ืžื“ืจื™ืš ืœื ื™ืชื•ื— ืื™ื•ืžื™ื ืฉืœ Sysmon, ื—ืœืง 1

ืžื“ืจื™ืš ืœื ื™ืชื•ื— ืื™ื•ืžื™ื ืฉืœ Sysmon, ื—ืœืง 1

ืžืืžืจ ื–ื” ื”ื•ื ื”ื—ืœืง ื”ืจืืฉื•ืŸ ืฉืœ ืกื“ืจื” ืขืœ ื ื™ืชื•ื— ืื™ื•ืžื™ Sysmon. ื›ืœ ืฉืืจ ื—ืœืงื™ ื”ืกื“ืจื”:

ื—ืœืง 1: ืžื‘ื•ื ืœื ื™ืชื•ื— ื™ื•ืžืŸ Sysmon (ืื ื—ื ื• ื›ืืŸ)
ื—ืœืง 2: ืฉื™ืžื•ืฉ ื‘ื ืชื•ื ื™ ืื™ืจื•ืขื™ Sysmon ืœื–ื™ื”ื•ื™ ืื™ื•ืžื™ื
ื—ืœืง 3. ื ื™ืชื•ื— ืžืขืžื™ืง ืฉืœ ืื™ื•ืžื™ Sysmon ื‘ืืžืฆืขื•ืช ื’ืจืคื™ื

ืื ืืชื” ืขื•ื‘ื“ ื‘ืื‘ื˜ื—ืช ืžื™ื“ืข, ื›ื ืจืื” ืฉืœืขืชื™ื ืงืจื•ื‘ื•ืช ืืชื” ืฆืจื™ืš ืœื”ื‘ื™ืŸ ื”ืชืงืคื•ืช ืžืชืžืฉื›ื•ืช. ืื ื›ื‘ืจ ื™ืฉ ืœืš ืขื™ืŸ ืžืื•ืžื ืช, ืืชื” ื™ื›ื•ืœ ืœื—ืคืฉ ืคืขื™ืœื•ืช ืœื ืกื˜ื ื“ืจื˜ื™ืช ื‘ื™ื•ืžื ื™ื ื”"ื’ื•ืœืžื™ื™ื" ื”ืœื ืžืขื•ื‘ื“ื™ื - ืœืžืฉืœ, ืกืงืจื™ืคื˜ PowerShell ืคื•ืขืœ ืขื ื”ืคืงื•ื“ื” DownloadString ืื• ืกืงืจื™ืคื˜ VBS ื”ืžืชื—ื–ื” ืœืงื•ื‘ืฅ Word - ืคืฉื•ื˜ ื’ืœื™ืœื” ื‘ื™ืŸ ื”ืคืขื™ืœื•ืช ื”ืื—ืจื•ื ื” ื‘ื™ื•ืžืŸ ื”ืื™ืจื•ืขื™ื ืฉืœ Windows. ืื‘ืœ ื–ื” ื›ืื‘ ืจืืฉ ืžืžืฉ ื’ื“ื•ืœ. ืœืžืจื‘ื” ื”ืžื–ืœ, ืžื™ืงืจื•ืกื•ืคื˜ ื™ืฆืจื” ืืช Sysmon, ืžื” ืฉืžืงืœ ื‘ื”ืจื‘ื” ืขืœ ื ื™ืชื•ื— ื”ืชืงืคื•ืช.

ืจื•ืฆื” ืœื”ื‘ื™ืŸ ืืช ื”ืจืขื™ื•ื ื•ืช ื”ื‘ืกื™ืกื™ื™ื ืžืื—ื•ืจื™ ื”ืื™ื•ืžื™ื ื”ืžื•ืฆื’ื™ื ื‘ื™ื•ืžืŸ Sysmon? ื”ื•ืจื“ ืืช ื”ืžื“ืจื™ืš ืฉืœื ื• ืื™ืจื•ืขื™ WMI ื›ืืžืฆืขื™ ืจื™ื’ื•ืœ ื•ืืชื” ืžื‘ื™ืŸ ืื™ืš ืžืงื•ืจื‘ื™ื ื™ื›ื•ืœื™ื ืœืฆืคื•ืช ื‘ื—ืฉืื™ ืขืœ ืขื•ื‘ื“ื™ื ืื—ืจื™ื. ื”ื‘ืขื™ื” ื”ืขื™ืงืจื™ืช ื‘ืขื‘ื•ื“ื” ืขื ื™ื•ืžืŸ ื”ืื™ืจื•ืขื™ื ืฉืœ Windows ื”ื™ื ื”ื™ืขื“ืจ ืžื™ื“ืข ืขืœ ืชื”ืœื™ื›ื™ ืื‘, ื›ืœื•ืžืจ. ืื™ ืืคืฉืจ ืœื”ื‘ื™ืŸ ืžืžื ื• ืืช ื”ื™ืจืจื›ื™ื™ืช ื”ืชื”ืœื™ื›ื™ื. ืขืจื›ื™ ื™ื•ืžืŸ Sysmon, ืœืขื•ืžืช ื–ืืช, ืžื›ื™ืœื™ื ืืช ืžื–ื”ื” ืชื”ืœื™ืš ื”ืื‘, ืฉืžื• ื•ืฉื•ืจืช ื”ืคืงื•ื“ื” ืฉื™ืฉ ืœื”ืคืขื™ืœ. ืชื•ื“ื” ืœืš, ืžื™ืงืจื•ืกื•ืคื˜.

ื‘ื—ืœืง ื”ืจืืฉื•ืŸ ืฉืœ ื”ืกื“ืจื” ืฉืœื ื•, ื ืจืื” ืžื” ืืชื” ื™ื›ื•ืœ ืœืขืฉื•ืช ืขื ืžื™ื“ืข ื‘ืกื™ืกื™ ืž-Sysmon. ื‘ื—ืœืง XNUMX, ื ื ืฆืœ ืืช ืžืœื•ื ื”ืžื™ื“ืข ืขืœ ืชื”ืœื™ืš ื”ืื‘ ื›ื“ื™ ืœื™ืฆื•ืจ ืžื‘ื ื™ ืฆื™ื•ืช ืžื•ืจื›ื‘ื™ื ื™ื•ืชืจ ื”ื™ื“ื•ืขื™ื ื›ื’ืจืคื™ ืื™ื•ืžื™ื. ื‘ื—ืœืง ื”ืฉืœื™ืฉื™, ื ืกืชื›ืœ ืขืœ ืืœื’ื•ืจื™ืชื ืคืฉื•ื˜ ืฉืกื•ืจืง ื’ืจืฃ ืื™ื•ืžื™ื ื›ื“ื™ ืœื—ืคืฉ ืคืขื™ืœื•ืช ื—ืจื™ื’ื” ืขืœ ื™ื“ื™ ื ื™ืชื•ื— ื”"ืžืฉืงืœ" ืฉืœ ื”ื’ืจืฃ. ื•ื‘ืกื•ืคื• ืฉืœ ื“ื‘ืจ, ืชืชื•ื’ืžืœ ื‘ืฉื™ื˜ืช ื–ื™ื”ื•ื™ ืื™ื•ืžื™ื ื”ืกืชื‘ืจื•ืชื™ืช ืžืกื•ื“ืจืช (ื•ืžื•ื‘ื ืช).

ื—ืœืง 1: ืžื‘ื•ื ืœื ื™ืชื•ื— ื™ื•ืžืŸ Sysmon

ืžื” ื™ื›ื•ืœ ืœืขื–ื•ืจ ืœืš ืœื”ื‘ื™ืŸ ืืช ื”ืžื•ืจื›ื‘ื•ืช ืฉืœ ื™ื•ืžืŸ ื”ืื™ืจื•ืขื™ื? ื‘ืกื•ืคื• ืฉืœ ื“ื‘ืจ - SIEM. ื–ื” ืžื ืจืžืœ ืื™ืจื•ืขื™ื ื•ืžืคืฉื˜ ืืช ื”ื ื™ืชื•ื— ืฉืœืื—ืจ ืžื›ืŸ. ืื‘ืœ ืื ื—ื ื• ืœื ืฆืจื™ื›ื™ื ืœืœื›ืช ื›ืœ ื›ืš ืจื—ื•ืง, ืœืคื—ื•ืช ืœื ื‘ื”ืชื—ืœื”. ื‘ื”ืชื—ืœื”, ื›ื“ื™ ืœื”ื‘ื™ืŸ ืืช ื”ืขืงืจื•ื ื•ืช ืฉืœ SIEM, ื–ื” ื™ืกืคื™ืง ืœื ืกื•ืช ืืช ื›ืœื™ ื”ืฉื™ืจื•ืช ื”ื—ื™ื ืžื™ ื”ื ืคืœื Sysmon. ื•ืงืœ ืœื”ืคืชื™ืข ืœืขื‘ื•ื“ ืื™ืชื”. ืชืžืฉื™ืš ื›ืš, ืžื™ืงืจื•ืกื•ืคื˜!

ืื™ืœื• ืชื›ื•ื ื•ืช ื™ืฉ ืœ-Sysmon?

ื‘ืงื™ืฆื•ืจ - ืžื™ื“ืข ืฉื™ืžื•ืฉื™ ื•ืงืจื™ื ืขืœ ื”ืชื”ืœื™ื›ื™ื (ืจืื• ืชืžื•ื ื•ืช ืœืžื˜ื”). ืชืžืฆื ื—ื‘ื•ืจื” ืฉืœ ืคืจื˜ื™ื ืฉื™ืžื•ืฉื™ื™ื ืฉืื™ื ื ื ืžืฆืื™ื ื‘ื™ื•ืžืŸ ื”ืื™ืจื•ืขื™ื ืฉืœ Windows, ืืš ื”ื—ืฉื•ื‘ื™ื ื‘ื™ื•ืชืจ ื”ื ื”ืฉื“ื•ืช ื”ื‘ืื™ื:

  • ืžื–ื”ื” ืชื”ืœื™ืš (ื‘ืขืฉืจื•ื ื™, ืœื ื‘ื”ืงืกื™ื“!)
  • ืžื–ื”ื” ืชื”ืœื™ืš ื”ื•ืจื”
  • ืขื™ื‘ื•ื“ ืฉื•ืจืช ื”ืคืงื•ื“ื”
  • ืฉื•ืจืช ื”ืคืงื•ื“ื” ืฉืœ ืชื”ืœื™ืš ื”ืื‘
  • Hash ืฉืœ ืชืžื•ื ืช ืงื•ื‘ืฅ
  • ืฉืžื•ืช ืฉืœ ืชืžื•ื ื•ืช ืงื‘ืฆื™ื

Sysmon ืžื•ืชืงืŸ ื”ืŸ ื›ืžื ื”ืœ ื”ืชืงืŸ ื•ื”ืŸ ื›ืฉื™ืจื•ืช - ืคืจื˜ื™ื ื ื•ืกืคื™ื ื›ืืŸ. ื”ื™ืชืจื•ืŸ ื”ืขื™ืงืจื™ ืฉืœื• ื”ื•ื ื”ื™ื›ื•ืœืช ืœื ืชื— ื™ื•ืžื ื™ื ืžืกืคืจ ืžืงื•ืจื•ืช, ืงื•ืจืœืฆื™ื” ืฉืœ ืžื™ื“ืข ื•ืคืœื˜ ืฉืœ ืขืจื›ื™ื ื”ืžืชืงื‘ืœื™ื ืœืชื™ืงื™ื™ืช ื™ื•ืžืŸ ืื™ืจื•ืขื™ื ืื—ืช ื”ืžืžื•ืงืžืช ืœืื•ืจืš ื”ื ืชื™ื‘ Microsoft -> Windows -> Sysmon -> ืชืคืขื•ืœื™. ื‘ื—ืงื™ืจื•ืช ืžืกืžืจื•ืช ืฉื™ืขืจ ืฉืœื™ ืขืœ ื™ื•ืžื ื™ Windows, ืžืฆืืชื™ ืืช ืขืฆืžื™ ื›ืœ ื”ื–ืžืŸ ืฆืจื™ืš ืœืขื‘ื•ืจ ื‘ื™ืŸ, ื ื ื™ื—, ืชื™ืงื™ื™ืช ื™ื•ืžื ื™ PowerShell ืœื‘ื™ืŸ ืชื™ืงื™ื™ืช ื”ืื‘ื˜ื—ื”, ืœื“ืคื“ืฃ ื‘ื™ื•ืžื ื™ ื”ืื™ืจื•ืขื™ื ื‘ื ื™ืกื™ื•ืŸ ืืžื™ืฅ ืœืงืฉืจ ืื™ื›ืฉื”ื• ืืช ื”ืขืจื›ื™ื ื‘ื™ืŸ ื”ืฉื ื™ื™ื . ื–ื• ืืฃ ืคืขื ืœื ืžืฉื™ืžื” ืงืœื”, ื•ื›ืคื™ ืฉื”ื‘ื ืชื™ ืžืื•ื—ืจ ื™ื•ืชืจ, ืขื“ื™ืฃ ืœื”ืฆื˜ื™ื™ื“ ืžื™ื“ ื‘ืืกืคื™ืจื™ืŸ.

Sysmon ืœื•ืงื—ืช ืงืคื™ืฆืช ืžื“ืจื’ื” ืงื“ื™ืžื” ืขืœ ื™ื“ื™ ืžืชืŸ ืžื™ื“ืข ืฉื™ืžื•ืฉื™ (ืื• ื›ืคื™ ืฉื”ืกืคืงื™ื ืื•ื”ื‘ื™ื ืœื•ืžืจ, ืฉื™ืžื•ืฉื™) ื›ื“ื™ ืœืกื™ื™ืข ื‘ื”ื‘ื ืช ื”ืชื”ืœื™ื›ื™ื ื”ื‘ืกื™ืกื™ื™ื. ืœืžืฉืœ, ื”ืชื—ืœืชื™ ืžืคื’ืฉ ืกื•ื“ื™ wmiexec, ื”ืžื“ืžื” ืชื ื•ืขื” ืฉืœ ืื™ืฉ ืคื ื™ื ื—ื›ื ื‘ืชื•ืš ื”ืจืฉืช. ื–ื” ืžื” ืฉืชืจืื” ื‘ื™ื•ืžืŸ ื”ืื™ืจื•ืขื™ื ืฉืœ Windows:

ืžื“ืจื™ืš ืœื ื™ืชื•ื— ืื™ื•ืžื™ื ืฉืœ Sysmon, ื—ืœืง 1

ื™ื•ืžืŸ Windows ืžืฆื™ื’ ืงืฆืช ืžื™ื“ืข ืขืœ ื”ืชื”ืœื™ืš, ืืš ื”ื•ื ืžื•ืขื™ืœ ืžืขื˜. ื‘ื ื•ืกืฃ ืžื–ื”ื™ ืชื”ืœื™ืš ื‘ื”ืงืกื“ืฆื™ืžืœื™???

ืขื‘ื•ืจ ืžืงืฆื•ืขืŸ IT ืžืงืฆื•ืขื™ ืขื ื”ื‘ื ื” ื‘ื™ืกื•ื“ื•ืช ื”ืคืจื™ืฆื”, ืฉื•ืจืช ื”ืคืงื•ื“ื” ืฆืจื™ื›ื” ืœื”ื™ื•ืช ื—ืฉื•ื“ื”. ื”ืฉื™ืžื•ืฉ ื‘-cmd.exe ื›ื“ื™ ืœื”ืคืขื™ืœ ืคืงื•ื“ื” ื ื•ืกืคืช ื•ืœื”ืคื ื•ืช ืืช ื”ืคืœื˜ ืœืงื•ื‘ืฅ ืขื ืฉื ืžื•ื–ืจ ื“ื•ืžื” ื‘ื‘ื™ืจื•ืจ ืœืคืขื•ืœื•ืช ืฉืœ ืชื•ื›ื ืช ื ื™ื˜ื•ืจ ื•ื‘ืงืจื” ืคื™ืงื•ื“ ื•ืฉืœื™ื˜ื” (C2): ื‘ื“ืจืš ื–ื• ื ื•ืฆืจืช ืคืกืื•ื“ื•-ืงืœื™ืคื” ื‘ืืžืฆืขื•ืช ืฉื™ืจื•ืชื™ WMI.
ืขื›ืฉื™ื• ื‘ื•ืื• ื ืกืชื›ืœ ืขืœ ื”ืžืงื‘ื™ืœื” ืœืขืจืš Sysmon, ื•ื ืฉื™ื ืœื‘ ื›ืžื” ืžื™ื“ืข ื ื•ืกืฃ ื”ื•ื ื ื•ืชืŸ ืœื ื•:

ืžื“ืจื™ืš ืœื ื™ืชื•ื— ืื™ื•ืžื™ื ืฉืœ Sysmon, ื—ืœืง 1

Sysmon ืชื›ื•ื ื•ืช ื‘ืฆื™ืœื•ื ืžืกืš ืื—ื“: ืžื™ื“ืข ืžืคื•ืจื˜ ืขืœ ื”ืชื”ืœื™ืš ื‘ืฆื•ืจื” ืงืจื™ื

ืืชื” ืœื ืจืง ืจื•ืื” ืืช ืฉื•ืจืช ื”ืคืงื•ื“ื”, ืืœื ื’ื ืืช ืฉื ื”ืงื•ื‘ืฅ, ื”ื ืชื™ื‘ ืœื™ื™ืฉื•ื ื”ื”ืคืขืœื”, ืžื” ืฉ-Windows ื™ื•ื“ืข ืขืœื™ื• ("ืžืขื‘ื“ ื”ืคืงื•ื“ื” ืฉืœ Windows"), ื”ืžื–ื”ื” ืฉืึถืœ ื”ึทื”ื•ึนืจึดื™ื ืชื”ืœื™ืš, ืฉื•ืจืช ืคืงื•ื“ื” ื”ื•ืจื”, ืฉื”ืฉื™ืงื” ืืช ืžืขื˜ืคืช cmd, ื›ืžื• ื’ื ืืช ืฉื ื”ืงื•ื‘ืฅ ื”ืืžื™ืชื™ ืฉืœ ืชื”ืœื™ืš ื”ืื‘. ื”ื›ืœ ื‘ืžืงื•ื ืื—ื“, ืกื•ืฃ ืกื•ืฃ!
ืžื™ื•ืžืŸ Sysmon ื ื™ืชืŸ ืœื”ืกื™ืง ืฉืขื ืกื‘ื™ืจื•ืช ื’ื‘ื•ื”ื” ืฉื•ืจืช ืคืงื•ื“ื” ื—ืฉื•ื“ื” ื–ื• ืฉืจืื™ื ื• ื‘ื™ื•ืžื ื™ื ื”"ื’ื•ืœืžื™ื™ื" ืื™ื ื” ืชื•ืฆืื” ืฉืœ ืขื‘ื•ื“ื” ืจื’ื™ืœื” ืฉืœ ื”ืขื•ื‘ื“. ืœื”ื™ืคืš, ื”ื•ื ื ื•ืฆืจ ืขืœ ื™ื“ื™ ืชื”ืœื™ืš ื“ืžื•ื™ C2 - wmiexec, ื›ืคื™ ืฉืฆื™ื™ื ืชื™ ืงื•ื“ื - ื•ื”ื•ื ื ื•ืฆืจ ื™ืฉื™ืจื•ืช ืขืœ ื™ื“ื™ ืชื”ืœื™ืš ื”ืฉื™ืจื•ืช ืฉืœ WMI (WmiPrvSe). ื›ืขืช ื™ืฉ ืœื ื• ืื™ื ื“ื™ืงืฆื™ื” ืœื›ืš ืฉืชื•ืงืฃ ืžืจื•ื—ืง ืื• ืคื ื™ืžื™ ื‘ื•ื“ืง ืืช ื”ืชืฉืชื™ืช ื”ืืจื’ื•ื ื™ืช.

ื”ื›ื™ืจื• ืืช Get-Sysmonlogs

ื›ืžื•ื‘ืŸ ืฉื–ื” ื ื”ื“ืจ ื›ืืฉืจ Sysmon ืฉื ืืช ื”ื™ื•ืžื ื™ื ื‘ืžืงื•ื ืื—ื“. ืื‘ืœ ื–ื” ื›ื ืจืื” ื™ื”ื™ื” ืืคื™ืœื• ื˜ื•ื‘ ื™ื•ืชืจ ืื ื ื•ื›ืœ ืœื’ืฉืช ืœืฉื“ื•ืช ื™ื•ืžืŸ ื‘ื•ื“ื“ื™ื ื‘ืื•ืคืŸ ืชื•ื›ื ืชื™ - ืœืžืฉืœ, ื‘ืืžืฆืขื•ืช ืคืงื•ื“ื•ืช PowerShell. ื‘ืžืงืจื” ื–ื”, ืชื•ื›ืœ ืœื›ืชื•ื‘ ืกืงืจื™ืคื˜ PowerShell ืงื˜ืŸ ืฉื™ื”ืคื•ืš ืืช ื”ื—ื™ืคื•ืฉ ืื—ืจ ืื™ื•ืžื™ื ืคื•ื˜ื ืฆื™ืืœื™ื™ื ืœืื•ื˜ื•ืžื˜ื™ื™ื!
ืœื ื”ื™ื™ืชื™ ื”ืจืืฉื•ืŸ ืฉื—ืฉื‘ ืขืœ ืจืขื™ื•ืŸ ื›ื–ื”. ื•ื˜ื•ื‘ ืฉื‘ื—ืœืง ืžื”ืคื•ืกื˜ื™ื ื‘ืคื•ืจื•ื ื•ื‘-GitHub ืคืจื•ื™ืงื˜ื™ื ื›ื‘ืจ ื”ื•ืกื‘ืจ ื›ื™ืฆื“ ืœื”ืฉืชืžืฉ ื‘-PowerShell ื›ื“ื™ ืœื ืชื— ืืช ื™ื•ืžืŸ Sysmon. ื‘ืžืงืจื” ืฉืœื™, ืจืฆื™ืชื™ ืœื”ื™ืžื ืข ืžื”ืฆื•ืจืš ืœื›ืชื•ื‘ ืฉื•ืจื•ืช ื ืคืจื“ื•ืช ืฉืœ ืกืงืจื™ืคื˜ ื ื™ืชื•ื— ืขื‘ื•ืจ ื›ืœ ืฉื“ื” ืฉืœ Sysmon. ืื– ื”ืฉืชืžืฉืชื™ ื‘ืขืงืจื•ืŸ ื”ืื™ืฉ ื”ืขืฆืœืŸ ื•ืื ื™ ื—ื•ืฉื‘ ืฉื”ื’ืขืชื™ ืœืžืฉื”ื• ืžืขื ื™ื™ืŸ ื›ืชื•ืฆืื” ืžื›ืš.
ื”ื ืงื•ื“ื” ื”ื—ืฉื•ื‘ื” ื”ืจืืฉื•ื ื” ื”ื™ื ื”ื™ื›ื•ืœืช ืฉืœ ื”ืงื‘ื•ืฆื” Get-WinEvent ืงืจื ืืช ื™ื•ืžื ื™ Sysmon, ืกื ืŸ ืืช ื”ืื™ืจื•ืขื™ื ื”ื“ืจื•ืฉื™ื ื•ืคืœื˜ ืืช ื”ืชื•ืฆืื” ืœืžืฉืชื ื” PS, ื›ืžื• ื›ืืŸ:

$events = Get-WinEvent  -LogName "Microsoft-Windows-Sysmon/Operational" | where { $_.id -eq 1 -or $_.id -eq 11}

ืื ืืชื” ืจื•ืฆื” ืœื‘ื“ื•ืง ืืช ื”ืคืงื•ื“ื” ื‘ืขืฆืžืš, ืขืœ ื™ื“ื™ ื”ืฆื’ืช ื”ืชื•ื›ืŸ ื‘ืจื›ื™ื‘ ื”ืจืืฉื•ืŸ ืฉืœ ืžืขืจืš $events, $events[0]. ื”ื•ื“ืขื”, ื”ืคืœื˜ ื™ื›ื•ืœ ืœื”ื™ื•ืช ืกื“ืจื” ืฉืœ ืžื—ืจื•ื–ื•ืช ื˜ืงืกื˜ ื‘ืคื•ืจืžื˜ ืคืฉื•ื˜ ืžืื•ื“: ืฉื ื”- ืฉื“ื” Sysmon, ื ืงื•ื“ืชื™ื™ื ื•ืื– ื”ืขืจืš ืขืฆืžื•.

ืžื“ืจื™ืš ืœื ื™ืชื•ื— ืื™ื•ืžื™ื ืฉืœ Sysmon, ื—ืœืง 1

ื”ื™ื“ื“! ืคืœื˜ ื™ื•ืžืŸ Sysmon ืœืคื•ืจืžื˜ ืžื•ื›ืŸ ืœ-JSON

ืืชื” ื—ื•ืฉื‘ ื›ืžื•ื ื™? ืขื ืงืฆืช ื™ื•ืชืจ ืžืืžืฅ, ืืชื” ื™ื›ื•ืœ ืœื”ืžื™ืจ ืืช ื”ืคืœื˜ ืœืžื—ืจื•ื–ืช ื‘ืคื•ืจืžื˜ JSON ื•ืœืื—ืจ ืžื›ืŸ ืœื˜ืขื•ืŸ ืื•ืชื• ื™ืฉื™ืจื•ืช ืœืื•ื‘ื™ื™ืงื˜ PS ื‘ืืžืฆืขื•ืช ืคืงื•ื“ื” ื—ื–ืงื” ConvertFrom-Json .
ืื ื™ ืืจืื” ืืช ืงื•ื“ PowerShell ืœื”ืžืจื” - ื–ื” ืžืื•ื“ ืคืฉื•ื˜ - ื‘ื—ืœืง ื”ื‘ื. ืœืขืช ืขืชื”, ื‘ื•ื ื ืจืื” ืžื” ื”ืคืงื•ื“ื” ื”ื—ื“ืฉื” ืฉืœื™ ืฉื ืงืจืืช get-sysmonlogs, ืฉื”ืชืงื ืชื™ ื›ืžื•ื“ื•ืœ PS, ื™ื›ื•ืœื” ืœืขืฉื•ืช.
ื‘ืžืงื•ื ืœืฆืœื•ืœ ืขืžื•ืง ืœืชื•ืš ื ื™ืชื•ื— ื™ื•ืžืŸ Sysmon ื‘ืืžืฆืขื•ืช ืžืžืฉืง ื™ื•ืžืŸ ืื™ืจื•ืขื™ื ืœื ื ื•ื—, ืื ื• ื™ื›ื•ืœื™ื ืœื—ืคืฉ ืœืœื ืžืืžืฅ ืคืขื™ืœื•ืช ืžืฆื˜ื‘ืจืช ื™ืฉื™ืจื•ืช ืžืคื’ื™ืฉืช PowerShell, ื›ืžื• ื’ื ืœื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื” PS ืื™ืคื” (ื›ื™ื ื•ื™ - "?") ื›ื“ื™ ืœืงืฆืจ ืืช ืชื•ืฆืื•ืช ื”ื—ื™ืคื•ืฉ:

ืžื“ืจื™ืš ืœื ื™ืชื•ื— ืื™ื•ืžื™ื ืฉืœ Sysmon, ื—ืœืง 1

ืจืฉื™ืžื” ืฉืœ ืงื•ื ื›ื™ื•ืช cmd ืฉื”ื•ืฉืงื• ื‘ืืžืฆืขื•ืช WMI. ื ื™ืชื•ื— ืื™ื•ืžื™ื ื‘ื–ื•ืœ ืขื ืฆื•ื•ืช Get-Sysmonlogs ืžืฉืœื ื•

ื ึดืคืœึธื! ื™ืฆืจืชื™ ื›ืœื™ ืœืกืงืจ ืืช ื™ื•ืžืŸ Sysmon ื›ืื™ืœื• ื”ื•ื ืžืกื“ ื ืชื•ื ื™ื. ื‘ืžืืžืจ ืฉืœื ื• ืขืœ ืžึฐื ึทืช ื”ึทืžึดืฉื‚ื›ึผึธืœ ืฆื•ื™ืŸ ื›ื™ ืคื•ื ืงืฆื™ื” ื–ื• ืชืชื‘ืฆืข ืขืœ ื™ื“ื™ ื›ืœื™ ื”ืฉื™ืจื•ืช ื”ืžื’ื ื™ื‘ ื”ืžืชื•ืืจ ื‘ื”, ืื ื›ื™ ืจืฉืžื™ืช ืขื“ื™ื™ืŸ ื‘ืืžืฆืขื•ืช ืžืžืฉืง ื“ืžื•ื™ SQL ืืžื™ืชื™. ื›ืŸ, EQL ืึตืœึถื’ึทื ื˜ึดื™, ืื‘ืœ ื ื™ื’ืข ื‘ื• ื‘ื—ืœืง ื”ืฉืœื™ืฉื™.

Sysmon ื•ื ื™ืชื•ื— ื’ืจืคื™ื

ื‘ื•ืื• ื ื–ื•ื– ืื—ื•ืจื” ื•ื ื—ืฉื•ื‘ ืขืœ ืžื” ืฉื™ืฆืจื ื• ื–ื” ืขืชื”. ื‘ืขื™ืงืจื• ืฉืœ ื“ื‘ืจ, ื™ืฉ ืœื ื• ื›ืขืช ืžืกื“ ื ืชื•ื ื™ื ืฉืœ ืื™ืจื•ืขื™ Windows ื”ื ื’ื™ืฉ ื‘ืืžืฆืขื•ืช PowerShell. ื›ืคื™ ืฉืฆื™ื™ื ืชื™ ืงื•ื“ื, ื™ืฉื ื ืงืฉืจื™ื ืื• ืงืฉืจื™ื ื‘ื™ืŸ ืจืฉื•ืžื•ืช - ื“ืจืš ParentProcessId - ื›ืš ืฉื ื™ืชืŸ ืœืงื‘ืœ ื”ื™ืจืจื›ื™ื” ืžืœืื” ืฉืœ ืชื”ืœื™ื›ื™ื.

ืื ืงืจืืช ืืช ื”ืกื“ืจื” "ื”ืจืคืชืงืื•ืช ื”ืชื•ื›ื ื” ื”ื–ื“ื•ื ื™ืช ื”ื—ืžืงืžืงื”" ืืชื” ื™ื•ื“ืข ืฉื”ืืงืจื™ื ืื•ื”ื‘ื™ื ืœื™ืฆื•ืจ ื”ืชืงืคื•ืช ืžื•ืจื›ื‘ื•ืช ืจื‘-ืฉืœื‘ื™ื•ืช, ืฉื‘ื”ืŸ ื›ืœ ืชื”ืœื™ืš ืžืฉื—ืง ืืช ื”ืชืคืงื™ื“ ื”ืงื˜ืŸ ืฉืœื• ื•ืžื›ื™ืŸ ืงืจืฉ ืงืคื™ืฆื” ืœืฉืœื‘ ื”ื‘ื. ืงืฉื” ืžืื•ื“ ืœืชืคื•ืก ื“ื‘ืจื™ื ื›ืืœื” ืคืฉื•ื˜ ืžื”ื™ื•ืžืŸ ื”"ื’ื•ืœืžื™".
ืื‘ืœ ืขื ืคืงื•ื“ืช Get-Sysmonlogs ืฉืœื™ ื•ืžื‘ื ื” ื ืชื•ื ื™ื ื ื•ืกืฃ ืฉื ืกืชื›ืœ ืขืœื™ื• ื‘ื”ืžืฉืš ื”ื˜ืงืกื˜ (ื’ืจืฃ, ื›ืžื•ื‘ืŸ), ื™ืฉ ืœื ื• ื“ืจืš ืžืขืฉื™ืช ืœื–ื”ื•ืช ืื™ื•ืžื™ื - ืžื” ืฉืคืฉื•ื˜ ื“ื•ืจืฉ ื—ื™ืคื•ืฉ ืงื•ื“ืงื•ื“ ื ื›ื•ืŸ.
ื›ืžื• ืชืžื™ื“ ื‘ืคืจื•ื™ืงื˜ื™ื ืฉืœื ื• ื‘ื‘ืœื•ื’ DYI, ื›ื›ืœ ืฉืชืขื‘ื“ื• ื™ื•ืชืจ ืขืœ ื ื™ืชื•ื— ื”ืคืจื˜ื™ื ืฉืœ ืื™ื•ืžื™ื ื‘ืงื ื” ืžื™ื“ื” ืงื˜ืŸ, ื›ืš ืชื‘ื™ื ื• ืขื“ ื›ืžื” ืžื•ืจื›ื‘ ื–ื™ื”ื•ื™ ื”ืื™ื•ืžื™ื ื‘ืจืžืช ื”ืืจื’ื•ืŸ. ื•ื”ืžื•ื“ืขื•ืช ื”ื–ื• ื”ื™ื ืžืื•ื“ ื ืงื•ื“ื” ื—ืฉื•ื‘ื”.

ืืช ื”ืกื™ื‘ื•ื›ื™ื ื”ืžืขื ื™ื™ื ื™ื ื”ืจืืฉื•ื ื™ื ื ืคื’ื•ืฉ ื‘ื—ืœืง ื”ืฉื ื™ ืฉืœ ื”ืžืืžืจ, ื‘ื• ื ืชื—ื™ืœ ืœื—ื‘ืจ ื‘ื™ืŸ ืื™ืจื•ืขื™ Sysmon ื–ื” ืœื–ื” ืœืžื‘ื ื™ื ืžื•ืจื›ื‘ื™ื ื”ืจื‘ื” ื™ื•ืชืจ.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”