŒã«ããã«ãŒã«ãç¶æ¿ããïŒã«ãŒã«ã®æ¹åã®ç¶æ³ã«ãåœãŠã¯ãŸããŸãïŒã
- ã«ãŒã«ã®ããŒãžã
ã«ãŒã«ã®ç¶æ¿ãšããŒãžã®å Žåãã¿ã€ãã®4ã€ã®å¯èœãªå€ïŒtype屿§ïŒã«é¢é£ããç¹å¥ãªèå¥åããããŸãã
é¢é£ããèå¥åã䜿çšãããšäŸ¿å©ãªå Žåããããšæãããç¶æ³ãèããŠã¿ãŸããããããããããããããã«ãUUID圢åŒã®é·ãèå¥åã®ä»£ããã«ãåã«XãYãZãšèšè¿°ããŸãã
æåã®ã±ãŒã¹ã§ã¯ãæ°ããã«ãŒã«ïŒidïŒXïŒã¯æ¢åã®ã«ãŒã«ïŒidïŒYïŒããæŽŸçããŸããããã¯ãæ°ããã«ãŒã«ã§äœæ¥ã®ããžãã¯ãæ¹åããå Žåã«çºçããå¯èœæ§ããããŸãããäœããã®çç±ã§å€ãã«ãŒã«ãç¶æããããšèããŠããŸãããããã£ãŠãã«ãŒã«ã«ã¯ä¿åãããå°æ¥äœ¿çšã§ãã芪ã«ãŒã«ããããŸãã
2çªç®ã®ã±ãŒã¹ã¯ã1ã€ã®äºå®ãé€ããŠãæåã®ã±ãŒã¹ãšåæ§ã§ããå€ãã«ãŒã«ã¯ä¿æãããŸãããã€ãŸããã«ãŒã«ãæ ¹æ¬çã«æžãçŽããæ°ããèå¥åãå²ãåœãŠãå¿ èŠããããå€ãèå¥åã¯å»æ¢ããïŒå»æ¢ããïŒã䜿çšãããªããªããŸãããã®ãããæžãçŽããã«ãŒã«ïŒidïŒYïŒããããããå¿ èŠãªããšå€æããŸãããæ°ããã«ãŒã«ã¯èå¥åïŒidïŒXïŒãåãåããŸãããã·ã°ãã«ãŒã«ã§ã¯ãåæ§ã®ç¶æ³ã¯æ¬¡ã®ããã«ãªããŸãã
3çªç®ã®ã±ãŒã¹ã§ã¯ã2ã€ä»¥äžã®æ¢åã®ã«ãŒã«ãããŒãžããçµæãšããŠæ°ããã«ãŒã«ã衚瀺ãããç¶æ³ãèããŠã¿ãŸããæ°ããã«ãŒã«ïŒidïŒXïŒã¯ã2ã€ã®ã«ãŒã«ïŒidïŒYãZïŒãããŒãžããçµæã§ããããŒãžã«é¢ä¿ããäž¡æ¹ã®èŠªã«ãŒã«ãä¿æãããããã«äœ¿çšã§ããããšã«æ³šæããããšãéèŠã§ããã·ã°ãã«ãŒã«ã§ã¯ãåæ§ã®ç¶æ³ã
次ã®ããã«ãªããŸããããŒãžäžã«ã«ãŒã«ã®é åºã¯å®çŸ©ãããŸããããã³ã¡ã³ãã§ã¯ããããããããããã«çªå·ãä»ããŠããŸãã
4çªç®ã®ã¿ã€ãã¯åå倿Žã§ããååã瀺ãããã«ãèå¥åéã®ãã®ã¿ã€ãã®é¢é£ä»ãã¯ãå€ãã«ãŒã«ã®ååã倿Žãããšãã«é©çšãããŸããå®éããã®ã¿ã€ãã¯å®éã«ã¯äœ¿çšãããŠããŸããã䜿çšäŸãšããŠãèè ã¯èå¥åãäœæããããã®ã¹ããŒã ã倿Žããã±ãŒã¹ãåŒçšããŠããŸãïŒUUIDãå¯äžã®å¯èœãªåœåã¹ããŒã ã§ã¯ãªãããšã«æ³šæããŠãã ããïŒã
ã«ãŒã«æºåå®äºã¹ããŒã¿ã¹ïŒã¹ããŒã¿ã¹å±æ§ïŒ
仿§ã«ããã°ãã«ãŒã«ã¯æ¬¡ã®3ã€ã®ç¶æ ã®ããããã«ãªããŸãã
- å®å®-ã«ãŒã«ãå®éã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã§äœ¿çšããŠæ»æãæ€åºã§ããŸãã倿Žã¯å¿ èŠãããŸããã
- ãã¹ã-ã«ãŒã«ã¯ã»ãŒå®å®ããŠããŸãããå°ã調æŽãå¿ èŠã§ãã
- å®éšç-ãã®ãããªã«ãŒã«ã¯å€æ°ã®èª€æ€ç¥ãçæããå¯èœæ§ããããŸãããåæã«è峿·±ãã€ãã³ããæããã«ããŸãã
éåžžãå®éã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã§ã«ãŒã«ãå®è¡ããåã¯ããšã©ãŒãçºçããé »åºŠãæ£ç¢ºã«ããããªããããã«ãŒã«ã«ã¯å®éšçãªã¹ããŒã¿ã¹ããããŸããããã«ãæ°ãæã®ãã¹ãã®åŸãã«ãŒã«ãé©åã«èšè¿°ãããŠããŠãšã©ãŒãçæãããªãå ŽåïŒãŸãã¯ãšã©ãŒãç¡èŠã§ããå ŽåïŒãå®å®ããã«ããŽãªã«è»¢éãããŸãããã以å€ã®å Žåã¯ãä¿®æ£ãè¡ãããå床ãã§ãã¯ãããŸããå ¬åŒã®Sigmaãªããžããªã«ã¯ãã¹ãã¹ããŒã¿ã¹ã®ã«ãŒã«ã¯ãããŸããã
ã«ãŒã«ãé åžãããã©ã€ã»ã³ã¹ïŒã©ã€ã»ã³ã¹å±æ§ïŒ
ã«ãŒã«ãé åžãããã©ã€ã»ã³ã¹ããã®åéã¯ããªãŒãœãããŠã§ã¢ã®äžçããæ¥ãŸãããæå®ãããããšã¯ãã£ãã«ãããŸããããæå®ããå Žåã¯ãSPDXID仿§ã«æºæ ããŠããå¿ èŠããããŸãã
ã«ãŒã«äœæè ïŒäœæè 屿§ïŒ
ãã®ãã£ãŒã«ãã«ã¯ãã«ãŒã«ã®ãã¹ãŠã®äœæè ãäžèŠ§è¡šç€ºãããŸããã«ãŒã«èªäœãæžãã人ã ãã§ãªããæ€åºã®å ã®ã¢ã€ãã¢ã®äœè ã瀺ãããšã¯è¯ã圢ã§ãããšèããããŠããŸãã
ã«ãŒã«ã®äœæã«åœ¹ç«ã£ãç ç©¶ãžã®ãªã³ã¯ïŒåç §å±æ§ïŒ
ã·ã°ãã«ãŒã«ãäœæãããšãã¯ãã«ãŒã«ã®äœæãæ¯æŽãŸãã¯åºæ¿ããå ã®èšäºããã€ãŒããããã³èª¿æ»ãžã®ãªã³ã¯ãå«ããã®ãéäŸã§ããä»ã®èª°ãã®ä»äºãžã®æ¬æã衚ãããšã«å ããŠããã®ãããªãªã³ã¯ã¯åŸã§ã«ãŒã«ãã©ã®ããã«æ©èœããããçè§£ããã®ã«åœ¹ç«ã¡ãŸãã
ã«ãŒã«ãããªã¬ãŒããããšãã«è¡šç€ºããåæã«åœ¹ç«ã€ã€ãã³ããã£ãŒã«ãïŒãã£ãŒã«ã屿§ïŒ
ã«ãŒã«ã®äœæè ã¯ãæ»æã¢ã«ãŽãªãºã ãšãã®å®è¡äžã«çæãããã€ãã³ããæ·±ãçè§£ããŠãããããSOCãªãã¬ãŒã¿ãŒãŸãã¯æ å ±ã»ãã¥ãªãã£ããŒã ã®å¥ã®åŸæ¥å¡ãã€ã³ã·ãã³ããçè§£ããã®ã«åœ¹ç«ã€ãã£ãŒã«ãã®ãªã¹ããã€ãã³ãããéžæã§ããŸãã
ã«ãŒã«ã®èª€æ€ç¥ã®ã±ãŒã¹ïŒå±æ§èª€æ€ç¥ïŒ
誀æ€ç¥ãã£ãŒã«ãã¯ãæ€åºã«ãŒã«ã§ã¯ããªãçãããã®ã§ããã€ãã³ãæ€èšŒã®éçšã«ã¯ãŸã£ãã圱é¿ããŸãããã2ã€ã®äŸ¿å©ãªããšãè¡ããŸãã
- ç¹å®ã®ã«ãŒã«ããªã¬ãŒããšã©ãŒã§ãããã©ããããŠãŒã¶ãŒã倿ã§ããããã«ããŸãã
- ã«ãŒã«ã®éçºè ã«ãã«ãŒã«ã誀ã£ãŠããªã¬ãŒãããå¯èœæ§ãããããšãããäžåºŠæãåºãããŠãã ããããã®ãããªèãã¯ãéçºè ãããæ£ç¢ºãªã«ãŒã«ãäœæããã®ã«åœ¹ç«ã¡ãŸãã
ããŸããŸãªã¿ã°ãšã¿ã°ïŒã¿ã°å±æ§ïŒ
éåžžããã®ãã£ãŒã«ãã¯MITRE ATTïŒCKããã³CARã¿ã°ã«äœ¿çšãããŸãããã®ãããªããŒã¯ã¢ããã«ãããSigmaã«ãŒã«ãä»ã®æ å ±ã»ãã¥ãªãã£ãããžã§ã¯ããšçµ±åã§ãããããã«ãŒã«ãããã«åé¡ããããšã匷ããå§ãããŸãããã ãããã®åœ¢åŒã§ã¯ãã«ãŒã«ã®äœæè ããã®ãããªã©ãã«ã®ã¿ã«å¶éããã®ã§ã¯ãªããä»»æã®ã©ãã«ãä»ããããšãã§ããŸãã
ã«ãŒã«ã®ã³ã¬ã¯ã·ã§ã³
YAMLæšæºã«ããã°ã1ã€ã®ãã¡ã€ã«ïŒçšèªã¹ããªãŒã å ïŒã«è€æ°ã®YAMLããã¥ã¡ã³ããå«ããããšãã§ããŸããããã¯ãYAMLããã¥ã¡ã³ãã¿ã°ïŒ3ã€ã®ãã€ãã³ïŒã---ãïŒïŒã®ãããã§å®çŸãããŸããSigma圢åŒã®å Žåããããã®ããã¥ã¡ã³ãã¯ç¬ç«ããSigmaã«ãŒã«ãŸãã¯ã¢ã¯ã·ã§ã³ããã¥ã¡ã³ãã«ããããšãã§ããŸãã
æåã®ã±ãŒã¹ã§ã¯ããã¹ãŠãåçŽã§ãã1ã€ã®ãã¡ã€ã«ã«å®å šãªSigmaã«ãŒã«ãå«ãŸããŠããŸãã YAMLããã¥ã¡ã³ãã©ãã«ïŒã«ãŒã«ã®äŸ/ proxy / proxy_ursnif_malware.ymlïŒã§äºãã«åé¢ãããŠãã
2çªç®ã®ã±ãŒã¹ã¯ãããè€éã§ããæäžäœã®ã¢ã¯ã·ã§ã³å±æ§ã«æ¬¡ã®3ã€ã®å€ã®ãããããããå ŽåãYAMLããã¥ã¡ã³ãã¯ã¢ã¯ã·ã§ã³ããã¥ã¡ã³ããšããŠæ±ãããŸãã
- global â , YAML- . action- . : , Sigma- ;
- reset â , action-;
- repeat â repeat .
泚ïŒaction屿§ã¯ãã«ãŒã«ã®ã©ãã«ã§ã衚瀺ã§ããŸãã
ã«ãŒã«ã®ã³ã¬ã¯ã·ã§ã³ã®æãäžè¬çãªäœ¿çšäŸã¯ãWindows Security EventID4688ãSysmonEventID 1ãªã©ãåæ§ã®ã€ãã³ãã«å¯ŸããŠè€æ°ã®Sigmaã«ãŒã«ãå®çŸ©ããããšã§ããã©ã¡ãã®ã€ãã³ããããã»ã¹äœæã®çµæãšããŠè¡šç€ºããããœãŒã¹ãç°ãªãã ãã§ããç¹å®ã®ã·ããªãªã®Sigmaã«ãŒã«ã®ã³ã¬ã¯ã·ã§ã³ã«ã¯ã次ã®3ã€ã®ã¢ã¯ã·ã§ã³ããã¥ã¡ã³ããå«ããããšãã§ããŸãã
- äžè¬çãªã¡ã¿ããŒã¿ãã£ãŒã«ããšæ€åºã€ã³ãžã±ãŒã¿ãå®çŸ©ããã°ããŒãã«ã¢ã¯ã·ã§ã³ããã¥ã¡ã³ãã
- Windowsã»ãã¥ãªãã£ã€ãã³ããã°ããã³ã€ãã³ãEventID = 4688ã®ãœãŒã¹ãå®çŸ©ããã«ãŒã«ã
- WindowsSysmonã€ãã³ããã°ããã³ã€ãã³ãEventID = 1ã®ãœãŒã¹ãå®çŸ©ããã«ãŒã«ã
å¥ã®è§£æ±ºçã¯æ¬¡ã®ãšããã§ãã
- äžè¬çãªã¡ã¿ããŒã¿ãã£ãŒã«ããå®çŸ©ããã°ããŒãã«ã¢ã¯ã·ã§ã³ããã¥ã¡ã³ãã
- Windows Security Event Log ( EventID=4688) .
- Action- repeat, logsource EventID , . 2.
action-
ãã®ã»ã¯ã·ã§ã³ã§ã¯ãã¢ã¯ã·ã§ã³å±æ§ã®å€ã«åºã¥ããŠSigmaããµããªãŒã«ãŒã«ãçæããæ¹æ³ã«ã€ããŠè©³ãã説æããŸããå€ãglobalã®action屿§ãå«ãYAMLããã¥ã¡ã³ãã¯ããã®ãã¡ã€ã«å ã®ã°ããŒãã«ããã¥ã¡ã³ããšèŠãªããããããã®ãã£ãŒã«ãã¯ä»ã®ãã¹ãŠã®ããã¥ã¡ã³ãã«è¿œå ãããŸãã
泚ïŒçŸåšã®ããã¥ã¡ã³ãã«ãªã»ããå€ã®ã¢ã¯ã·ã§ã³å±æ§ãå«ãŸããŠããå Žåãã°ããŒãã«ããã¥ã¡ã³ããã£ãŒã«ãã¯è¿œå ãããŸããã
ã°ããŒãã«ããã¥ã¡ã³ããæäœããããã®ããžãã¯ã¯æ¬¡ã®ãšããã§ããããŒãµãŒãã°ããŒãã«ããã¥ã¡ã³ãïŒã°ããŒãã«å€ãæã€ã¢ã¯ã·ã§ã³å±æ§ãå«ãããã¥ã¡ã³ãïŒãæ€åºãããšããã«ããã®ãã£ãŒã«ããç¹å¥ãªãããã¡ãŒã«è¿œå ããæ¬¡ã®ããã¥ã¡ã³ãã«é²ã¿ãŸãããã®ç¹å¥ãªãããã¡ãGLOBALYAMLãšåŒã³ãŸããããå°æ¥ãå³ã§åç §ããã®ã«åœ¹ç«ã¡ãŸãã
éèŠïŒããã¥ã¡ã³ãã®å¢çã¯ã---ãããŒã¯ã§å®çŸ©ãããŠããããããããã®ããŒã¯ããã¡ã€ã«ã«æ£ããé 眮ããããšãéèŠã§ãã
以äžã®äŸã§ã¯ãæåã®YAMLããã¥ã¡ã³ãã«å€globalã®ã¢ã¯ã·ã§ã³å±æ§ãå«ãŸããŠããŸãããã®ããã¥ã¡ã³ãã®å¢çã¯ãæåã®ããã¥ã¡ã³ãããŒã¯ãŸã§æ¡åŒµãããŸãããããã£ãŠãæåã®ããã¥ã¡ã³ãå šäœãã°ããŒãã«ãããã¡ã«æžã蟌ãŸããŸããæ¬¡ã«ããã®ãããã¡ã®ãã£ãŒã«ããåŸç¶ã®åããã¥ã¡ã³ãã«è¿œå ãããŸãããã®çµæãåºåã§2ã€ã®ã«ãŒã«ãåŸãããŸããã¹ããŒã 1.YAMLããã¥ã¡ã³ãã©ãã«ãæ£ããå²ãåœãŠãŠåçŽãªã«ãŒã«ãåŠçãã ãã ããæåã®ã©ãã«ãåé€ãŸãã¯å¿ãããšãYAMLããã¥ã¡ã³ã2ã®ãã¹ãŠã®ãã£ãŒã«ããã°ããŒãã«ããã¥ã¡ã³ãã«å«ãŸããŸãããã®çµæãåºåã«èª€ã£ãæ€çŽ¢èå¥åã®ã»ãããæã€ã«ãŒã«ã1ã€ã ãååŸãããŸãããããã£ãŠããã®ãããªè€åã«ãŒã«ã§YAMLããã¥ã¡ã³ãã«é©åã«ã©ãã«ãä»ããããšãéåžžã«éèŠã§ãã
ã¹ããŒã 2.åã®ã«ãŒã«ã®åŠç-YAMLããã¥ã¡ã³ãã®æåã®ã©ãã«ãä»ããã®ãå¿ããå Žå
ã°ããŒãã«ããã¥ã¡ã³ãã¯å¿ ãããæåã«æ¥ããšã¯éããªãããšã«æ³šæããŠãã ãããåã®2ã€ã®ã¹ããŒã ãèŠããšãå¿ ãããYAML DOCUMENT 1ã§ãããšã¯éããŸãããããã«ãåæ°åœ¢ã§ããå¿ èŠã¯ãããŸãããæ¬¡ã®å³ã¯ããããæç¢ºã«ç€ºããŠããŸããã¹ããŒã 3.ã°ããŒãã«YAMLããã¥ã¡ã³ããæå®ããããã®ããŸããŸãªãªãã·ã§ã³ãå«ãã«ãŒã«ã®åŠç ããã§ãYAMLããã¥ã¡ã³ãå ã®ã¿ã°ã®æ£ããé 眮ã«é¢é£ããåé¡ãæ€èšããŸããããŸããã°ããŒãã«å€ãæã€action屿§ã䜿çšããŠãããŸããŸãªæ¹æ³ã§ã°ããŒãã«YAMLããã¥ã¡ã³ããèšå®ã§ããããšãããããŸãããæ¬¡ã«ãã¢ã¯ã·ã§ã³å±æ§ã®æ®ãã®2ã€ã®å€ïŒãªã»ãããšç¹°ãè¿ãïŒã䜿çšããŠã«ãŒã«ã倿ããããã®ã¹ããŒã ãèŠãŠã¿ãŸãããã
ã¹ããŒã 4.ãªã»ããå€ãšç¹°ãè¿ãå€ã䜿çšããŠã¢ã¯ã·ã§ã³å±æ§ãå«ãã«ãŒã«ãåŠçãã
ã·ã°ããããžã§ã¯ãã«ã€ããŠä»ã«äœãèšãå¿ èŠããããŸãã
Sigmaã¯ããã®ã·ãªãŒãºã§åãäžãããã©ãŒããããããã«ãŒã«ã®ã»ããã ãã§ã¯ãããŸããã
ç§ãã¡ã®åºçç©ã§ã¯ãã«ãŒã«ã®åœ¢åŒãšæ§æã®èª¬æã«çŠç¹ãåœãŠãŸããããã ããã«ãŒã«ã¯ãããžã§ã¯ãã®ååã«ãããŸããã2ã€ç®ã¯ãsigmacã³ã³ããŒã¿ãŒã䜿çšããããã¯ãšã³ãã§ããåŸæ¥ããããã®ã³ã³ããŒã¿ãŒã¯ããŠãããŒãµã«å ¥åãšç¹å®ã®åºåãåãããã¢ããã¿ãŒããšèããããšãã§ããŸããæ®éçãªèšè¿°åœ¢åŒãéåžžã«äŸ¿å©ã«ããã®ã¯ããã®ãããªãã¢ããã¿ãŒãã®ååšã§ãããã®ç¶æ³ã§ã¯ããµããŒããããŠããã·ã¹ãã ã®ã©ãã䜿çšãããã¯é¢ä¿ãããŸãããSigmaã§ã¯ãã¢ã€ãã¢ãšæ€åºã¢ã«ãŽãªãºã ãèšè¿°ã§ããŸããäžæ¹ãsigmacã³ã³ããŒã¿ãŒã®ããã¯ãšã³ãã¯ãã¿ãŒã²ããã·ã¹ãã ã®ç¹å®ã®æ§æãšãã£ãŒã«ãã®ãããã³ã°ãæ åœããŸãã
ãã ããã«ãŒã«ãããŠã³ããŒãããŠå¿ èŠãªã¿ãŒã²ããã·ã¹ãã ã®æ§æã«å€æããããšã§ãã·ã¹ãã ãå°éç¥èã§æºããããšã«é¢é£ãããã¹ãŠã®åé¡ã解決ã§ãããšã¯éããŸãããSigmaãçŸæç¹ã§ããã«äœ¿çšã§ãããœãªã¥ãŒã·ã§ã³ã§ã¯ãªãçç±ãšãã«ãŒã«ã®æ§æãçè§£ããå¿ èŠãããçç±ã«ã€ããŠç°¡åã«èª¬æããŸãã
çŸåšã®ã·ã°ãã®èª²é¡
ã·ã°ãã¯æŽ»çºã«éçºãããŠãããããžã§ã¯ãã§ãããä»ã®æé·ããŠãããããžã§ã¯ããšåæ§ã«ãã·ã°ãã«ã¯ç¬èªã®èª²é¡ããããŸããå人çã«ã¯ãããããéçºã®ãã€ã³ãããã³æé·ã®é åãšããŠèªèããŠããŸããããã¯ãªãŒãã³ãœãŒã¹ãããžã§ã¯ãã§ãããããåãåãããããšã§ããããžã§ã¯ãã®ç¹å®ã®éšåã®éçºã«å€§ããè²¢ç®ããããšãã§ããŸãããã¬ãŒã ã¯ãŒã¯ã®äž»ãªåŒã³åºãã«ã€ããŠãçŸæç¹ã§äœãåç §ããŠããã®ãããªã¹ãããŸãã
- . .
- , Windows- (. ). , .
- Wiki , . .
- experimental â , .
- .
- , .
ç§èªèº«ã®çµéšãããã·ã°ããããžã§ã¯ãã«ç²ŸéããŠOSCDã«åå ãããšãããªã¹ãã®æåã®é ç®ãæãéèŠã§ããããšã倿ãããšèšããŸããMaxPatrol SIEMãšSigmaã®æ§æã®éãã¯ãããŒã¯ãŒãã®ã»ãã³ãã£ã¯ã¹ãšçžé¢ã«ãŒã«ã®èšèšã ãã«ãšã©ãŸããªãããšã倿ããŸããããã®æ®µéã§ã¯ã€ãã³ãçžé¢ã®å¯èœæ§ããªããããäžéšã®ã¢ã€ãã¢ã¯Sigmaæ§æã®èгç¹ãã説æã§ããŸãããçžé¢ã¡ã«ããºã ã䜿çšãããšãã€ãã³ããã£ãŒã«ãã®äžè¬çãªå€ãæ€çŽ¢ãããã®ãããªã€ãã³ããçžäºã«é¢é£ä»ããããšãã§ããŸããããã¯ãã€ãã³ãéã®é¢ä¿ãæ£ç¢ºã«ç¢ºç«ããå Žåã«åœ¹ç«ã¡ãŸããããšãã°ã1ã€ã®ãŠãŒã¶ãŒã»ãã·ã§ã³å ã®ã€ãã³ãã远跡ããŸãããããè¡ãã«ã¯ãLogonIDãã£ãŒã«ããŸãã¯ããã«çžåœããå€ã§ã€ãã³ãããã€ã³ãããå¿ èŠããããŸãã
ãã€ã³ãæ€åºãŸãã¯çŽæ¥é¢é£ããªãã€ãã³ãã«åºã¥ãæ€åºã¯ãSigmaã䜿çšããŠéåžžã«ããŸãèšè¿°ãããŠããããšã«æ³šæããŠãã ããã
ãããã®åé¡ããã®ä»ã®åé¡ã«å¯ŸåŠããããã®1ã€ã®æ¹æ³ã¯ãOSCDã¹ããªã³ãã®1ã€ã«ç©æ¥µçã«åå ããããšã§ãããããŠãå€ãã®ã¿ã¹ã¯ãããã®ã§ã誰ãã圌ã«ãšã£ãŠè峿·±ããã®ãèŠã€ããããšãã§ããŸãã
æ°ããã¹ããªã³ããéããªãç»å ŽããŸãããã²ãåå ãã ããã
æåã®ã¹ããªã³ãã®äž»å¬è ã«ã¯ãã€ãã³ãã®è³ªãšåå è ã«å¯Ÿããæ°é ãã®ããæ åºŠã«æè¬ã®æã衚ããŸããæã§èšå ¥ãããååå è ã«éãããå¯äžã®ããŒãœãã©ã€ãºããããã¹ãã«ãŒãã¯äœã§ããïŒç§ãã¡ã®åŽã§ã¯ãæ°ããã¹ããªã³ãã«åŒãç¶ãåå ããSigmaãªããžããªã«å®è¡å¯èœãªè²¢ç®ãããäºå®ã§ãã
äžé£ã®èšäºãèªã¿ãã«ãŒã«ã®åœ¢åŒãçè§£ãããšãæ å ±ã»ãã¥ãªãã£ã³ãã¥ããã£å šäœã®å©çã®ããã«å°éç¥èã䜿çšã§ããããã«ãªããŸãã
å¿ ã2åç®ã®ã¹ããªã³ãã«åå ããŠãã ãããåå¥ã«åå ããŠããŒã ãç·šæããäžç·ã«äžçãããå®å šã«ããŸãããïŒ
OSCDã€ãã·ã¢ããã®é£çµ¡å ïŒ
èè ïŒAnton Kutepovãå°éå®¶ãµãŒãã¹éšéããã³ããžãã£ããã¯ãããžãŒéçºã®ã¹ãã·ã£ãªã¹ãïŒPTãšãã¹ããŒãã»ãã¥ãªãã£ã»ã³ã¿ãŒïŒ