ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ื

ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ื
ืืœื’ื•ืจื™ืชืžื™ื ื•ื˜ืงื˜ื™ืงื•ืช ืชื’ื•ื‘ื” ืœืื™ืจื•ืขื™ ืื‘ื˜ื—ืช ืžื™ื“ืข, ืžื’ืžื•ืช ื‘ืžืชืงืคื•ืช ืกื™ื™ื‘ืจ ืขื“ื›ื ื™ื•ืช, ื’ื™ืฉื•ืช ืœื—ืงื™ืจืช ื“ืœื™ืคื•ืช ื ืชื•ื ื™ื ื‘ื—ื‘ืจื•ืช, ื—ืงืจ ื“ืคื“ืคื ื™ื ื•ืžื›ืฉื™ืจื™ื ื ื™ื™ื“ื™ื, ื ื™ืชื•ื— ืงื‘ืฆื™ื ืžื•ืฆืคื ื™ื, ื—ื™ืœื•ืฅ ื ืชื•ื ื™ ืžื™ืงื•ื ื’ื™ืื•ื’ืจืคื™ ื•ื ื™ืชื•ื— ืฉืœ ื›ืžื•ื™ื•ืช ื’ื“ื•ืœื•ืช ืฉืœ ื ืชื•ื ื™ื - ื›ืœ ืืœื• ื•ืื—ืจื™ื. ื ื™ืชืŸ ืœืœืžื•ื“ ื‘ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ื—ื“ืฉื™ื ืฉืœ Group-IB ื•-Belkasoft. ื‘ืื•ื’ื•ืกื˜ ืื ื—ื ื• ื”ื•ื›ืจื– ื”ืงื•ืจืก ื”ืจืืฉื•ืŸ ืฉืœ Belkasoft Digital Forensics, ืฉืžืชื—ื™ืœ ื‘-9 ื‘ืกืคื˜ืžื‘ืจ, ื•ืœืื—ืจ ืฉืงื™ื‘ืœื ื• ืžืกืคืจ ืจื‘ ืฉืœ ืฉืืœื•ืช, ื”ื—ืœื˜ื ื• ืœื“ื‘ืจ ื‘ื™ืชืจ ืคื™ืจื•ื˜ ืขืœ ืžื” ื™ืœืžื“ื• ื”ืชืœืžื™ื“ื™ื, ืื™ื–ื” ื™ื“ืข, ืžื™ื•ืžื ื•ื™ื•ืช ื•ื‘ื•ื ื•ืกื™ื (!) ื™ืงื‘ืœื• ืžื™ ืœื”ื’ื™ืข ืœืกื•ืฃ. ืงื•ื“ื ื›ืœ.

ืฉื ื™ื™ื ื”ื›ืœ ื‘ืื—ื“

ื”ืจืขื™ื•ืŸ ืœืขืจื•ืš ืงื•ืจืกื™ ื”ื›ืฉืจื” ืžืฉื•ืชืคื™ื ื”ื•ืคื™ืข ืœืื—ืจ ืฉื”ืžืฉืชืชืคื™ื ื‘ืงื•ืจืก Group-IB ื”ื—ืœื• ืœืฉืื•ืœ ืขืœ ื›ืœื™ ืฉื™ืขื–ื•ืจ ืœื”ื ืœื—ืงื•ืจ ืžืขืจื›ื•ืช ืžื—ืฉื‘ื™ื ื•ืจืฉืชื•ืช ืฉื ืคื’ืขื•, ื•ืœืฉืœื‘ ืืช ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืฉืœ ื›ืœื™ ืขื–ืจ ื—ื™ื ืžื™ื™ื ืฉื•ื ื™ื ืฉืื ื• ืžืžืœื™ืฆื™ื ืœื”ืฉืชืžืฉ ื‘ื”ื ื‘ืžื”ืœืš ืชื’ื•ื‘ื” ืœืื™ืจื•ืขื™ื.

ืœื“ืขืชื ื•, ื›ืœื™ ื›ื–ื” ื™ื›ื•ืœ ืœื”ื™ื•ืช Belkasoft Evidence Center (ื›ื‘ืจ ื“ื™ื‘ืจื ื• ืขืœ ื–ื” ื‘ ัั‚ะฐั‚ัŒะต ืื™ื’ื•ืจ ืžื™ื›ืื™ืœื•ื‘ "ื”ืžืคืชื— ืœื”ืชื—ืœื”: ื”ืชื•ื›ื ื” ื•ื”ื—ื•ืžืจื” ื”ื˜ื•ื‘ื•ืช ื‘ื™ื•ืชืจ ืœื–ื™ื”ื•ื™ ืคืœื™ืœื™ ืžื—ืฉื‘ื™ื"). ืœื›ืŸ, ืคื™ืชื—ื ื• ื™ื—ื“ ืขื ื‘ืœืงืกื•ืคื˜ ืฉื ื™ ืงื•ืจืกื™ ื”ื›ืฉืจื”: Belkasoft Digital Forensics ะธ ื‘ื“ื™ืงืช ืชื’ื•ื‘ื” ืœืื™ืจื•ืขื™ื ืฉืœ Belkasoft.

ื—ืฉื•ื‘: ื”ืงื•ืจืกื™ื ื”ื ืขื•ืงื‘ื™ื ื•ืžืงื•ืฉืจื™ื ื–ื” ืœื–ื”! Belkasoft Digital Forensics ืžื•ืงื“ืฉืช ืœืชื•ื›ื ื™ืช Belkasoft Evidence Center, ื•-Belkasoft Incident Response Examination ืžื•ืงื“ืฉืช ืœื—ืงื™ืจืช ืชืงืจื™ื•ืช ื‘ืืžืฆืขื•ืช ืžื•ืฆืจื™ Belkasoft. ื›ืœื•ืžืจ, ืœืคื ื™ ืœื™ืžื•ื“ ื”ืงื•ืจืก ื‘ื—ื™ื ืช ืชื’ื•ื‘ื” ืœืื™ืจื•ืขื™ื ืฉืœ Belkasoft, ืื ื• ืžืžืœื™ืฆื™ื ื‘ื—ื•ื ืœื”ืฉืœื™ื ืืช ื”ืงื•ืจืก ื“ื™ื’ื™ื˜ืœื™ ืœื–ื™ื”ื•ื™ ืคืœื™ืœื™ ืฉืœ Belkasoft. ืื ืชืชื—ื™ืœ ืžื™ื“ ืขื ืงื•ืจืก ืขืœ ื—ืงื™ืจื•ืช ืื™ืจื•ืขื™ื, ื™ื™ืชื›ืŸ ืฉืœืชืœืžื™ื“ ื™ื”ื™ื• ืคืขืจื™ ื™ื“ืข ืžืขืฆื‘ื ื™ื ื‘ืฉื™ืžื•ืฉ ื‘ืžืจื›ื– ื”ืจืื™ื•ืช ืฉืœ Belkasoft, ื‘ืื™ืชื•ืจ ื•ื‘ื—ื™ื ืช ื—ืคืฆื™ื ืžืฉืคื˜ื™ื™ื. ื–ื” ืขืฉื•ื™ ืœื”ื•ื‘ื™ืœ ืœืขื•ื‘ื“ื” ืฉื‘ืžื”ืœืš ื”ื”ื›ืฉืจื” ื‘ืงื•ืจืก ื‘ื—ื™ื ืช ืชื’ื•ื‘ื” ืœืื™ืจื•ืขื™ื ืฉืœ Belkasoft, ืœืชืœืžื™ื“ ืื• ืฉืœื ื™ื”ื™ื” ื–ืžืŸ ืœืฉืœื•ื˜ ื‘ื—ื•ืžืจ, ืื• ืฉื™ืื˜ ืืช ืฉืืจ ื”ืงื‘ื•ืฆื” ื‘ืจื›ื™ืฉืช ื™ื“ืข ื—ื“ืฉ, ืฉื›ืŸ ื–ืžืŸ ื”ื”ื“ืจื›ื” ื™ื•ืงื“ืฉ. ืขืœ ื™ื“ื™ ื”ืžืืžืŸ ืฉืžืกื‘ื™ืจ ืืช ื”ื—ื•ืžืจ ืžื”ืงื•ืจืก ืฉืœ Belkasoft Digital Forensics.

ื–ื™ื”ื•ื™ ืคืœื™ืœื™ ืžื—ืฉื‘ื™ื ืขื Belkasoft Evidence Center

ืžื˜ืจืช ื”ืงื•ืจืก Belkasoft Digital Forensics - ื”ืฆื™ื’ื• ืœืชืœืžื™ื“ื™ื ืืช ืชื•ื›ื ื™ืช Belkasoft Evidence Center, ืœืžื“ื• ืื•ืชื ืœื”ืฉืชืžืฉ ื‘ืชื•ื›ื ื™ืช ื–ื• ื›ื“ื™ ืœืืกื•ืฃ ืจืื™ื•ืช ืžืžืงื•ืจื•ืช ืฉื•ื ื™ื (ืื—ืกื•ืŸ ื‘ืขื ืŸ, ื–ื™ื›ืจื•ืŸ ื’ื™ืฉื” ืืงืจืื™ืช (RAM), ืžื›ืฉื™ืจื™ื ื ื™ื™ื“ื™ื, ืžื“ื™ื™ืช ืื—ืกื•ืŸ (ื›ื•ื ื ื™ื ืงืฉื™ื—ื™ื, ื›ื•ื ื ื™ ื”ื‘ื–ืง ื•ื›ื•'), ืžืืกื˜ืจ ื˜ื›ื ื™ืงื•ืช ื•ื˜ื›ื ื™ืงื•ืช ืžืฉืคื˜ื™ื•ืช ื‘ืกื™ืกื™ื•ืช, ืฉื™ื˜ื•ืช ื‘ื“ื™ืงื” ืžืฉืคื˜ื™ืช ืฉืœ ื—ืคืฆื™ Windows, ืžื›ืฉื™ืจื™ื ื ื™ื™ื“ื™ื, ืžื–ื‘ืœื•ืช RAM. ื›ืžื• ื›ืŸ ืชืœืžื“ ืœื–ื”ื•ืช ื•ืœืชืขื“ ื—ืคืฆื™ื ืฉืœ ื“ืคื“ืคื ื™ื ื•ืชื•ื›ื ื™ื•ืช ื”ื•ื“ืขื•ืช ืžื™ื™ื“ื™ื•ืช, ืœื™ืฆื•ืจ ืขื•ืชืงื™ื ืžืฉืคื˜ื™ื™ื ืฉืœ ื ืชื•ื ื™ื ืžืžืงื•ืจื•ืช ืฉื•ื ื™ื, ืœื—ืœืฅ ื ืชื•ื ื™ ืžื™ืงื•ื ื’ื™ืื•ื’ืจืคื™ ื•ืœื—ืคืฉ ืขื‘ื•ืจ ืจืฆืคื™ ื˜ืงืกื˜ (ื—ื™ืคื•ืฉ ืžื™ืœื•ืช ืžืคืชื—), ื”ืฉืชืžืฉ ื‘-hash ื‘ืขืช ื‘ื™ืฆื•ืข ืžื—ืงืจ, ื ืชื— ืืช ื”ืจื™ืฉื•ื ืฉืœ Windows, ืฉืœื˜ ื‘ืžื™ื•ืžื ื•ื™ื•ืช ืฉืœ ื—ืงืจ ืžืกื“ื™ ื ืชื•ื ื™ื ืœื ื™ื“ื•ืขื™ื ืฉืœ SQLite, ื”ื™ืกื•ื“ื•ืช ืฉืœ ื‘ื—ื™ื ืช ืงื‘ืฆื™ ื’ืจืคื™ืงื” ื•ื•ื™ื“ืื• ื•ื˜ื›ื ื™ืงื•ืช ืื ืœื™ื˜ื™ื•ืช ื”ืžืฉืžืฉื•ืช ื‘ืžื”ืœืš ื—ืงื™ืจื•ืช.

ื”ืงื•ืจืก ื™ื•ืขื™ืœ ืœืžื•ืžื—ื™ื ื‘ืขืœื™ ื”ืชืžื—ื•ืช ื‘ืชื—ื•ื ื–ื™ื”ื•ื™ ืคืœื™ืœื™ ื˜ื›ื ื™ ืžืžื•ื—ืฉื‘ (ื–ื™ื”ื•ื™ ืคืœื™ืœื™ ืžื—ืฉื‘); ืžื•ืžื—ื™ื ื˜ื›ื ื™ื™ื ื”ืงื•ื‘ืขื™ื ืืช ื”ืกื™ื‘ื•ืช ืœืคืจื™ืฆื” ืžื•ืฆืœื—ืช, ืžื ืชื—ื™ื ืืช ืฉืจืฉืจืช ื”ืื™ืจื•ืขื™ื ื•ืืช ื”ื”ืฉืœื›ื•ืช ืฉืœ ื”ืชืงืคื•ืช ืกื™ื™ื‘ืจ; ืžื•ืžื—ื™ื ื˜ื›ื ื™ื™ื ื”ืžื–ื”ื™ื ื•ืžืชืขื“ื™ื ื’ื ื™ื‘ืช ื ืชื•ื ื™ื (ื“ืœื™ืคื•ืช) ืขืœ ื™ื“ื™ ืื™ืฉ ืคื ื™ื (ืžืคืจ ืคื ื™ืžื™); ืžื•ืžื—ื™ e-Discovery; ืฆื•ื•ืช SOC ื•-CERT/CSIRT; ืขื•ื‘ื“ื™ ืื‘ื˜ื—ืช ืžื™ื“ืข; ื—ื•ื‘ื‘ื™ ื–ื™ื”ื•ื™ ืคืœื™ืœื™ ืžื—ืฉื‘ื™ื.

ืชื•ื›ื ื™ืช ื”ืงื•ืจืก:

  • Belkasoft Evidence Center (BEC): ืฆืขื“ื™ื ืจืืฉื•ื ื™ื
  • ื™ืฆื™ืจื” ื•ื˜ื™ืคื•ืœ ื‘ืชื™ืงื™ื ื‘-BEC
  • ืืกื•ืฃ ืจืื™ื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ืœื—ืงื™ืจื•ืช ืžืฉืคื˜ื™ื•ืช ืขื BEC

ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ื

  • ืฉื™ืžื•ืฉ ื‘ืžืกื ื ื™ื
  • ื”ืคืงืช ื“ื•ื—ื•ืช
  • ืžื—ืงืจ ืขืœ ืชื•ื›ื ื™ื•ืช ื”ื•ื“ืขื•ืช ืžื™ื™ื“ื™ื•ืช

ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ื

  • ืžื—ืงืจ ื“ืคื“ืคืŸ ืื™ื ื˜ืจื ื˜

ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ื

  • ืžื—ืงืจ ืžื›ืฉื™ืจื™ื ื ื™ื™ื“ื™ื
  • ื—ื™ืœื•ืฅ ื ืชื•ื ื™ ืžื™ืงื•ื ื’ื™ืื•ื’ืจืคื™

ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ื

  • ื—ื™ืคื•ืฉ ืจืฆืคื™ ื˜ืงืกื˜ ื‘ืžืงืจื™ื
  • ื—ื™ืœื•ืฅ ื•ื ื™ืชื•ื— ื ืชื•ื ื™ื ืžืžื—ืกื ื™ ืขื ืŸ
  • ืฉื™ืžื•ืฉ ื‘ืกื™ืžื ื™ื•ืช ื›ื“ื™ ืœื”ื“ื’ื™ืฉ ืขื“ื•ื™ื•ืช ืžืฉืžืขื•ืชื™ื•ืช ืฉื ืžืฆืื• ื‘ืžื”ืœืš ื”ืžื—ืงืจ
  • ื‘ื—ื™ื ืช ืงื‘ืฆื™ ืžืขืจื›ืช Windows

ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ื

  • ื ื™ืชื•ื— ื”ืจื™ืฉื•ื ืฉืœ Windows
  • ื ื™ืชื•ื— ืžืกื“ื™ ื ืชื•ื ื™ื ืฉืœ SQLite

ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ื

  • ืฉื™ื˜ื•ืช ืฉื—ื–ื•ืจ ื ืชื•ื ื™ื
  • ื˜ื›ื ื™ืงื•ืช ืœื‘ื—ื™ื ืช ื”ืฉืœื›ื•ืช RAM
  • ืฉื™ืžื•ืฉ ื‘ืžื—ืฉื‘ื•ืŸ hash ื•ื ื™ืชื•ื— hash ื‘ืžื—ืงืจ ืžืฉืคื˜ื™
  • ื ื™ืชื•ื— ืงื‘ืฆื™ื ืžื•ืฆืคื ื™ื
  • ืฉื™ื˜ื•ืช ืœืœื™ืžื•ื“ ืงื‘ืฆื™ ื’ืจืคื™ืงื” ื•ื•ื™ื“ืื•
  • ื”ืฉื™ืžื•ืฉ ื‘ื˜ื›ื ื™ืงื•ืช ืื ืœื™ื˜ื™ื•ืช ื‘ืžื—ืงืจ ืžืฉืคื˜ื™
  • ืื•ื˜ื•ืžืฆื™ื” ืฉืœ ืคืขื•ืœื•ืช ืฉื’ืจืชื™ื•ืช ื‘ืืžืฆืขื•ืช ืฉืคืช ื”ืชื›ื ื•ืช ื”ืžื•ื‘ื ื™ืช Belkascripts

ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ื

  • ืฉื™ืขื•ืจื™ื ืžืขืฉื™ื™ื

ืงื•ืจืก: ื‘ื—ื™ื ืช ืชื’ื•ื‘ื” ืœืื™ืจื•ืขื™ื ืฉืœ Belkasoft

ืžื˜ืจืช ื”ืงื•ืจืก ื”ื™ื ืœืœืžื•ื“ ืืช ื™ืกื•ื“ื•ืช ื”ื—ืงื™ืจื” ืคื•ืจื ื–ื™ืช ืฉืœ ืžืชืงืคื•ืช ืกื™ื™ื‘ืจ ื•ืืช ืืคืฉืจื•ื™ื•ืช ื”ืฉื™ืžื•ืฉ ื‘ืžืจื›ื– ื”ืจืื™ื•ืช ืฉืœ Belkasoft ื‘ื—ืงื™ืจื”. ืชืœืžื“ื• ืขืœ ื”ื•ื•ืงื˜ื•ืจื™ื ื”ืขื™ืงืจื™ื™ื ืฉืœ ื”ืชืงืคื•ืช ืžื•ื“ืจื ื™ื•ืช ืขืœ ืจืฉืชื•ืช ืžื—ืฉื‘ื™ื, ืชืœืžื“ื• ืœืกื•ื•ื’ ื”ืชืงืคื•ืช ืžื—ืฉื‘ ืขืœ ืกืžืš ืžื˜ืจื™ืฆืช MITER ATT&CK, ืชื—ื™ืœื• ืืœื’ื•ืจื™ืชืžื™ื ืœืžื—ืงืจ ืฉืœ ืžืขืจื›ื•ืช ื”ืคืขืœื” ื›ื“ื™ ืœื‘ืกืก ืืช ืขื•ื‘ื“ืช ื”ืคืฉืจื” ื•ืœืฉื—ื–ืจ ืืช ืคืขื•ืœื•ืช ื”ืชื•ืงืคื™ื, ืชืœืžื“ื• ื”ื™ื›ืŸ ืžืžื•ืงืžื™ื ื—ืคืฆื™ื ืฆื™ื™ื ื• ืื™ืœื• ืงื‘ืฆื™ื ื ืคืชื—ื• ืœืื—ืจื•ื ื”, ื”ื™ื›ืŸ ืžืขืจื›ืช ื”ื”ืคืขืœื” ืžืื—ืกื ืช ืžื™ื“ืข ืขืœ ืื•ืคืŸ ื”ื”ื•ืจื“ื” ื•ื”ื‘ื™ืฆื•ืข ืฉืœ ืงื‘ืฆื™ ื”ืคืขืœื”, ื›ื™ืฆื“ ื”ืชื•ืงืคื™ื ืขื‘ืจื• ื‘ืจื—ื‘ื™ ื”ืจืฉืช, ื•ืœืžื“ ื›ื™ืฆื“ ืœื‘ื—ื•ืŸ ืืช ื”ื—ืคืฆื™ื ื”ืœืœื• ื‘ืืžืฆืขื•ืช BEC. ืชืœืžื“ื• ื’ื ืื™ืœื• ืื™ืจื•ืขื™ื ื‘ื™ื•ืžื ื™ ื”ืžืขืจื›ืช ืžืขื ื™ื™ื ื™ื ืžื ืงื•ื“ืช ืžื‘ื˜ ืฉืœ ื—ืงื™ืจืช ืื™ืจื•ืขื™ื ื•ื–ื™ื”ื•ื™ ื’ื™ืฉื” ืžืจื—ื•ืง, ื•ืชืœืžื“ื• ื›ื™ืฆื“ ืœื—ืงื•ืจ ืื•ืชื ื‘ืืžืฆืขื•ืช BEC.

ื”ืงื•ืจืก ื™ื”ื™ื” ืฉื™ืžื•ืฉื™ ืœืžื•ืžื—ื™ื ื˜ื›ื ื™ื™ื ืฉื™ืงื‘ืขื• ืืช ื”ืกื™ื‘ื•ืช ืœืคืจื™ืฆื” ืžื•ืฆืœื—ืช, ืžื ืชื—ื™ื ืฉืจืฉืจืื•ืช ืื™ืจื•ืขื™ื ื•ืืช ื”ื”ืฉืœื›ื•ืช ืฉืœ ื”ืชืงืคื•ืช ืกื™ื™ื‘ืจ; ืžื ื”ืœื™ ืžืขืจื›ืช; ืฆื•ื•ืช SOC ื•-CERT/CSIRT; ืฆื•ื•ืช ืื‘ื˜ื—ืช ืžื™ื“ืข.

ืกืงื™ืจืช ื”ืงื•ืจืก

Cyber โ€‹โ€‹โ€‹โ€‹Kill Chain ืžืชืืจ ืืช ื”ืฉืœื‘ื™ื ื”ืขื™ืงืจื™ื™ื ืฉืœ ื›ืœ ืžืชืงืคื” ื˜ื›ื ื™ืช ืขืœ ืžื—ืฉื‘ื™ ื”ืงื•ืจื‘ืŸ (ืื• ืจืฉืช ื”ืžื—ืฉื‘ื™ื) ื›ื“ืœืงืžืŸ:
ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ื
ื”ืคืขื•ืœื•ืช ืฉืœ ืขื•ื‘ื“ื™ SOC (CERT, ืื‘ื˜ื—ืช ืžื™ื“ืข ื•ื›ื•') ืžื›ื•ื•ื ื•ืช ืœืžื ื•ืข ืžืคื•ืœืฉื™ื ืœื’ืฉืช ืœืžืฉืื‘ื™ ืžื™ื“ืข ืžื•ื’ื ื™ื.

ืื ืื›ืŸ ื—ื•ื“ืจื™ื ืชื•ืงืคื™ื ืœืชืฉืชื™ืช ื”ืžื•ื’ื ืช, ืขืœ ื”ืื ืฉื™ื ืœืขื™ืœ ืœื ืกื•ืช ืœืžื–ืขืจ ืืช ื”ื ื–ืง ืžืคืขื™ืœื•ืช ื”ืชื•ืงืคื™ื, ืœืงื‘ื•ืข ื›ื™ืฆื“ ื‘ื•ืฆืขื” ื”ืชืงื™ืคื”, ืœืฉื—ื–ืจ ืืช ื”ืื™ืจื•ืขื™ื ื•ืจืฆืฃ ื”ืคืขื•ืœื•ืช ืฉืœ ื”ืชื•ืงืคื™ื ื‘ืžื‘ื ื” ื”ืžื™ื“ืข ืฉื ืคื’ืข, ื•ืœื ืงื•ื˜ ืืžืฆืขื™ื ืœืžื ื™ืขืช ืชืงื™ืคื” ืžืกื•ื’ ื–ื” ื‘ืขืชื™ื“.

ื ื™ืชืŸ ืœืžืฆื•ื ืืช ืกื•ื’ื™ ื”ืขืงื‘ื•ืช ื”ื‘ืื™ื ื‘ืชืฉืชื™ืช ืžื™ื“ืข ืฉื ืคื’ืขื”, ื”ืžืขื™ื“ื™ื ืขืœ ื›ืš ืฉื”ืจืฉืช (ื”ืžื—ืฉื‘) ื ืคื’ืขื”:

ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ื
ื ื™ืชืŸ ืœืžืฆื•ื ืืช ื›ืœ ื”ืขืงื‘ื•ืช ื”ืœืœื• ื‘ืืžืฆืขื•ืช ืชื•ื›ื ื™ืช Belkasoft Evidence Center.

ืœ-BEC ืžื•ื“ื•ืœ "ื—ืงื™ืจืช ืชืงืจื™ื•ืช", ืฉื‘ื•, ื‘ืขืช ื ื™ืชื•ื— ืืžืฆืขื™ ืื—ืกื•ืŸ, ืžื•ืฆื‘ ืžื™ื“ืข ืขืœ ื—ืคืฆื™ื ืฉื™ื›ื•ืœ ืœืขื–ื•ืจ ืœื—ื•ืงืจ ื‘ืขืช ื—ืงื™ืจืช ืชืงืจื™ื•ืช.

ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ื
BEC ืชื•ืžืš ื‘ื‘ื“ื™ืงื” ืฉืœ ื”ืกื•ื’ื™ื ื”ืขื™ืงืจื™ื™ื ืฉืœ ื—ืคืฆื™ Windows ื”ืžืฆื‘ื™ืขื™ื ืขืœ ื‘ื™ืฆื•ืข ืงื‘ืฆื™ ื”ืคืขืœื” ื‘ืžืขืจื›ืช ื”ื ื—ืงืจืช, ืœืจื‘ื•ืช ืงื‘ืฆื™ Amcache, Userassist, Prefetch, BAM/DAM, ืฆื™ืจ ื”ื–ืžืŸ ืฉืœ Windows 10,ื ื™ืชื•ื— ืื™ืจื•ืขื™ ืžืขืจื›ืช.

ืžื™ื“ืข ืขืœ ืขืงื‘ื•ืช ื”ืžื›ื™ืœื™ื ืžื™ื“ืข ืขืœ ืคืขื•ืœื•ืช ื”ืžืฉืชืžืฉ ื‘ืžืขืจื›ืช ืฉื ืคืจืฆื” ื™ื›ื•ืœ ืœื”ื™ื•ืช ืžื•ืฆื’ ื‘ืฆื•ืจื” ื”ื‘ืื”:

ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ื
ืžื™ื“ืข ื–ื”, ื‘ื™ืŸ ื”ื™ืชืจ, ื›ื•ืœืœ ืžื™ื“ืข ืขืœ ื”ืคืขืœืช ืงื‘ืฆื™ ื”ืคืขืœื”:

ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ืืžื™ื“ืข ืขืœ ื”ืคืขืœืช ื”ืงื•ื‘ืฅ 'RDPWInst.exe'.

ืžื™ื“ืข ืขืœ ื ื•ื›ื—ื•ืช ื”ืชื•ืงืคื™ื ื‘ืžืขืจื›ื•ืช ืฉื ืคื’ืขื• ื ื™ืชืŸ ืœืžืฆื•ื ื‘ืžืคืชื—ื•ืช ื”ืคืขืœื” ืฉืœ ื”ืจื™ืฉื•ื ืฉืœ Windows, ืฉื™ืจื•ืชื™ื, ืžืฉื™ืžื•ืช ืžืชื•ื–ืžื ื•ืช, ืกืงืจื™ืคื˜ื™ื ืœื›ื ื™ืกื”, WMI ื•ื›ื•'. ื“ื•ื’ืžืื•ืช ืœื–ื™ื”ื•ื™ ืžื™ื“ืข ืขืœ ืชื•ืงืคื™ื ื”ืžืฆื•ืจืคื™ื ืœืžืขืจื›ืช ื ื™ืชืŸ ืœืจืื•ืช ื‘ืฆื™ืœื•ืžื™ ื”ืžืกืš ื”ื‘ืื™ื:

ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ืื”ื’ื‘ืœืช ืชื•ืงืคื™ื ื‘ืืžืฆืขื•ืช ืžืชื–ืžืŸ ื”ืžืฉื™ืžื•ืช ืขืœ ื™ื“ื™ ื™ืฆื™ืจืช ืžืฉื™ืžื” ื”ืžืจื™ืฅ ืกืงืจื™ืคื˜ PowerShell.

ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ืืื™ื—ื•ื“ ืชื•ืงืคื™ื ื‘ืืžืฆืขื•ืช Windows Management Instrumentation (WMI).

ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ืืื™ื—ื•ื“ ืชื•ืงืคื™ื ื‘ืืžืฆืขื•ืช ืกืงืจื™ืคื˜ ื›ื ื™ืกื”.

ื ื™ืชืŸ ืœื–ื”ื•ืช ืชื ื•ืขื” ืฉืœ ืชื•ืงืคื™ื ื‘ืจืฉืช ืžื—ืฉื‘ื™ื ืฉื ืคื’ืขื”, ืœืžืฉืœ, ืขืœ ื™ื“ื™ ื ื™ืชื•ื— ื™ื•ืžื ื™ ืžืขืจื›ืช Windows (ืื ื”ืชื•ืงืคื™ื ืžืฉืชืžืฉื™ื ื‘ืฉื™ืจื•ืช RDP).

ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ืืžื™ื“ืข ืขืœ ื—ื™ื‘ื•ืจื™ RDP ืฉื–ื•ื”ื•.

ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ืฉืœ Group-IB ื•-Belkasoft: ืžื” ื ืœืžื“ ื•ืžื™ ืœื‘ื•ืืžื™ื“ืข ืขืœ ืชื ื•ืขืช ื”ืชื•ืงืคื™ื ื‘ืจื—ื‘ื™ ื”ืจืฉืช.

ื›ืš, Belkasoft Evidence Center ื™ื›ื•ืœ ืœืกื™ื™ืข ืœื—ื•ืงืจื™ื ืœื–ื”ื•ืช ืžื—ืฉื‘ื™ื ืฉื ืคื’ืขื• ื‘ืจืฉืช ืžื—ืฉื‘ื™ื ืžื•ืชืงืคืช, ืœืžืฆื•ื ืขืงื‘ื•ืช ืฉืœ ื”ืฉืงื” ืฉืœ ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช, ืขืงื‘ื•ืช ืฉืœ ืงื™ื‘ื•ืข ื‘ืžืขืจื›ืช ื•ืชื ื•ืขื” ื‘ืจื—ื‘ื™ ื”ืจืฉืช, ื•ืฉืืจ ืขืงื‘ื•ืช ืฉืœ ืคืขื™ืœื•ืช ืชื•ืงืคื™ื ื‘ืžื—ืฉื‘ื™ื ืฉื ืคื’ืขื•.

ื›ื™ืฆื“ ืœื‘ืฆืข ืžื—ืงืจ ื›ื–ื” ื•ืœืืชืจ ืืช ื”ื—ืคืฆื™ื ื”ืžืชื•ืืจื™ื ืœืขื™ืœ ืžืชื•ืืจ ื‘ืงื•ืจืก ื”ื”ื›ืฉืจื” ืฉืœ Belkasoft Incident Response Examination.

ืชื•ื›ื ื™ืช ื”ืงื•ืจืก:

  • ืžื’ืžื•ืช ืžืชืงืคื•ืช ืกื™ื™ื‘ืจ. ื˜ื›ื ื•ืœื•ื’ื™ื•ืช, ื›ืœื™ื, ืžื˜ืจื•ืช ืฉืœ ืชื•ืงืคื™ื
  • ืฉื™ืžื•ืฉ ื‘ืžื•ื“ืœื™ื ืฉืœ ืื™ื•ืžื™ื ื›ื“ื™ ืœื”ื‘ื™ืŸ ืืช ื”ื˜ืงื˜ื™ืงื•ืช, ื”ื˜ื›ื ื™ืงื•ืช ื•ื”ื ื”ืœื™ื ืฉืœ ื”ืชื•ืงืคื™ื
  • ืฉืจืฉืจืช ื”ืจื’ ืกื™ื™ื‘ืจ
  • ืืœื’ื•ืจื™ืชื ืชื’ื•ื‘ื” ืœืื™ืจื•ืขื™ื: ื–ื™ื”ื•ื™, ืœื•ืงืœื™ื–ืฆื™ื”, ื™ืฆื™ืจืช ืื™ื ื“ื™ืงื˜ื•ืจื™ื, ื—ื™ืคื•ืฉ ืฆืžืชื™ื ื ื’ื•ืขื™ื ื—ื“ืฉื™ื
  • ื ื™ืชื•ื— ืžืขืจื›ื•ืช Windows ื‘ืืžืฆืขื•ืช BEC
  • ื–ื™ื”ื•ื™ ืฉื™ื˜ื•ืช ืฉืœ ื–ื™ื”ื•ื ืจืืฉื•ื ื™, ื”ืชืคืฉื˜ื•ืช ืจืฉืช, ืื™ื—ื•ื“ ื•ืคืขื™ืœื•ืช ืจืฉืช ืฉืœ ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ื‘ืืžืฆืขื•ืช BEC
  • ื–ื™ื”ื•ื™ ืžืขืจื›ื•ืช ื ื’ื•ืขื•ืช ื•ืฉื—ื–ื•ืจ ื”ื™ืกื˜ื•ืจื™ื™ืช ื–ื™ื”ื•ืžื™ื ื‘ืืžืฆืขื•ืช BEC
  • ืฉื™ืขื•ืจื™ื ืžืขืฉื™ื™ื

ืฉืืœื•ืช ื ืคื•ืฆื•ืชื”ื™ื›ืŸ ืžืชืงื™ื™ืžื™ื ื”ืงื•ืจืกื™ื?
ื”ืงื•ืจืกื™ื ืžืชืงื™ื™ืžื™ื ื‘ืžื˜ื” Group-IB ืื• ื‘ืืชืจ ื—ื™ืฆื•ื ื™ (ืžืจื›ื– ื”ื“ืจื›ื”). ื™ืฉ ืืคืฉืจื•ืช ืœืžืืžืŸ ืœื ืกื•ืข ืœืืชืจื™ื ืขื ืœืงื•ื—ื•ืช ืขืกืงื™ื™ื.

ืžื™ ืžืขื‘ื™ืจ ืืช ื”ืฉื™ืขื•ืจื™ื?
ืžืืžื ื™ื ื‘-Group-IB ื”ื ืžืชืจื’ืœื™ื ื‘ืขืœื™ ื ื™ืกื™ื•ืŸ ืจื‘ ืฉื ื™ื ื‘ื‘ื™ืฆื•ืข ืžื—ืงืจ ืžืฉืคื˜ื™, ื—ืงื™ืจื•ืช ืืจื’ื•ื ื™ื•ืช ื•ืชื’ื•ื‘ื” ืœืื™ืจื•ืขื™ ืื‘ื˜ื—ืช ืžื™ื“ืข.

ื”ื›ื™ืฉื•ืจื™ื ืฉืœ ื”ืžืืžื ื™ื ืžืื•ืฉืจื™ื ืขืœ ื™ื“ื™ ืชืขื•ื“ื•ืช ื‘ื™ื ืœืื•ืžื™ื•ืช ืจื‘ื•ืช: GCFA, MCFE, ACE, EnCE ื•ื›ื• '.

ื”ืžืืžื ื™ื ืฉืœื ื• ืžื•ืฆืื™ื ื‘ืงืœื•ืช ืฉืคื” ืžืฉื•ืชืคืช ืขื ื”ืงื”ืœ, ื•ืžืกื‘ื™ืจื™ื ื‘ื‘ื™ืจื•ืจ ืืคื™ืœื• ืืช ื”ื ื•ืฉืื™ื ื”ืžื•ืจื›ื‘ื™ื ื‘ื™ื•ืชืจ. ื”ืกื˜ื•ื“ื ื˜ื™ื ื™ืœืžื“ื• ืžื™ื“ืข ืจื‘ ืจืœื•ื•ื ื˜ื™ ื•ืžืขื ื™ื™ืŸ ืขืœ ื—ืงื™ืจืช ืื™ืจื•ืขื™ ืžื—ืฉื‘, ืฉื™ื˜ื•ืช ื–ื™ื”ื•ื™ ื•ืžื ื™ืขืช ื”ืชืงืคื•ืช ืžื—ืฉื‘, ื•ื™ืงื‘ืœื• ื™ื“ืข ืžืขืฉื™ ืืžื™ืชื™ ืฉื™ื•ื›ืœื• ืœื™ื™ืฉื ืžื™ื“ ืœืื—ืจ ืกื™ื•ื ื”ืœื™ืžื•ื“ื™ื.

ื”ืื ื”ืงื•ืจืกื™ื ื™ืกืคืงื• ืžื™ื•ืžื ื•ื™ื•ืช ืฉื™ืžื•ืฉื™ื•ืช ืฉืื™ื ืŸ ืงืฉื•ืจื•ืช ืœืžื•ืฆืจื™ Belkasoft, ืื• ื”ืื ืžื™ื•ืžื ื•ื™ื•ืช ืืœื• ืœื ื™ื”ื™ื• ื™ืฉื™ืžื•ืช ืœืœื ืชื•ื›ื ื” ื–ื•?
ื”ืžื™ื•ืžื ื•ื™ื•ืช ืฉื ืจื›ืฉื• ื‘ืžื”ืœืš ื”ื”ื“ืจื›ื” ื™ื”ื™ื• ืฉื™ืžื•ืฉื™ื•ืช ืœืœื ืฉื™ืžื•ืฉ ื‘ืžื•ืฆืจื™ Belkasoft.

ืžื” ื›ืœื•ืœ ื‘ื‘ื“ื™ืงื” ื”ืจืืฉื•ื ื™ืช?

ื‘ื“ื™ืงื” ืจืืฉื•ื ื™ืช ื”ื™ื ืžื‘ื—ืŸ ื™ื“ืข ื‘ื™ืกื•ื“ื•ืช ื”ื–ื™ื”ื•ื™ ื”ืคืœื™ืœื™ ื”ืžืžื•ื—ืฉื‘. ืื™ืŸ ืชื•ื›ื ื™ื•ืช ืœื‘ื—ื•ืŸ ืืช ื”ื™ื“ืข ื‘ืžื•ืฆืจื™ Belkasoft ื•-Group-IB.

ื”ื™ื›ืŸ ื ื™ืชืŸ ืœืžืฆื•ื ืžื™ื“ืข ืขืœ ื”ืงื•ืจืกื™ื ื”ื—ื™ื ื•ื›ื™ื™ื ืฉืœ ื”ื—ื‘ืจื”?

ื‘ืžืกื’ืจืช ืงื•ืจืกื™ื ื—ื™ื ื•ื›ื™ื™ื, Group-IB ืžื›ืฉื™ืจื” ืžื•ืžื—ื™ื ื‘ืชื’ื•ื‘ื” ืœืื™ืจื•ืขื™ื, ื—ืงืจ ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช, ืžื•ืžื—ื™ ืžื•ื“ื™ืขื™ืŸ ืกื™ื™ื‘ืจ (Threat Intelligence), ืžื•ืžื—ื™ื ืœืขื‘ื•ื“ื” ื‘-Security Operation Center (SOC), ืžื•ืžื—ื™ื ืœืฆื™ื“ ืื™ื•ืžื™ื ืคืจื•ืืงื˜ื™ื‘ื™ (Threat Hunter) ื•ื›ื•'. . ืจืฉื™ืžื” ืžืœืื” ืฉืœ ืงื•ืจืกื™ื ืงื ื™ื™ื ื™ื™ื ืž- Group-IB ื–ืžื™ื ื” ื›ืืŸ.

ืื™ืœื• ื‘ื•ื ื•ืกื™ื ืžืงื‘ืœื™ื ืกื˜ื•ื“ื ื˜ื™ื ืฉืžืกื™ื™ืžื™ื ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ื‘ื™ืŸ Group-IB ืœ-Belkasoft?
ืžื™ ืฉืกื™ื™ื ื”ื›ืฉืจื” ื‘ืงื•ืจืกื™ื ืžืฉื•ืชืคื™ื ื‘ื™ืŸ Group-IB ื•-Belkasoft ื™ืงื‘ืœื•:

  1. ืชืขื•ื“ืช ืกื™ื•ื ื”ืงื•ืจืก;
  2. ืžื ื•ื™ ื—ื•ื“ืฉื™ ื—ื™ื ื ืœืžืจื›ื– ื”ืจืื™ื•ืช ืฉืœ Belkasoft;
  3. 10% ื”ื ื—ื” ื‘ืจื›ื™ืฉืช Belkasoft Evidence Center.

ืžื–ื›ื™ืจื™ื ืœื›ื ืฉื”ืงื•ืจืก ื”ืจืืฉื•ืŸ ืžืชื—ื™ืœ ื‘ื™ื•ื ืฉื ื™, 9 ืกืคื˜ืžื‘ืจ,- ืืœ ืชืคืกืคืกื• ืืช ื”ื”ื–ื“ืžื ื•ืช ืœืฆื‘ื•ืจ ื™ื“ืข ื™ื™ื—ื•ื“ื™ ื‘ืชื—ื•ื ืื‘ื˜ื—ืช ืžื™ื“ืข, ื–ื™ื”ื•ื™ ืคืœื™ืœื™ ืžื—ืฉื‘ื™ื ื•ืชื’ื•ื‘ื” ืœืื™ืจื•ืขื™ื! ื”ืจืฉืžื” ืœืงื•ืจืก ื›ืืŸ.

ืžืงื•ืจื•ืชื‘ื”ื›ื ืช ื”ืžืืžืจ, ื”ืฉืชืžืฉื ื• ื‘ืžืฆื’ืช ืฉืœ ืื•ืœื’ ืกืงื•ืœืงื™ืŸ "ืฉื™ืžื•ืฉ ื‘ื–ื™ื”ื•ื™ ืคืœื™ืœื™ ืžื‘ื•ืกืก ืžืืจื— ื›ื“ื™ ืœืงื‘ืœ ืื™ื ื“ื™ืงื˜ื•ืจื™ื ืฉืœ ืคืฉืจื” ืœืชื’ื•ื‘ื” ืžื•ืฆืœื—ืช ืœืื™ืจื•ืขื™ื ืžื•ื ืขื™ ืžื•ื“ื™ืขื™ืŸ."

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”