ื›ื™ืฆื“ ืžืขืจื›ื•ืช ื ื™ืชื•ื— ืชืขื‘ื•ืจื” ืžื–ื”ื•ืช ื˜ืงื˜ื™ืงื•ืช ื”ืืงืจื™ื ื‘ืืžืฆืขื•ืช MITER ATT&CK ื‘ืืžืฆืขื•ืช ื”ื“ื•ื’ืžื” ืฉืœ PT Network Attack Discovery

ื›ื™ืฆื“ ืžืขืจื›ื•ืช ื ื™ืชื•ื— ืชืขื‘ื•ืจื” ืžื–ื”ื•ืช ื˜ืงื˜ื™ืงื•ืช ื”ืืงืจื™ื ื‘ืืžืฆืขื•ืช MITER ATT&CK ื‘ืืžืฆืขื•ืช ื”ื“ื•ื’ืžื” ืฉืœ PT Network Attack Discovery

ืœืคื™ Verizon, ืจื•ื‘ (87%) ืฉืœ ืื™ืจื•ืขื™ ืื‘ื˜ื—ืช ื”ืžื™ื“ืข ืžืชืจื—ืฉื™ื ืชื•ืš ื“ืงื•ืช ืกืคื•ืจื•ืช, ื•ืœ-68% ืžื”ื—ื‘ืจื•ืช ืœื•ืงื— ื—ื•ื“ืฉื™ื ืœื’ืœื•ืช ืื•ืชื. ื–ื” ืžืื•ืฉืจ ืขืœ ื™ื“ื™ ืžื—ืงืจ ืฉืœ ืžื›ื•ืŸ ืคื•ื ืžื•ืŸ, ืœืคื™ื” ืœื•ืงื— ืœืจื•ื‘ ื”ืืจื’ื•ื ื™ื 206 ื™ืžื™ื ื‘ืžืžื•ืฆืข ื›ื“ื™ ืœื–ื”ื•ืช ืื™ืจื•ืข. ื‘ื”ืชื‘ืกืก ืขืœ ื”ื ื™ืกื™ื•ืŸ ืฉืœ ื”ื—ืงื™ืจื•ืช ืฉืœื ื•, ื”ืืงืจื™ื ื™ื›ื•ืœื™ื ืœืฉืœื•ื˜ ื‘ืชืฉืชื™ืช ืฉืœ ื—ื‘ืจื” ื‘ืžืฉืš ืฉื ื™ื ืžื‘ืœื™ ืœื”ืชื’ืœื•ืช. ื›ืš, ื‘ืื—ื“ ื”ืืจื’ื•ื ื™ื ืฉื‘ื”ื ื—ืงืจื• ื”ืžื•ืžื—ื™ื ืฉืœื ื• ืื™ืจื•ืข ืื‘ื˜ื—ืช ืžื™ื“ืข, ื”ืชื’ืœื” ื›ื™ ื”ืืงืจื™ื ืฉืœื˜ื• ืœื—ืœื•ื˜ื™ืŸ ื‘ื›ืœ ืชืฉืชื™ืช ื”ืืจื’ื•ืŸ ื•ื’ื ื‘ื• ืžื™ื“ืข ื—ืฉื•ื‘ ื‘ืื•ืคืŸ ืงื‘ื•ืข. ื‘ืžืฉืš ืฉืžื•ื ื” ืฉื ื™ื.

ื ื ื™ื— ืฉื›ื‘ืจ ืคื•ืขืœ SIEM ืฉืื•ืกืฃ ื™ื•ืžื ื™ื ื•ืžื ืชื— ืื™ืจื•ืขื™ื, ื•ืชื•ื›ื ืช ืื ื˜ื™ ื•ื™ืจื•ืก ืžื•ืชืงื ืช ื‘ืฆืžืชื™ ื”ืงืฆื”. ืขืœ ื›ืœ ืคื ื™ื, ืœื ื”ื›ืœ ื ื™ืชืŸ ืœื–ื™ื”ื•ื™ ื‘ืืžืฆืขื•ืช SIEM, ื‘ื“ื™ื•ืง ื›ืคื™ ืฉืื™ ืืคืฉืจ ืœื”ื˜ืžื™ืข ืžืขืจื›ื•ืช EDR ื‘ื›ืœ ื”ืจืฉืช, ืžื” ืฉืื•ืžืจ ืฉืœื ื ื™ืชืŸ ืœื”ื™ืžื ืข ืžื ืงื•ื“ื•ืช ืขื™ื•ื•ืจื•ืช. ืžืขืจื›ื•ืช ื ื™ืชื•ื— ืชืขื‘ื•ืจืช ืจืฉืช (NTA) ืขื•ื–ืจื•ืช ืœื”ืชืžื•ื“ื“ ืื™ืชืŸ. ืคืชืจื•ื ื•ืช ืืœื• ืžื–ื”ื™ื ืคืขื™ืœื•ืช ืชื•ืงืคื™ื ื‘ืฉืœื‘ื™ื ื”ืžื•ืงื“ืžื™ื ื‘ื™ื•ืชืจ ืฉืœ ื—ื“ื™ืจืช ื”ืจืฉืช, ื•ื›ืŸ ื‘ืžื”ืœืš ื ื™ืกื™ื•ื ื•ืช ืœื”ืฉื™ื’ ื“ืจื™ืกืช ืจื’ืœ ื•ืœืคืชื— ื”ืชืงืคื” ื‘ืชื•ืš ื”ืจืฉืช.

ื™ืฉื ื ืฉื ื™ ืกื•ื’ื™ื ืฉืœ NTAs: ื—ืœืงื ืขื•ื‘ื“ื™ื ืขื NetFlow, ืื—ืจื™ื ืžื ืชื—ื™ื ืชืขื‘ื•ืจื” ื’ื•ืœืžื™ืช. ื”ื™ืชืจื•ืŸ ืฉืœ ื”ืžืขืจื›ื•ืช ื”ืฉื ื™ื•ืช ื”ื•ื ืฉื”ืŸ ื™ื›ื•ืœื•ืช ืœืื—ืกืŸ ืจืฉื•ืžื•ืช ืชื ื•ืขื” ื’ื•ืœืžื™ื•ืช. ื”ื•ื“ื•ืช ืœื›ืš, ืžื•ืžื—ื” ืื‘ื˜ื—ืช ืžื™ื“ืข ื™ื›ื•ืœ ืœื•ื•ื“ื ืืช ื”ืฆืœื—ืช ื”ืชืงื™ืคื”, ืœืžืงื ืืช ื”ืื™ื•ื, ืœื”ื‘ื™ืŸ ื›ื™ืฆื“ ื”ืชืจื—ืฉื” ื”ืชืงื™ืคื” ื•ื›ื™ืฆื“ ืœืžื ื•ืข ืžืชืงืคื” ื“ื•ืžื” ื‘ืขืชื™ื“.

ืื ื• ื ืจืื” ื›ื™ืฆื“ ื‘ืืžืฆืขื•ืช NTA ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืจืื™ื•ืช ื™ืฉื™ืจื•ืช ืื• ืขืงื™ืคื•ืช ื›ื“ื™ ืœื–ื”ื•ืช ืืช ื›ืœ ื˜ืงื˜ื™ืงื•ืช ื”ื”ืชืงืคื” ื”ืžื•ื›ืจื•ืช ื”ืžืชื•ืืจื•ืช ื‘ืžืื’ืจ ื”ื™ื“ืข MITER ATT & CK. ื ื“ื‘ืจ ืขืœ ื›ืœ ืื—ืช ืž-12 ื”ื˜ืงื˜ื™ืงื•ืช, ื ื ืชื— ืืช ื”ื˜ื›ื ื™ืงื•ืช ืฉืžืชื’ืœื•ืช ืขืœ ื™ื“ื™ ืชื ื•ืขื”, ื•ื ื“ื’ื™ื ืืช ื–ื™ื”ื•ื™ืŸ ื‘ืืžืฆืขื•ืช ืžืขืจื›ืช ื”-NTA ืฉืœื ื•.

ืขืœ ื‘ืกื™ืก ื”ื™ื“ืข ืฉืœ ATT&CK

MITER ATT&CK ื”ื•ื ื‘ืกื™ืก ื™ื“ืข ืฆื™ื‘ื•ืจื™ ืฉืคื•ืชื— ื•ืžืชื•ื—ื–ืง ืขืœ ื™ื“ื™ MITER Corporation ื”ืžื‘ื•ืกืก ืขืœ ื ื™ืชื•ื— ืฉืœ APTs ืžื”ื—ื™ื™ื ื”ืืžื™ืชื™ื™ื. ื–ื•ื”ื™ ืžืขืจื›ืช ืžื•ื‘ื ื™ืช ืฉืœ ื˜ืงื˜ื™ืงื•ืช ื•ื˜ื›ื ื™ืงื•ืช ื”ืžืฉืžืฉื•ืช ืชื•ืงืคื™ื. ื–ื” ืžืืคืฉืจ ืœืื ืฉื™ ืื‘ื˜ื—ืช ืžื™ื“ืข ืžื›ืœ ื”ืขื•ืœื ืœื“ื‘ืจ ื‘ืื•ืชื” ืฉืคื”. ืžืื’ืจ ื”ื ืชื•ื ื™ื ืžืชืจื—ื‘ ื›ืœ ื”ื–ืžืŸ ื•ืžืชื•ื•ืกืฃ ื‘ื™ื“ืข ื—ื“ืฉ.

ืžืกื“ ื”ื ืชื•ื ื™ื ืžื–ื”ื” 12 ื˜ืงื˜ื™ืงื•ืช, ื”ืžื—ื•ืœืงื•ืช ืœืคื™ ืฉืœื‘ื™ื ืฉืœ ืžืชืงืคืช ืกื™ื™ื‘ืจ:

  • ื’ื™ืฉื” ืจืืฉื•ื ื™ืช;
  • ื‘ื™ืฆื•ืข;
  • ืงื•ื ืกื•ืœื™ื“ืฆื™ื” (ื”ืชืžื“ื”);
  • ื”ืกืœืžื” ืฉืœ ื–ื›ื•ื™ื•ืช ื™ืชืจ;
  • ืžื ื™ืขืช ื’ื™ืœื•ื™ (ื”ืชื—ืžืงื•ืช ืžื”ื’ื ื”);
  • ื”ืฉื’ืช ืื™ืฉื•ืจื™ื (ื’ื™ืฉื” ืœืื™ืฉื•ืจื™ื);
  • ื—ึฒืงึดื™ืจึธื”;
  • ืชื ื•ืขื” ื‘ืชื•ืš ื”ื”ื™ืงืฃ (ืชื ื•ืขื” ืœืจื•ื—ื‘);
  • ืื™ืกื•ืฃ ื ืชื•ื ื™ื (ืื™ืกื•ืฃ);
  • ืคื™ืงื•ื“ ื•ื‘ืงืจื”;
  • ื—ื™ืœื•ืฅ ื ืชื•ื ื™ื;
  • ืคึผึฐื’ึดื™ืขึธื”.

ืขื‘ื•ืจ ื›ืœ ื˜ืงื˜ื™ืงื”, ื‘ืกื™ืก ื”ื™ื“ืข ืฉืœ ATT&CK ืžืคืจื˜ ืจืฉื™ืžื” ืฉืœ ื˜ื›ื ื™ืงื•ืช ืฉืขื•ื–ืจื•ืช ืœืชื•ืงืคื™ื ืœื”ืฉื™ื’ ืืช ืžื˜ืจืชื ื‘ืฉืœื‘ ื”ื ื•ื›ื—ื™ ืฉืœ ื”ื”ืชืงืคื”. ืžื›ื™ื•ื•ืŸ ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืื•ืชื” ื˜ื›ื ื™ืงื” ื‘ืฉืœื‘ื™ื ืฉื•ื ื™ื, ื”ื™ื ื™ื›ื•ืœื” ืœื”ืชื™ื™ื—ืก ืœืžืกืคืจ ื˜ืงื˜ื™ืงื•ืช.

ืชื™ืื•ืจ ื›ืœ ื˜ื›ื ื™ืงื” ื›ื•ืœืœ:

  • ืžื–ื”ื”;
  • ืจืฉื™ืžื” ืฉืœ ื˜ืงื˜ื™ืงื•ืช ืฉื‘ื”ืŸ ื ืขืฉื” ืฉื™ืžื•ืฉ;
  • ื“ื•ื’ืžืื•ืช ืœืฉื™ืžื•ืฉ ืขืœ ื™ื“ื™ ืงื‘ื•ืฆื•ืช APT;
  • ืืžืฆืขื™ื ืœืฆืžืฆื•ื ื ื–ืงื™ื ืžื”ืฉื™ืžื•ืฉ ื‘ื•;
  • ื”ืžืœืฆื•ืช ืื™ืชื•ืจ.

ืžื•ืžื—ื™ ืื‘ื˜ื—ืช ืžื™ื“ืข ื™ื›ื•ืœื™ื ืœื”ืฉืชืžืฉ ื‘ื™ื“ืข ืžืžืกื“ ื”ื ืชื•ื ื™ื ื›ื“ื™ ืœื‘ื ื•ืช ืžื™ื“ืข ืขืœ ืฉื™ื˜ื•ืช ืชืงื™ืคื” ื ื•ื›ื—ื™ื•ืช, ื•ื‘ื”ืชื—ืฉื‘ ื‘ื›ืš ืœื‘ื ื•ืช ืžืขืจื›ืช ืื‘ื˜ื—ื” ื™ืขื™ืœื”. ื”ื”ื‘ื ื” ื›ื™ืฆื“ ืคื•ืขืœื•ืช ืงื‘ื•ืฆื•ืช APT ืืžื™ืชื™ื•ืช ื™ื›ื•ืœื” ื’ื ืœื”ืคื•ืš ืœืžืงื•ืจ ืœื”ืฉืขืจื•ืช ืœื—ื™ืคื•ืฉ ื™ื–ื•ื ืื—ืจ ืื™ื•ืžื™ื ื‘ืชื•ืš ืฆื™ื“ ืื™ื•ืžื™ื.

ืื•ื“ื•ืช ื’ื™ืœื•ื™ ืชืงื™ืคื•ืช ืจืฉืช PT

ื ื–ื”ื” ืฉื™ืžื•ืฉ ื‘ื˜ื›ื ื™ืงื•ืช ืžืžื˜ืจื™ืฆืช ATT&CK ื‘ืืžืฆืขื•ืช ื”ืžืขืจื›ืช ื’ื™ืœื•ื™ ื”ืชืงืคื•ืช ืจืฉืช PT โ€” ืžืขืจื›ืช Positive Technologies NTA, ืฉื ื•ืขื“ื” ืœื–ื”ื•ืช ื”ืชืงืคื•ืช ืขืœ ื”ื”ื™ืงืฃ ื•ื‘ืชื•ืš ื”ืจืฉืช. PT NAD ืžื›ืกื”, ื‘ื“ืจื’ื•ืช ืฉื•ื ื•ืช, ืืช ื›ืœ 12 ื”ื˜ืงื˜ื™ืงื•ืช ืฉืœ ืžื˜ืจื™ืฆืช MITER ATT&CK. ื”ื•ื ื”ื—ื–ืง ื‘ื™ื•ืชืจ ื‘ื–ื™ื”ื•ื™ ื˜ื›ื ื™ืงื•ืช ืœื’ื™ืฉื” ืจืืฉื•ื ื™ืช, ืชื ื•ืขื” ืฆื™ื“ื™ืช ื•ืคื™ืงื•ื“ ื•ื‘ืงืจื”. ื‘ื”ื, PT NAD ืžื›ืกื” ื™ื•ืชืจ ืžืžื—ืฆื™ืช ืžื”ื˜ื›ื ื™ืงื•ืช ื”ื™ื“ื•ืขื•ืช, ื•ืžื–ื”ื” ืืช ื”ื™ื™ืฉื•ื ืฉืœื”ืŸ ืขืœ ื™ื“ื™ ืกื™ืžื ื™ื ื™ืฉื™ืจื™ื ืื• ืขืงื™ืคื™ื.

ื”ืžืขืจื›ืช ืžื–ื”ื” ื”ืชืงืคื•ืช ื‘ืืžืฆืขื•ืช ื˜ื›ื ื™ืงื•ืช ATT&CK ื‘ืืžืฆืขื•ืช ื›ืœืœื™ ื–ื™ื”ื•ื™ ืฉื ื•ืฆืจื• ืขืœ ื™ื“ื™ ื”ืฆื•ื•ืช ืžืจื›ื– ืื‘ื˜ื—ื” ืžื•ืžื—ื” PT (PT ESC), ืœืžื™ื“ืช ืžื›ื•ื ื”, ืื™ื ื“ื™ืงื˜ื•ืจื™ื ืฉืœ ืคืฉืจื”, ื ื™ืชื•ื— ืขืžื•ืง ื•ื ื™ืชื•ื— ืจื˜ืจื•ืกืคืงื˜ื™ื‘ื™. ื ื™ืชื•ื— ืชื ื•ืขื” ื‘ื–ืžืŸ ืืžืช ื‘ืฉื™ืœื•ื‘ ืขื ืจื˜ืจื•ืกืคืงื˜ื™ื‘ื” ืžืืคืฉืจืช ืœื–ื”ื•ืช ืคืขื™ืœื•ืช ื–ื“ื•ื ื™ืช ื ืกืชืจืช ื ื•ื›ื—ื™ืช ื•ืœืขืงื•ื‘ ืื—ืจ ื•ืงื˜ื•ืจื™ ื”ืชืคืชื—ื•ืช ื•ื›ืจื•ื ื•ืœื•ื’ื™ื” ืฉืœ ื”ืชืงืคื•ืช.

ื›ืืŸ ืžื™ืคื•ื™ ืžืœื ืฉืœ PT NAD ืœืžื˜ืจื™ืฆืช MITER ATT&CK. ื”ืชืžื•ื ื” ื’ื“ื•ืœื”, ืื– ืื ื• ืžืฆื™ืขื™ื ืœืš ืœืฆืคื•ืช ื‘ื” ื‘ื—ืœื•ืŸ ื ืคืจื“.

ื’ื™ืฉื” ืจืืฉื•ื ื™ืช

ื›ื™ืฆื“ ืžืขืจื›ื•ืช ื ื™ืชื•ื— ืชืขื‘ื•ืจื” ืžื–ื”ื•ืช ื˜ืงื˜ื™ืงื•ืช ื”ืืงืจื™ื ื‘ืืžืฆืขื•ืช MITER ATT&CK ื‘ืืžืฆืขื•ืช ื”ื“ื•ื’ืžื” ืฉืœ PT Network Attack Discovery

ื˜ืงื˜ื™ืงื•ืช ื’ื™ืฉื” ืจืืฉื•ื ื™ื•ืช ื›ื•ืœืœื•ืช ื˜ื›ื ื™ืงื•ืช ืœื—ื“ื•ืจ ืœืจืฉืช ืฉืœ ื—ื‘ืจื”. ื”ืžื˜ืจื” ืฉืœ ื”ืชื•ืงืคื™ื ื‘ืฉืœื‘ ื–ื” ื”ื™ื ืœื”ืขื‘ื™ืจ ืงื•ื“ ื–ื“ื•ื ื™ ืœืžืขืจื›ืช ื”ืžื•ืชืงืคืช ื•ืœื”ื‘ื˜ื™ื— ืืคืฉืจื•ืช ืœื”ืžืฉืš ื‘ื™ืฆื•ืขื•.

ื ื™ืชื•ื— ืชื ื•ืขื” ืž-PT NAD ื—ื•ืฉืฃ ืฉื‘ืข ื˜ื›ื ื™ืงื•ืช ืœื”ืฉื’ืช ื’ื™ืฉื” ืจืืฉื•ื ื™ืช:

1. T1189: ืคืฉืจื” ื‘ื ืกื™ืขื”

ื˜ื›ื ื™ืงื” ืฉื‘ื” ื”ืงื•ืจื‘ืŸ ืคื•ืชื— ืืชืจ ืื™ื ื˜ืจื ื˜ ื”ืžืฉืžืฉ ืชื•ืงืคื™ื ื›ื“ื™ ืœื ืฆืœ ืืช ื“ืคื“ืคืŸ ื”ืื™ื ื˜ืจื ื˜ ื•ืœื”ืฉื™ื’ ืืกื™ืžื•ื ื™ ื’ื™ืฉื” ืœืืคืœื™ืงืฆื™ื•ืช.

ืžื” ืขื•ืฉื” PT NAD?: ืื ืชืขื‘ื•ืจืช ื”ืื™ื ื˜ืจื ื˜ ืื™ื ื” ืžื•ืฆืคื ืช, PT NAD ื‘ื•ื“ืง ืืช ื”ืชื•ื›ืŸ ืฉืœ ืชื’ื•ื‘ื•ืช ืฉืจืช HTTP. ืชื’ื•ื‘ื•ืช ืืœื• ืžื›ื™ืœื•ืช ื ื™ืฆื•ืœื™ื ื”ืžืืคืฉืจื™ื ืœืชื•ืงืคื™ื ืœื‘ืฆืข ืงื•ื“ ืฉืจื™ืจื•ืชื™ ื‘ืชื•ืš ื”ื“ืคื“ืคืŸ. PT NAD ืžื–ื”ื” ืื•ื˜ื•ืžื˜ื™ืช ื ื™ืฆื•ืœ ื›ื–ื” ื‘ืืžืฆืขื•ืช ื›ืœืœื™ ื–ื™ื”ื•ื™.

ื‘ื ื•ืกืฃ, PT NAD ืžื–ื”ื” ืืช ื”ืื™ื•ื ื‘ืฉืœื‘ ื”ืงื•ื“ื. ื›ืœืœื™ื ื•ืื™ื ื“ื™ืงื˜ื•ืจื™ื ืฉืœ ืคืฉืจื” ืžื•ืคืขืœื™ื ืื ื”ืžืฉืชืžืฉ ื‘ื™ืงืจ ื‘ืืชืจ ืฉื”ืคื ื” ืื•ืชื• ืœืืชืจ ืขื ืฉืœืœ ื ื™ืฆื•ืœื™ื.

2. T1190: ื ืฆืœ ื™ื™ืฉื•ื ื”ืคื•ื ื” ืœืฆื™ื‘ื•ืจ

ื ื™ืฆื•ืœ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืฉื™ืจื•ืชื™ื ื”ื ื’ื™ืฉื™ื ืžื”ืื™ื ื˜ืจื ื˜.

ืžื” ืขื•ืฉื” PT NAD?: ืžื‘ืฆืข ื‘ื“ื™ืงื” ืžืขืžื™ืงื” ืฉืœ ื”ืชื•ื›ืŸ ืฉืœ ืžื ื•ืช ืจืฉืช, ืžื–ื”ื” ืกื™ืžื ื™ื ืœืคืขื™ืœื•ืช ื—ืจื™ื’ื”. ื‘ืคืจื˜, ื™ืฉื ื ื›ืœืœื™ื ื”ืžืืคืฉืจื™ื ืœืš ืœื–ื”ื•ืช ื”ืชืงืคื•ืช ืขืœ ืžืขืจื›ื•ืช ื ื™ื”ื•ืœ ืชื•ื›ืŸ (CMS) ื’ื“ื•ืœื•ืช, ืžืžืฉืงื™ ืื™ื ื˜ืจื ื˜ ืฉืœ ืฆื™ื•ื“ ืจืฉืช ื•ื”ืชืงืคื•ืช ืขืœ ืฉืจืชื™ ื“ื•ืืจ ื•-FTP.

3. T1133: ืฉื™ืจื•ืชื™ื ืžืจื•ื—ืงื™ื ื—ื™ืฆื•ื ื™ื™ื

ืชื•ืงืคื™ื ืžืฉืชืžืฉื™ื ื‘ืฉื™ืจื•ืชื™ ื’ื™ืฉื” ืžืจื—ื•ืง ื›ื“ื™ ืœื”ืชื—ื‘ืจ ืœืžืฉืื‘ื™ ืจืฉืช ืคื ื™ืžื™ื™ื ืžื‘ื—ื•ืฅ.

ืžื” ืขื•ืฉื” PT NAD?: ืžื›ื™ื•ื•ืŸ ืฉื”ืžืขืจื›ืช ืžื–ื”ื” ืคืจื•ื˜ื•ืงื•ืœื™ื ืœื ืœืคื™ ืžืกืคืจื™ ื™ืฆื™ืื”, ืืœื ืœืคื™ ืชื•ื›ืŸ ื”ื—ื‘ื™ืœื•ืช, ืžืฉืชืžืฉื™ ื”ืžืขืจื›ืช ื™ื›ื•ืœื™ื ืœืกื ืŸ ืชืขื‘ื•ืจื” ื›ื“ื™ ืœืžืฆื•ื ืืช ื›ืœ ื”ืคืขืœื•ืช ืฉืœ ืคืจื•ื˜ื•ืงื•ืœื™ ื’ื™ืฉื” ืžืจื—ื•ืง ื•ืœื‘ื“ื•ืง ืืช ื”ืœื’ื™ื˜ื™ืžื™ื•ืช ืฉืœื”ื.

4. T1193: ืงื•ื‘ืฅ ืžืฆื•ืจืฃ ืœื—ื ื™ืช

ืื ื—ื ื• ืžื“ื‘ืจื™ื ืขืœ ื”ืฉืœื™ื—ื” ื”ื™ื“ื•ืขื” ืœืฉืžืฆื” ืฉืœ ืงื‘ืฆื™ ื“ื™ื•ื’ ืžืฆื•ืจืคื™ื.

ืžื” ืขื•ืฉื” PT NAD?: ืžื—ืœืฅ ืื•ื˜ื•ืžื˜ื™ืช ืงื‘ืฆื™ื ืžื”ืชื ื•ืขื” ื•ื‘ื•ื“ืง ืื•ืชื ืžื•ืœ ืื™ื ื“ื™ืงื˜ื•ืจื™ื ืฉืœ ืคืฉืจื”. ืงื‘ืฆื™ื ื”ื ื™ืชื ื™ื ืœื”ืคืขืœื” ื‘ืงื‘ืฆื™ื ืžืฆื•ืจืคื™ื ืžื–ื•ื”ื™ื ืขืœ ื™ื“ื™ ื›ืœืœื™ื ื”ืžื ืชื—ื™ื ืืช ืชื•ื›ืŸ ืชืขื‘ื•ืจืช ื”ื“ื•ืืจ. ื‘ืกื‘ื™ื‘ื” ืืจื’ื•ื ื™ืช, ื”ืฉืงืขื” ื›ื–ื• ื ื—ืฉื‘ืช ืœืื ื•ืžืœื™ืช.

5. T1192: ืงื™ืฉื•ืจ ืœื—ื ื™ืช

ืฉื™ืžื•ืฉ ื‘ืงื™ืฉื•ืจื™ ืคื™ืฉื™ื ื’. ื”ื˜ื›ื ื™ืงื” ื›ื•ืœืœืช ืชื•ืงืคื™ื ืฉืœื™ื—ืช ื“ื•ื"ืœ ื“ื™ื•ื’ ืขื ืงื™ืฉื•ืจ ืฉืœื•ื—ืฆื™ื ืขืœื™ื•, ืžื•ืจื™ื“ ืชื•ื›ื ื” ื–ื“ื•ื ื™ืช. ื›ื›ืœืœ, ื”ืงื™ืฉื•ืจ ืžืœื•ื•ื” ื‘ื˜ืงืกื˜ ืฉื ืขืจืš ื‘ื”ืชืื ืœื›ืœ ื›ืœืœื™ ื”ื”ื ื“ืกื” ื”ื—ื‘ืจืชื™ืช.

ืžื” ืขื•ืฉื” PT NAD?: ืžื–ื”ื” ืงื™ืฉื•ืจื™ ื“ื™ื•ื’ ื‘ืืžืฆืขื•ืช ืื™ื ื“ื™ืงื˜ื•ืจื™ื ืฉืœ ืคืฉืจื”. ืœื“ื•ื’ืžื”, ื‘ืžืžืฉืง PT NAD ืื ื• ืจื•ืื™ื ื”ืคืขืœื” ื‘ื” ื”ื™ื” ื—ื™ื‘ื•ืจ HTTP ื“ืจืš ืงื™ืฉื•ืจ ืฉื ื›ืœืœ ื‘ืจืฉื™ืžืช ื›ืชื•ื‘ื•ืช ื”ื“ื™ื•ื’ (phishing-urls).

ื›ื™ืฆื“ ืžืขืจื›ื•ืช ื ื™ืชื•ื— ืชืขื‘ื•ืจื” ืžื–ื”ื•ืช ื˜ืงื˜ื™ืงื•ืช ื”ืืงืจื™ื ื‘ืืžืฆืขื•ืช MITER ATT&CK ื‘ืืžืฆืขื•ืช ื”ื“ื•ื’ืžื” ืฉืœ PT Network Attack Discovery

ื—ื™ื‘ื•ืจ ื“ืจืš ืงื™ืฉื•ืจ ืžืจืฉื™ืžืช ื”ืื™ื ื“ื™ืงื˜ื•ืจื™ื ืฉืœ ื›ืชื•ื‘ื•ืช ื“ื™ื•ื’ ืžืชืคืฉืจื•ืช

6. T1199: ืžืขืจื›ืช ื™ื—ืกื™ื ืžื”ื™ืžื ื”

ื’ื™ืฉื” ืœืจืฉืช ืฉืœ ื”ื ืคื’ืข ื‘ืืžืฆืขื•ืช ืฆื“ื“ื™ื ืฉืœื™ืฉื™ื™ื ืขื™ืžื ื™ืฆืจ ื”ื ืคื’ืข ื™ื—ืกื™ ืืžื•ืŸ. ืชื•ืงืคื™ื ื™ื›ื•ืœื™ื ืœืคืจื•ืฅ ืืจื’ื•ืŸ ืžื”ื™ืžืŸ ื•ืœื”ืชื—ื‘ืจ ืœืจืฉืช ื”ื™ืขื“ ื‘ืืžืฆืขื•ืชื•. ืœืฉื ื›ืš, ื”ื ืžืฉืชืžืฉื™ื ื‘ื—ื™ื‘ื•ืจื™ VPN ืื• ืืžื•ืŸ ืชื—ื•ื, ืื•ืชื ื ื™ืชืŸ ืœื–ื”ื•ืช ื‘ืืžืฆืขื•ืช ื ื™ืชื•ื— ืชืขื‘ื•ืจื”.

ืžื” ืขื•ืฉื” PT NAD?: ืžื ืชื— ืคืจื•ื˜ื•ืงื•ืœื™ื ืฉืœ ื™ื™ืฉื•ืžื™ื ื•ืฉื•ืžืจ ืืช ื”ืฉื“ื•ืช ื”ืžื ื•ืชื—ื™ื ื‘ืžืกื“ ื”ื ืชื•ื ื™ื, ื›ืš ืฉืžื ืชื— ืื‘ื˜ื—ืช ืžื™ื“ืข ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืžืกื ื ื™ื ื›ื“ื™ ืœืžืฆื•ื ืืช ื›ืœ ื—ื™ื‘ื•ืจื™ ื”-VPN ื”ื—ืฉื•ื“ื™ื ืื• ื—ื™ื‘ื•ืจื™ื ื—ื•ืฆื™-ื“ื•ืžื™ื™ื ื™ื ื‘ืžืกื“ ื”ื ืชื•ื ื™ื.

7. T1078: ื—ืฉื‘ื•ื ื•ืช ื—ื•ืงื™ื™ื

ืฉื™ืžื•ืฉ ื‘ืื™ืฉื•ืจื™ื ืกื˜ื ื“ืจื˜ื™ื™ื, ืžืงื•ืžื™ื™ื ืื• ื“ื•ืžื™ื™ื ื™ื ืœื”ืจืฉืื” ื‘ืฉื™ืจื•ืชื™ื ื—ื™ืฆื•ื ื™ื™ื ื•ืคื ื™ืžื™ื™ื.

ืžื” ืขื•ืฉื” PT NAD?: ืžืื—ื–ืจ ืื•ื˜ื•ืžื˜ื™ืช ืื™ืฉื•ืจื™ื ืžืคืจื•ื˜ื•ืงื•ืœื™ HTTP, FTP, SMTP, POP3, IMAP, SMB, DCE/RPC, SOCKS5, LDAP, Kerberos. ื‘ืื•ืคืŸ ื›ืœืœื™, ืžื“ื•ื‘ืจ ื‘ื›ื ื™ืกื”, ืกื™ืกืžื” ื•ืกื™ืžืŸ ืœืื™ืžื•ืช ืžื•ืฆืœื—ืช. ืื ื ืขืฉื” ื‘ื”ื ืฉื™ืžื•ืฉ, ื”ื ืžื•ืฆื’ื™ื ื‘ื›ืจื˜ื™ืก ื”ืคื’ื™ืฉื” ื”ืžืชืื™ื.

ื‘ื™ืฆื•ืข

ื›ื™ืฆื“ ืžืขืจื›ื•ืช ื ื™ืชื•ื— ืชืขื‘ื•ืจื” ืžื–ื”ื•ืช ื˜ืงื˜ื™ืงื•ืช ื”ืืงืจื™ื ื‘ืืžืฆืขื•ืช MITER ATT&CK ื‘ืืžืฆืขื•ืช ื”ื“ื•ื’ืžื” ืฉืœ PT Network Attack Discovery
ื˜ืงื˜ื™ืงื•ืช ื‘ื™ืฆื•ืข ื›ื•ืœืœื•ืช ื˜ื›ื ื™ืงื•ืช ืฉื‘ื”ืŸ ืžืฉืชืžืฉื™ื ื”ืชื•ืงืคื™ื ื›ื“ื™ ืœื”ืคืขื™ืœ ืงื•ื“ ื‘ืžืขืจื›ื•ืช ืฉื ืคืจืฆื•ืช. ื”ืคืขืœืช ืงื•ื“ ื–ื“ื•ื ื™ ืขื•ื–ืจืช ืœืชื•ืงืคื™ื ืœื‘ืกืก ื ื•ื›ื—ื•ืช (ื˜ืงื˜ื™ืงืช ื”ืชืžื“ื”) ื•ืœื”ืจื—ื™ื‘ ืืช ื”ื’ื™ืฉื” ืœืžืขืจื›ื•ืช ืžืจื•ื—ืงื•ืช ื‘ืจืฉืช ืขืœ ื™ื“ื™ ืžืขื‘ืจ ื‘ืชื•ืš ื”ื”ื™ืงืฃ.

PT NAD ืžืืคืฉืจ ืœืš ืœื–ื”ื•ืช ืฉื™ืžื•ืฉ ื‘-14 ื˜ื›ื ื™ืงื•ืช ื”ืžืฉืžืฉื•ืช ืชื•ืงืคื™ื ืœื‘ื™ืฆื•ืข ืงื•ื“ ื–ื“ื•ื ื™.

1. T1191: CMSTP (ืžืชืงื™ืŸ ืคืจื•ืคื™ืœื™ ืžื ื”ืœ ื”ื—ื™ื‘ื•ืจื™ื ืฉืœ Microsoft)

ื˜ืงื˜ื™ืงื” ืฉื‘ื” ืชื•ืงืคื™ื ืžื›ื™ื ื™ื ืงื•ื‘ืฅ INF ืžื™ื•ื—ื“ ืœื”ืชืงื ื” ื–ื“ื•ื ื™ืช ืขื‘ื•ืจ ื›ืœื™ ื”ืฉื™ืจื•ืช ื”ืžื•ื‘ื ื” ืฉืœ Windows CMSTP.exe (Connection Manager Profile Installer). CMSTP.exe ืœื•ืงื— ืืช ื”ืงื•ื‘ืฅ ื›ืคืจืžื˜ืจ ื•ืžืชืงื™ืŸ ืืช ืคืจื•ืคื™ืœ ื”ืฉื™ืจื•ืช ืขื‘ื•ืจ ื”ื—ื™ื‘ื•ืจ ื”ืžืจื•ื—ืง. ื›ืชื•ืฆืื” ืžื›ืš, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘-CMSTP.exe ื›ื“ื™ ืœื˜ืขื•ืŸ ื•ืœื”ืคืขื™ืœ ืกืคืจื™ื•ืช ืงื™ืฉื•ืจื™ื ื“ื™ื ืžื™ื•ืช (*.dll) ืื• ืกืงืจื™ืคื˜ื™ื (*.sct) ืžืฉืจืชื™ื ืžืจื•ื—ืงื™ื.

ืžื” ืขื•ืฉื” PT NAD?: ืžื–ื”ื” ืื•ื˜ื•ืžื˜ื™ืช ื”ืขื‘ืจื” ืฉืœ ืกื•ื’ื™ื ืžื™ื•ื—ื“ื™ื ืฉืœ ืงื‘ืฆื™ INF ื‘ืชืขื‘ื•ืจืช HTTP. ื‘ื ื•ืกืฃ ืœื›ืš, ื”ื•ื ืžื–ื”ื” ืฉื™ื“ื•ืจ HTTP ืฉืœ ืกืงืจื™ืคื˜ื™ื ื–ื“ื•ื ื™ื™ื ื•ืกืคืจื™ื•ืช ืงื™ืฉื•ืจื™ื ื“ื™ื ืžื™ื™ื ืžืฉืจืช ืžืจื•ื—ืง.

2. T1059: ืžืžืฉืง ืฉื•ืจืช ืคืงื•ื“ื”

ืื™ื ื˜ืจืืงืฆื™ื” ืขื ืžืžืฉืง ืฉื•ืจืช ื”ืคืงื•ื“ื”. ื ื™ืชืŸ ืœื™ืฆื•ืจ ืื™ื ื˜ืจืืงืฆื™ื” ืขื ืžืžืฉืง ืฉื•ืจืช ื”ืคืงื•ื“ื” ื‘ืื•ืคืŸ ืžืงื•ืžื™ ืื• ืžืจื—ื•ืง, ืœืžืฉืœ ื‘ืืžืฆืขื•ืช ื›ืœื™ ืขื–ืจ ืœื’ื™ืฉื” ืžืจื—ื•ืง.

ืžื” ืขื•ืฉื” PT NAD?: ืžื–ื”ื” ืื•ื˜ื•ืžื˜ื™ืช ื ื•ื›ื—ื•ืช ืฉืœ ืงื•ื ื›ื™ื•ืช ื‘ื”ืชื‘ืกืก ืขืœ ืชื’ื•ื‘ื•ืช ืœืคืงื•ื“ื•ืช ื›ื“ื™ ืœื”ืคืขื™ืœ ื›ืœื™ ืฉื™ืจื•ืช ืฉื•ื ื™ื ืฉืœ ืฉื•ืจืช ื”ืคืงื•ื“ื”, ื›ื’ื•ืŸ ping, ifconfig.

3. T1175: ืžื•ื“ืœ ืื•ื‘ื™ื™ืงื˜ ืจื›ื™ื‘ ื•-COM ืžื‘ื•ื–ืจ

ืฉื™ืžื•ืฉ ื‘ื˜ื›ื ื•ืœื•ื’ื™ื•ืช COM ืื• DCOM ืœื‘ื™ืฆื•ืข ืงื•ื“ ื‘ืžืขืจื›ื•ืช ืžืงื•ืžื™ื•ืช ืื• ืžืจื•ื—ืงื•ืช ื‘ื–ืžืŸ ืžืขื‘ืจ ื‘ืจืฉืช.

ืžื” ืขื•ืฉื” PT NAD?: ืžื–ื”ื” ืงืจื™ืื•ืช DCOM ื—ืฉื•ื“ื•ืช ืฉืชื•ืงืคื™ื ืžืฉืชืžืฉื™ื ื‘ื”ืŸ ื‘ื“ืจืš ื›ืœืœ ื›ื“ื™ ืœื”ืคืขื™ืœ ืชื•ื›ื ื™ื•ืช.

4. T1203: ื ื™ืฆื•ืœ ืœื‘ื™ืฆื•ืข ืœืงื•ื—

ื ื™ืฆื•ืœ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืœื‘ื™ืฆื•ืข ืงื•ื“ ืฉืจื™ืจื•ืชื™ ื‘ืชื—ื ืช ืขื‘ื•ื“ื”. ื”ื ื™ืฆื•ืœ ื”ืฉื™ืžื•ืฉื™ ื‘ื™ื•ืชืจ ืขื‘ื•ืจ ืชื•ืงืคื™ื ื”ื•ื ืืœื• ื”ืžืืคืฉืจื™ื ืœื”ืคืขื™ืœ ืงื•ื“ ืขืœ ืžืขืจื›ืช ืžืจื•ื—ืงืช, ืžื›ื™ื•ื•ืŸ ืฉื”ื ื™ื›ื•ืœื™ื ืœืืคืฉืจ ืœืชื•ืงืคื™ื ืœืงื‘ืœ ื’ื™ืฉื” ืœืžืขืจื›ืช ื–ื•. ื ื™ืชืŸ ืœื™ื™ืฉื ืืช ื”ื˜ื›ื ื™ืงื” ื‘ืืžืฆืขื•ืช ื”ืฉื™ื˜ื•ืช ื”ื‘ืื•ืช: ื“ื™ื•ื•ืจ ื–ื“ื•ื ื™, ืืชืจ ืื™ื ื˜ืจื ื˜ ืขื ื ื™ืฆื•ืœ ื“ืคื“ืคืŸ ื•ื ื™ืฆื•ืœ ืžืจื—ื•ืง ืฉืœ ืคื’ื™ืขื•ื™ื•ืช ื™ื™ืฉื•ืžื™ื.

ืžื” ืขื•ืฉื” PT NAD?: ื‘ืขืช ื ื™ืชื•ื— ืชืขื‘ื•ืจืช ื“ื•ืืจ, PT NAD ื‘ื•ื“ืง ืืช ื ื•ื›ื—ื•ืชื ืฉืœ ืงื‘ืฆื™ ื”ืคืขืœื” ื‘ืงื‘ืฆื™ื ืžืฆื•ืจืคื™ื. ืžื—ืœืฅ ืื•ื˜ื•ืžื˜ื™ืช ืžืกืžื›ื™ื ืžืฉืจื“ื™ื™ื ืžืžื™ื™ืœื™ื ืฉืขืœื•ืœื™ื ืœื”ื›ื™ืœ ื ื™ืฆื•ืœ. ื ื™ืกื™ื•ื ื•ืช ืœื ืฆืœ ืคื’ื™ืขื•ื™ื•ืช ื’ืœื•ื™ื™ื ื‘ืชืขื‘ื•ืจื”, ืฉ-PT NAD ืžื–ื”ื” ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™.

5. T1170: mshta

ื”ืฉืชืžืฉ ื‘ื›ืœื™ ื”ืฉื™ืจื•ืช mshta.exe, ื”ืžืจื™ืฅ ื™ื™ืฉื•ืžื™ HTML ืฉืœ Microsoft (HTA) ืขื ืกื™ื•ืžืช .hta. ืžื›ื™ื•ื•ืŸ ืฉ-mshta ืžืขื‘ื“ ืงื‘ืฆื™ื ืขื•ืงืคื™ื ืืช ื”ื’ื“ืจื•ืช ื”ืื‘ื˜ื—ื” ืฉืœ ื”ื“ืคื“ืคืŸ, ืชื•ืงืคื™ื ื™ื›ื•ืœื™ื ืœื”ืฉืชืžืฉ ื‘-mshta.exe ื›ื“ื™ ืœื‘ืฆืข ืงื‘ืฆื™ HTA, JavaScript ืื• VBScript ื–ื“ื•ื ื™ื™ื.

ืžื” ืขื•ืฉื” PT NAD?: ืงื‘ืฆื™ .hta ืœื‘ื™ืฆื•ืข ื‘ืืžืฆืขื•ืช mshta ืžืฉื•ื“ืจื™ื ื’ื ื‘ืจืฉืช - ื ื™ืชืŸ ืœืจืื•ืช ื–ืืช ื‘ืชืขื‘ื•ืจื”. PT NAD ืžื–ื”ื” ื”ืขื‘ืจืช ืงื‘ืฆื™ื ื–ื“ื•ื ื™ื™ื ื›ืืœื” ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™. ื”ื•ื ืœื•ื›ื“ ืงื‘ืฆื™ื, ื•ื ื™ืชืŸ ืœืฆืคื•ืช ื‘ืžื™ื“ืข ืขืœื™ื”ื ื‘ื›ืจื˜ื™ืก ื”ืคื’ื™ืฉื”.

6. T1086: ืคื’ื– ื›ื•ื—

ืฉื™ืžื•ืฉ ื‘- PowerShell ื›ื“ื™ ืœืžืฆื•ื ืžื™ื“ืข ื•ืœื”ืคืขื™ืœ ืงื•ื“ ื–ื“ื•ื ื™.

ืžื” ืขื•ืฉื” PT NAD?: ื›ืืฉืจ PowerShell ืžืฉืžืฉ ืชื•ืงืคื™ื ืžืจื•ื—ืงื™ื, PT NAD ืžื–ื”ื” ื–ืืช ื‘ืืžืฆืขื•ืช ื›ืœืœื™ื. ื”ื•ื ืžื–ื”ื” ืžื™ืœื•ืช ืžืคืชื— ื‘ืฉืคืช PowerShell ื”ืžืฉืžืฉื•ืช ืœืจื•ื‘ ื‘ืกืงืจื™ืคื˜ื™ื ื–ื“ื•ื ื™ื™ื ื•ืฉื™ื“ื•ืจ ืฉืœ ืกืงืจื™ืคื˜ื™ื ืฉืœ PowerShell ืขืœ ืคื ื™ ืคืจื•ื˜ื•ืงื•ืœ SMB.

7. T1053: ืžืฉื™ืžื” ืžืชื•ื–ืžื ืช
ืฉื™ืžื•ืฉ ื‘-Windows Task Scheduler ื•ื›ืœื™ ืฉื™ืจื•ืช ืื—ืจื™ื ื›ื“ื™ ืœื”ืคืขื™ืœ ืื•ื˜ื•ืžื˜ื™ืช ืชื•ื›ื ื™ื•ืช ืื• ืกืงืจื™ืคื˜ื™ื ื‘ื–ืžื ื™ื ืกืคืฆื™ืคื™ื™ื.

ืžื” ืขื•ืฉื” PT NAD?: ืชื•ืงืคื™ื ื™ื•ืฆืจื™ื ืžืฉื™ืžื•ืช ื›ืืœื”, ื‘ื“ืจืš ื›ืœืœ ืžืจื—ื•ืง, ื›ืœื•ืžืจ ื”ืคืขืœื•ืช ื›ืืœื” ื’ืœื•ื™ื•ืช ื‘ืชื ื•ืขื”. PT NAD ืžื–ื”ื” ืื•ื˜ื•ืžื˜ื™ืช ืคืขื•ืœื•ืช ื™ืฆื™ืจืช ื•ืฉื™ื ื•ื™ ืžืฉื™ืžื•ืช ื—ืฉื•ื“ื•ืช ื‘ืืžืฆืขื•ืช ืžืžืฉืงื™ ATSVC ื•-ITaskSchedulerService RPC.

8. T1064: ืกืงืจื™ืคื˜ื™ื

ื‘ื™ืฆื•ืข ืกืงืจื™ืคื˜ื™ื ืœืื•ื˜ื•ืžืฆื™ื” ืฉืœ ืคืขื•ืœื•ืช ืฉื•ื ื•ืช ืฉืœ ืชื•ืงืคื™ื.

ืžื” ืขื•ืฉื” PT NAD?: ืžื–ื”ื” ืฉื™ื“ื•ืจ ืฉืœ ืกืงืจื™ืคื˜ื™ื ื‘ืจืฉืช, ื›ืœื•ืžืจ ืขื•ื“ ืœืคื ื™ ื”ืฉืงืชื. ื”ื•ื ืžื–ื”ื” ืชื•ื›ืŸ ืกืงืจื™ืคื˜ ื‘ืชืขื‘ื•ืจื” ื’ื•ืœืžื™ืช ื•ืžื–ื”ื” ืฉื™ื“ื•ืจ ืจืฉืช ืฉืœ ืงื‘ืฆื™ื ืขื ื”ืจื—ื‘ื•ืช ื”ืžืชืื™ืžื•ืช ืœืฉืคื•ืช ืกืงืจื™ืคื˜ ืคื•ืคื•ืœืจื™ื•ืช.

9. T1035: ื‘ื™ืฆื•ืข ืฉื™ืจื•ืช

ื”ืคืขืœ ืงื•ื‘ืฅ ื”ืคืขืœื”, ื”ื•ืจืื•ืช ืžืžืฉืง ืฉื•ืจืช ืคืงื•ื“ื” ืื• ืกืงืจื™ืคื˜ ืขืœ ื™ื“ื™ ืื™ื ื˜ืจืืงืฆื™ื” ืขื ืฉื™ืจื•ืชื™ Windows, ื›ื’ื•ืŸ Service Control Manager (SCM).

ืžื” ืขื•ืฉื” PT NAD?: ื‘ื•ื“ืง ืชืขื‘ื•ืจืช SMB ื•ืžื–ื”ื” ื’ื™ืฉื” ืœ-SCM ืขื ื›ืœืœื™ื ืœื™ืฆื™ืจื”, ืฉื™ื ื•ื™ ื•ื”ืชื—ืœืช ืฉื™ืจื•ืช.

ื ื™ืชืŸ ืœื™ื™ืฉื ืืช ื˜ื›ื ื™ืงืช ื”ืคืขืœืช ื”ืฉื™ืจื•ืช ื‘ืืžืฆืขื•ืช ื›ืœื™ ื”ืฉื™ืจื•ืช ืœื‘ื™ืฆื•ืข ืคืงื•ื“ื•ืช ืžืจื—ื•ืง PSExec. PT NAD ืžื ืชื— ืืช ืคืจื•ื˜ื•ืงื•ืœ SMB ื•ืžื–ื”ื” ืืช ื”ืฉื™ืžื•ืฉ ื‘-PSExec ื›ืืฉืจ ื”ื•ื ืžืฉืชืžืฉ ื‘ืงื•ื‘ืฅ PSEXESVC.exe ืื• ื‘ืฉื ื”ืฉื™ืจื•ืช ื”ืกื˜ื ื“ืจื˜ื™ PSEXECSVC ื›ื“ื™ ืœื”ืคืขื™ืœ ืงื•ื“ ื‘ืžื—ืฉื‘ ืžืจื•ื—ืง. ื”ืžืฉืชืžืฉ ืฆืจื™ืš ืœื‘ื“ื•ืง ืืช ืจืฉื™ืžืช ื”ืคืงื•ื“ื•ืช ื”ืžื‘ื•ืฆืขื•ืช ื•ืืช ื”ืœื’ื™ื˜ื™ืžื™ื•ืช ืฉืœ ื‘ื™ืฆื•ืข ืคืงื•ื“ื•ืช ืžืจื—ื•ืง ืžื”ืžืืจื—.

ื›ืจื˜ื™ืก ื”ื”ืชืงืคื” ื‘-PT NAD ืžืฆื™ื’ ื ืชื•ื ื™ื ืขืœ ื”ื˜ืงื˜ื™ืงื•ืช ื•ื”ื˜ื›ื ื™ืงื•ืช ื”ืžืฉืžืฉื•ืช ืœืคื™ ืžื˜ืจื™ืฆืช ATT&CK ื›ืš ืฉื”ืžืฉืชืžืฉ ื™ื›ื•ืœ ืœื”ื‘ื™ืŸ ื‘ืื™ื–ื” ืฉืœื‘ ืฉืœ ื”ื”ืชืงืคื” ื ืžืฆืื™ื ื”ืชื•ืงืคื™ื, ืœืื™ืœื• ืžื˜ืจื•ืช ื”ื ืจื•ื“ืคื™ื, ื•ืื™ืœื• ืืžืฆืขื™ ืคื™ืฆื•ื™ ืœื ืงื•ื˜.

ื›ื™ืฆื“ ืžืขืจื›ื•ืช ื ื™ืชื•ื— ืชืขื‘ื•ืจื” ืžื–ื”ื•ืช ื˜ืงื˜ื™ืงื•ืช ื”ืืงืจื™ื ื‘ืืžืฆืขื•ืช MITER ATT&CK ื‘ืืžืฆืขื•ืช ื”ื“ื•ื’ืžื” ืฉืœ PT Network Attack Discovery

ื”ื›ืœืœ ืœื’ื‘ื™ ื”ืฉื™ืžื•ืฉ ื‘ื›ืœื™ ื”ืฉื™ืจื•ืช PSExec ืžื•ืคืขืœ, ืžื” ืฉืขืฉื•ื™ ืœื”ืฆื‘ื™ืข ืขืœ ื ื™ืกื™ื•ืŸ ืœื‘ืฆืข ืคืงื•ื“ื•ืช ื‘ืžื—ืฉื‘ ืžืจื•ื—ืง

10. T1072: ืชื•ื›ื ืช ืฆื“ ืฉืœื™ืฉื™

ื˜ื›ื ื™ืงื” ืฉื‘ื” ืชื•ืงืคื™ื ืžืงื‘ืœื™ื ื’ื™ืฉื” ืœืชื•ื›ื ืช ื ื™ื”ื•ืœ ืžืจื—ื•ืง ืื• ืœืžืขืจื›ืช ืคืจื™ืกืช ืชื•ื›ื ื” ืืจื’ื•ื ื™ืช ื•ืžืฉืชืžืฉื™ื ื‘ื” ื›ื“ื™ ืœื”ืคืขื™ืœ ืงื•ื“ ื–ื“ื•ื ื™. ื“ื•ื’ืžืื•ืช ืœืชื•ื›ื ื•ืช ื›ืืœื”: SCCM, VNC, TeamViewer, HBSS, Altiris.
ืื’ื‘, ื”ื˜ื›ื ื™ืงื” ืจืœื•ื•ื ื˜ื™ืช ื‘ืžื™ื•ื—ื“ ื‘ืงืฉืจ ืขื ื”ืžืขื‘ืจ ื”ืžืืกื™ื‘ื™ ืœืขื‘ื•ื“ื” ืžืจื—ื•ืง, ื•ื›ืชื•ืฆืื” ืžื›ืš, ื—ื™ื‘ื•ืจ ืฉืœ ืžื›ืฉื™ืจื™ื ื‘ื™ืชื™ื™ื ืœื ืžื•ื’ื ื™ื ืจื‘ื™ื ื“ืจืš ืขืจื•ืฆื™ ื’ื™ืฉื” ืžืจื—ื•ืง ืžืคื•ืงืคืงื™ื.

ืžื” ืขื•ืฉื” PT NAD?: ืžื–ื”ื” ืื•ื˜ื•ืžื˜ื™ืช ืืช ื”ืคืขื•ืœื” ืฉืœ ืชื•ื›ื ื” ื›ื–ื• ื‘ืจืฉืช. ืœื“ื•ื’ืžื”, ื”ื›ืœืœื™ื ืžื•ืคืขืœื™ื ืขืœ ื™ื“ื™ ื—ื™ื‘ื•ืจื™ื ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœ VNC ื•ืคืขื™ืœื•ืชื• ืฉืœ ื”-EvilVNC Trojan, ืฉืžืชืงื™ืŸ ื‘ืกืชืจ ืฉืจืช VNC ืขืœ ื”ืžืืจื— ืฉืœ ื”ืงื•ืจื‘ืŸ ื•ืžืฉื™ืง ืื•ืชื• ืื•ื˜ื•ืžื˜ื™ืช. ื›ืžื• ื›ืŸ, PT NAD ืžื–ื”ื” ืื•ื˜ื•ืžื˜ื™ืช ืืช ืคืจื•ื˜ื•ืงื•ืœ TeamViewer, ื–ื” ืขื•ื–ืจ ืœืื ืœื™ืกื˜, ื‘ืืžืฆืขื•ืช ืžืกื ืŸ, ืœืžืฆื•ื ืืช ื›ืœ ื”ืคืขืœื•ืช ื›ืืœื” ื•ืœื‘ื“ื•ืง ืืช ื”ืœื’ื™ื˜ื™ืžื™ื•ืช ืฉืœื”ืŸ.

11. T1204: ื‘ื™ืฆื•ืข ืžืฉืชืžืฉ

ื˜ื›ื ื™ืงื” ืฉื‘ื” ื”ืžืฉืชืžืฉ ืžืจื™ืฅ ืงื‘ืฆื™ื ืฉื™ื›ื•ืœื™ื ืœื”ื•ื‘ื™ืœ ืœื‘ื™ืฆื•ืข ืงื•ื“. ื–ื” ื™ื›ื•ืœ ืœื”ื™ื•ืช, ืœืžืฉืœ, ืื ื”ื•ื ืคื•ืชื— ืงื•ื‘ืฅ ื”ืคืขืœื” ืื• ืžืจื™ืฅ ืžืกืžืš ืื•ืคื™ืก ืขื ืžืืงืจื•.

ืžื” ืขื•ืฉื” PT NAD?: ืจื•ืื” ืงื‘ืฆื™ื ื›ืืœื” ื‘ืฉืœื‘ ื”ื”ืขื‘ืจื”, ืœืคื ื™ ืฉื”ื ืžื•ืฉืงื™ื. ืžื™ื“ืข ืขืœื™ื”ื ื ื™ืชืŸ ืœืœืžื•ื“ ื‘ื›ืจื˜ื™ืก ื”ืžืคื’ืฉื™ื ืฉื‘ื”ื ื”ื ืฉื•ื“ืจื•.

12. T1047: ืžื›ืฉื•ืจ ื ื™ื”ื•ืœ Windows

ืฉื™ืžื•ืฉ ื‘ื›ืœื™ WMI, ื”ืžืกืคืง ื’ื™ืฉื” ืžืงื•ืžื™ืช ื•ืžืจื•ื—ืงืช ืœืจื›ื™ื‘ื™ ืžืขืจื›ืช Windows. ื‘ืืžืฆืขื•ืช WMI, ื”ืชื•ืงืคื™ื ื™ื›ื•ืœื™ื ืœื™ืฆื•ืจ ืื™ื ื˜ืจืืงืฆื™ื” ืขื ืžืขืจื›ื•ืช ืžืงื•ืžื™ื•ืช ื•ืžืจื•ื—ืงื•ืช ื•ืœื‘ืฆืข ืžื’ื•ื•ืŸ ืžืฉื™ืžื•ืช, ื›ื’ื•ืŸ ืื™ืกื•ืฃ ืžื™ื“ืข ืœืžื˜ืจื•ืช ืกื™ื•ืจ ื•ื”ืคืขืœืช ืชื”ืœื™ื›ื™ื ืžืจื—ื•ืง ืชื•ืš ื›ื“ื™ ืชื ื•ืขื” ืœืจื•ื—ื‘.

ืžื” ืขื•ืฉื” PT NAD?: ืžื›ื™ื•ื•ืŸ ืฉืื™ื ื˜ืจืืงืฆื™ื•ืช ืขื ืžืขืจื›ื•ืช ืžืจื•ื—ืงื•ืช ื‘ืืžืฆืขื•ืช WMI ื’ืœื•ื™ื•ืช ื‘ืชืขื‘ื•ืจื”, PT NAD ืžื–ื”ื” ืื•ื˜ื•ืžื˜ื™ืช ื‘ืงืฉื•ืช ืจืฉืช ืœื™ืฆื™ืจืช ื”ืคืขืœื•ืช WMI ื•ื‘ื•ื“ืง ืืช ื”ืชืขื‘ื•ืจื” ืขื‘ื•ืจ ืกืงืจื™ืคื˜ื™ื ื”ืžืฉืชืžืฉื™ื ื‘-WMI.

13. T1028: ื ื™ื”ื•ืœ ืžืจื—ื•ืง ืฉืœ Windows

ืฉื™ืžื•ืฉ ื‘ืฉื™ืจื•ืช ื•ืคืจื•ื˜ื•ืงื•ืœ ืฉืœ Windows ื”ืžืืคืฉืจื™ื ืœืžืฉืชืžืฉ ืื™ื ื˜ืจืืงืฆื™ื” ืขื ืžืขืจื›ื•ืช ืžืจื•ื—ืงื•ืช.

ืžื” ืขื•ืฉื” PT NAD?: ืจื•ืื” ื—ื™ื‘ื•ืจื™ ืจืฉืช ืฉื ื•ืฆืจื• ื‘ืืžืฆืขื•ืช ื ื™ื”ื•ืœ ืžืจื—ื•ืง ืฉืœ Windows. ื”ืคืขืœื•ืช ื›ืืœื” ืžื–ื•ื”ื•ืช ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™ ืขืœ ื™ื“ื™ ื”ื›ืœืœื™ื.

14. T1220: ืขื™ื‘ื•ื“ ืกืงืจื™ืคื˜ XSL (ืฉืคืช ื’ื™ืœื™ื•ืŸ ืกื’ื ื•ื ื•ืช ื”ืจื—ื‘ื”).

ืฉืคืช ืกื™ืžื•ืŸ ื‘ืกื’ื ื•ืŸ XSL ืžืฉืžืฉืช ืœืชื™ืื•ืจ ื”ืขื™ื‘ื•ื“ ื•ื”ื”ื“ืžื™ื” ืฉืœ ื ืชื•ื ื™ื ื‘ืงื•ื‘ืฆื™ XML. ื›ื“ื™ ืœืชืžื•ืš ื‘ืคืขื•ืœื•ืช ืžื•ืจื›ื‘ื•ืช, ืชืงืŸ XSL ื›ื•ืœืœ ืชืžื™ื›ื” ื‘ืกืงืจื™ืคื˜ื™ื ืžืฉื•ื‘ืฆื™ื ื‘ืฉืคื•ืช ืฉื•ื ื•ืช. ืฉืคื•ืช ืืœื• ืžืืคืฉืจื•ืช ื‘ื™ืฆื•ืข ืฉืœ ืงื•ื“ ืฉืจื™ืจื•ืชื™, ืžื” ืฉืžื•ื‘ื™ืœ ืœืขืงื™ืคื” ืฉืœ ืžื“ื™ื ื™ื•ืช ืื‘ื˜ื—ื” ื”ืžื‘ื•ืกืกืช ืขืœ ืจืฉื™ืžื•ืช ืœื‘ื ื•ืช.

ืžื” ืขื•ืฉื” PT NAD?: ืžื–ื”ื” ื”ืขื‘ืจื” ืฉืœ ืงื‘ืฆื™ื ื›ืืœื” ื“ืจืš ื”ืจืฉืช, ื›ืœื•ืžืจ ืขื•ื“ ืœืคื ื™ ื”ืฉืงืชื. ื–ื” ืžื–ื”ื” ืื•ื˜ื•ืžื˜ื™ืช ืงื‘ืฆื™ XSL ื”ืžื•ืขื‘ืจื™ื ื‘ืจืฉืช ื•ืงื‘ืฆื™ื ืขื ืกื™ืžื•ืŸ XSL ื—ืจื™ื’.

ื‘ื—ื•ืžืจื™ื ื”ื‘ืื™ื, ื ื‘ื—ืŸ ื›ื™ืฆื“ ืžืขืจื›ืช PT Network Attack Discovery NTA ืžื•ืฆืืช ื˜ืงื˜ื™ืงื•ืช ื•ื˜ื›ื ื™ืงื•ืช ืชื•ืงืคื™ื ืื—ืจื•ืช ื‘ื”ืชืื ืœ-MITER ATT&CK. ื”ืžืฉืš ืœืขืงื•ื‘!

ืžื—ื‘ืจื™ื:

  • ืื ื˜ื•ืŸ ืงื•ื˜ืคื•ื‘, ืžื•ืžื—ื” ื‘ืžืจื›ื– ื”ืื‘ื˜ื—ื” PT Expert, Positive Technologies
  • ื ื˜ืœื™ื” ืงื–ื ืงื•ื‘ื”, ืžืฉื•ื•ืงืช ืžื•ืฆืจื™ื ื‘ื—ื‘ืจืช Positive Technologies

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”