ãŠãŒã¶ãŒã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã¯ãæ å ±ã»ãã¥ãªãã£ã®èŠ³ç¹ããã€ã³ãã©ã¹ãã©ã¯ãã£ã®æãè匱ãªãã€ã³ãã§ãã ãŠãŒã¶ãŒã¯ãå®å šãªéä¿¡å ããéä¿¡ãããããã«èŠããŠããææãããµã€ããžã®ãªã³ã¯ãå«ãŸããæçŽãä»äºçšã¡ãŒã«ã§åãåãããšããããŸãã ãããã誰ãããä»äºã«åœ¹ç«ã€ãŠãŒãã£ãªãã£ãæªç¥ã®å ŽæããããŠã³ããŒãããã§ãããã ã¯ãããã«ãŠã§ã¢ããŠãŒã¶ãŒãéããŠäŒæ¥å éšãªãœãŒã¹ã«ã©ã®ããã«äŸµå ¥ãããã«ã€ããŠã¯ãæ°åã®ã±ãŒã¹ãæãã€ãããšãã§ããŸãã ãããã£ãŠãã¯ãŒã¯ã¹ããŒã·ã§ã³ã«ã¯ããã«æ³šæãå¿ èŠã§ãããã®èšäºã§ã¯ãæ»æãç£èŠããããã«ã©ãã§ã©ã®ãããªã€ãã³ããå®è¡ããå¿ èŠããããã説æããŸãã
å¯èœãªéãæ©ã段éã§æ»æãæ€åºããããã«ãWindows ã«ã¯ãã»ãã¥ãªã㣠ã€ãã³ã ãã°ãã·ã¹ãã ç£èŠãã°ãããã³ Power Shell ãã°ãšãã XNUMX ã€ã®äŸ¿å©ãªã€ãã³ã ãœãŒã¹ããããŸãã
ã»ãã¥ãªãã£ã€ãã³ããã°
ããã¯ãã·ã¹ãã ã»ãã¥ãªã㣠ãã°ã®äž»ãªä¿åå Žæã§ãã ããã«ã¯ããŠãŒã¶ãŒã®ãã°ã€ã³/ãã°ã¢ãŠãããªããžã§ã¯ããžã®ã¢ã¯ã»ã¹ãããªã·ãŒã®å€æŽããã®ä»ã®ã»ãã¥ãªãã£é¢é£ã®ã¢ã¯ãã£ããã£ã®ã€ãã³ããå«ãŸããŸãã ãã¡ãããé©åãªããªã·ãŒãèšå®ãããŠããå Žåã«éããŸãã
ãŠãŒã¶ãŒãšã°ã«ãŒãã®åæ (ã€ãã³ã 4798 ããã³ 4799)ã æ»æã®æåã«ããã«ãŠã§ã¢ã¯å€ãã®å Žåãã¯ãŒã¯ã¹ããŒã·ã§ã³äžã®ããŒã«ã« ãŠãŒã¶ãŒ ã¢ã«ãŠã³ããšããŒã«ã« ã°ã«ãŒããæ€çŽ¢ããŠããã®æªããååŒã®ããã®èªèšŒæ
å ±ãèŠã€ããŸãã ãããã®ã€ãã³ãã¯ãæªæã®ããã³ãŒããé²è¡ããåéãããããŒã¿ã䜿çšããŠä»ã®ã·ã¹ãã ã«æ¡æ£ããåã«æ€åºããã®ã«åœ¹ç«ã¡ãŸãã
ããŒã«ã« ã¢ã«ãŠã³ãã®äœæãšããŒã«ã« ã°ã«ãŒãã®å€æŽ (ã€ãã³ã 4720ã4722 ïœ 4726ã4738ã4740ã4767ã4780ã4781ã4794ã5376ãããã³ 5377)ã ããšãã°ãããŒã«ã«ç®¡çè ã°ã«ãŒãã«æ°ãããŠãŒã¶ãŒãè¿œå ããããšã«ãã£ãŠæ»æãéå§ãããããšããããŸãã
ããŒã«ã« ã¢ã«ãŠã³ãã䜿çšããŠãã°ã€ã³ãè©Šè¡ããŸã (ã€ãã³ã 4624)ã ç«æŽŸãªãŠãŒã¶ãŒã¯ãã¡ã€ã³ ã¢ã«ãŠã³ãã§ãã°ã€ã³ããŸãããããŒã«ã« ã¢ã«ãŠã³ãã§ã®ãã°ã€ã³ãç¹å®ããããšãæ»æã®éå§ãæå³ããå¯èœæ§ããããŸãã ã€ãã³ã 4624 ã«ã¯ãã¡ã€ã³ ã¢ã«ãŠã³ãã§ã®ãã°ã€ã³ãå«ãŸãããããã€ãã³ããåŠçãããšãã¯ããã¡ã€ã³ãã¯ãŒã¯ã¹ããŒã·ã§ã³åãšç°ãªãã€ãã³ãããã£ã«ã¿ãŒã§é€å€ããå¿ èŠããããŸãã
æå®ãããã¢ã«ãŠã³ãã§ãã°ã€ã³ããããšããŸãã (ã€ãã³ã 4648)ã ããã¯ãããã»ã¹ããå®è¡ãã¢ãŒãã§å®è¡ãããŠãããšãã«çºçããŸãã ããã¯ã·ã¹ãã ã®éåžžã®åäœäžã«ã¯çºçãã¹ãã§ã¯ãªãããããã®ãããªã€ãã³ãã¯å¶åŸ¡ããå¿ èŠããããŸãã
ã¯ãŒã¯ã¹ããŒã·ã§ã³ã®ããã¯/ããã¯è§£é€ (ã€ãã³ã 4800 ïœ 4803)ã äžå¯©ãªã€ãã³ãã®ã«ããŽãªã«ã¯ãããã¯ãããã¯ãŒã¯ã¹ããŒã·ã§ã³ã§çºçããã¢ã¯ã·ã§ã³ãå«ãŸããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«æ§æã®å€æŽ (ã€ãã³ã 4944 ïœ 4958)ã æ°ãããœãããŠã§ã¢ãã€ã³ã¹ããŒã«ãããšããã¡ã€ã¢ãŠã©ãŒã«ã®æ§æèšå®ãå€æŽãããå¯èœæ§ããããããã«ãã誀æ€ç¥ãçºçããå¯èœæ§ããããŸãã ã»ãšãã©ã®å Žåããã®ãããªå€æŽãå¶åŸ¡ããå¿ èŠã¯ãããŸããããç¥ã£ãŠããŠæã¯ãããŸããã
ãã©ã°ã¢ã³ããã¬ã€ ããã€ã¹ã®æ¥ç¶ (ã€ãã³ã 6416ãWindows 10 ã®ã¿)ã ãŠãŒã¶ãŒãéåžžã¯æ°ããããã€ã¹ãã¯ãŒã¯ã¹ããŒã·ã§ã³ã«æ¥ç¶ããªãã®ã«ãçªç¶æ¥ç¶ããããã«ãªãå Žåã¯ãããã«æ³šæããããšãéèŠã§ãã
Windows ã«ã¯ã埮調æŽçšã® 9 ã€ã®ç£æ»ã«ããŽãªãš 50 ã®ãµãã«ããŽãªãå«ãŸããŠããŸãã èšå®ã§æå¹ã«ããå¿ èŠããããµãã«ããŽãªã®æå°ã»ãã:
ãã°ãªã³/ãã°ãªã
- ãã°ãªã³;
- ãã°ãªã;
- ã¢ã«ãŠã³ãã®ããã¯ã¢ãŠã;
- ãã®ä»ã®ãã°ãªã³/ãã°ãªã ã€ãã³ãã
ã¢ã«ãŠã³ããããžã¡ã³ã
- ãŠãŒã¶ãŒã¢ã«ãŠã³ã管ç;
- ã»ãã¥ãªãã£ã°ã«ãŒã管çã
ããªã·ãŒã®å€æŽ
- ç£æ»ããªã·ãŒã®å€æŽã
- èªèšŒããªã·ãŒã®å€æŽã
- èªå¯ããªã·ãŒã®å€æŽã
ã·ã¹ãã ã¢ãã¿ãŒïŒSysmonïŒ
Sysmon ã¯ãã·ã¹ãã ãã°ã«ã€ãã³ããèšé²ã§ãã Windows ã«çµã¿èŸŒãŸãããŠãŒãã£ãªãã£ã§ãã éåžžã¯åå¥ã«ã€ã³ã¹ããŒã«ããå¿ èŠããããŸãã
ãããã®åãã€ãã³ãã¯ãååãšã㊠(å¿
èŠãªç£æ»ããªã·ãŒãæå¹ã«ããããšã§) ã»ãã¥ãªã㣠ãã°ã§èŠã€ããããšãã§ããŸãããSysmon ã¯ãã詳现ãªæ
å ±ãæäŸããŸãã SysmonããååŸã§ããã€ãã³ãã¯äœã§ãã?
ããã»ã¹ã®äœæ (ã€ãã³ã ID 1)ã ã·ã¹ãã ã»ãã¥ãªã㣠ã€ãã³ã ãã°ã§ã¯ã*.exe ããã€éå§ããããããããããã®ååãšèµ·åãã¹ã衚瀺ãããŸãã ãã ããSysmon ãšã¯ç°ãªããã¢ããªã±ãŒã·ã§ã³ ããã·ã¥ã衚瀺ããããšã¯ã§ããŸããã æªæã®ãããœãããŠã§ã¢ã¯ç¡å®³ãª notepad.exe ãšåŒã°ããããšããããŸããããããæããã«ããã®ã¯ããã·ã¥ã§ãã
ãããã¯ãŒã¯æ¥ç¶ (ã€ãã³ã ID 3)ã æããã«ããããã¯ãŒã¯æ¥ç¶ã¯å€æ°ãããããããã¹ãŠã远跡ããããšã¯äžå¯èœã§ãã ãã ããã»ãã¥ãªã㣠ãã°ãšã¯ç°ãªããSysmon ã¯ãããã¯ãŒã¯æ¥ç¶ã ProcessID ãã£ãŒã«ããš ProcessGUID ãã£ãŒã«ãã«ãã€ã³ãã§ããéä¿¡å ãšå®å ã®ããŒããš IP ã¢ãã¬ã¹ã衚瀺ã§ããããšãèæ ®ããããšãéèŠã§ãã
ã·ã¹ãã ã¬ãžã¹ããªã®å€æŽ (ã€ãã³ã ID 12 ïœ 14)ã èªåèªèº«ãèªåå®è¡ã«è¿œå ããæãç°¡åãªæ¹æ³ã¯ãã¬ãžã¹ããªã«ç»é²ããããšã§ãã ã»ãã¥ãªã㣠ãã°ã¯ãããå®è¡ã§ããŸãããSysmon ã«ã¯ã誰ãããã€ãã©ãããå€æŽãå ããããããã»ã¹ ID ãšä»¥åã®ããŒã®å€ã衚瀺ãããŸãã
ãã¡ã€ã«ã®äœæ (ã€ãã³ã ID 11)ã Sysmon ã¯ãã»ãã¥ãªã㣠ãã°ãšã¯ç°ãªãããã¡ã€ã«ã®å Žæã ãã§ãªãååã衚瀺ããŸãã ãã¹ãŠã远跡ããããšã¯ã§ããªãããšã¯æããã§ãããç¹å®ã®ãã£ã¬ã¯ããªãç£æ»ããããšã¯ã§ããŸãã
ãããŠãã»ãã¥ãªã㣠ãã° ããªã·ãŒã«ã¯ãªããSysmon ã«å«ãŸãããã®ã¯æ¬¡ã®ãšããã§ãã
ãã¡ã€ã«äœææå»ã®å€æŽ (ã€ãã³ã ID 2)ã äžéšã®ãã«ãŠã§ã¢ã¯ããã¡ã€ã«ã®äœææ¥ãåœè£ ããŠãæè¿äœæããããã¡ã€ã«ã®ã¬ããŒããããã®æ¥ä»ãé ãããšãã§ããŸãã
ãã©ã€ããŒãšãã€ããã㯠ã©ã€ãã©ãªãããŒãããŠããŸã (ã€ãã³ã ID 6 ïœ 7)ã DLL ãšããã€ã¹ ãã©ã€ããŒã®ã¡ã¢ãªãžã®ããŒããç£èŠããããžã¿ã«çœ²åãšãã®æå¹æ§ããã§ãã¯ããŸãã
å®è¡äžã®ããã»ã¹ (ã€ãã³ã ID 8) ã«ã¹ã¬ãããäœæããŸãã ãããç£èŠããå¿ èŠãããæ»æã® XNUMX çš®é¡ã§ãã
RawAccessRead ã€ãã³ã (ã€ãã³ã ID 9)ã ã.ãã䜿çšãããã£ã¹ã¯èªã¿åãæäœã ã»ãšãã©ã®å Žåããã®ãããªæŽ»åã¯ç°åžžã§ãããšèããã¹ãã§ãã
ååä»ããã¡ã€ã« ã¹ããªãŒã (ã€ãã³ã ID 15) ãäœæããŸãã ãã¡ã€ã«ã®å 容ã®ããã·ã¥ãå«ãã€ãã³ããçºè¡ããååä»ããã¡ã€ã« ã¹ããªãŒã ãäœæããããšãã€ãã³ãããã°ã«èšé²ãããŸãã
ååä»ããã€ããšæ¥ç¶ãäœæããŸã (ã€ãã³ã ID 17 ïœ 18)ã ååä»ããã€ããä»ããŠä»ã®ã³ã³ããŒãã³ããšéä¿¡ããæªæã®ããã³ãŒãã远跡ããŸãã
WMI ã¢ã¯ãã£ãã㣠(ã€ãã³ã ID 19)ã WMI ãããã³ã«çµç±ã§ã·ã¹ãã ã«ã¢ã¯ã»ã¹ãããšãã«çæãããã€ãã³ãã®ç»é²ã
Sysmon èªäœãä¿è·ããã«ã¯ãID 4 (Sysmon ã®åæ¢ãšéå§) ãš ID 16 (Sysmon æ§æã®å€æŽ) ã®ã€ãã³ããç£èŠããå¿ èŠããããŸãã
ãã¯ãŒã·ã§ã«ãã°
Power Shell 㯠Windows ã€ã³ãã©ã¹ãã©ã¯ãã£ã管çããããã®åŒ·åãªããŒã«ã§ãããããæ»æè ããããéžæããå¯èœæ§ãé«ããªããŸãã Power Shell ã€ãã³ã ããŒã¿ã®ååŸã«ã¯ãWindows PowerShell ãã°ãš Microsoft-WindowsPowerShell/Operational ãã°ã® XNUMX ã€ã®ãœãŒã¹ã䜿çšã§ããŸãã
Windows PowerShell ãã°
ããŒã¿ ãããã€ããŒãããŒããããŸãã (ã€ãã³ã ID 600)ã PowerShell ãããã€ããŒã¯ãPowerShell ã衚瀺ããã³ç®¡çããããã®ããŒã¿ ãœãŒã¹ãæäŸããããã°ã©ã ã§ãã ããšãã°ãçµã¿èŸŒã¿ãããã€ããŒã¯ãWindows ç°å¢å€æ°ãŸãã¯ã·ã¹ãã ã¬ãžã¹ããªã§ããå¯èœæ§ããããŸãã æªæã®ãã掻åãé©æã«æ€åºããã«ã¯ãæ°ãããµãã©ã€ã€ãŒã®åºçŸãç£èŠããå¿
èŠããããŸãã ããšãã°ããããã€ããŒã®äžã« WSMan ã衚瀺ãããŠããå Žåã¯ããªã¢ãŒã PowerShell ã»ãã·ã§ã³ãéå§ãããŠããŸãã
Microsoft-WindowsPowerShell / æäœãã° (ãŸã㯠PowerShell 6 ã® MicrosoftWindows-PowerShellCore / Operational)
ã¢ãžã¥ãŒã«ã®ãã°èšé² (ã€ãã³ã ID 4103)ã ã€ãã³ãã«ã¯ãå®è¡ãããåã³ãã³ããšãã®ã³ãã³ããåŒã³åºãããã©ã¡ãŒã¿ã«é¢ããæ
å ±ãä¿åãããŸãã
ã¹ã¯ãªããã®ãã°èšé²ã®ããã㯠(ã€ãã³ã ID 4104)ã ã¹ã¯ãªãã ãããã¯ã®ãã°ã«ã¯ãå®è¡ããã PowerShell ã³ãŒãã®ãã¹ãŠã®ãããã¯ã衚瀺ãããŸãã æ»æè ãã³ãã³ããé èœããããšããŠãããã®ã€ãã³ã ã¿ã€ãã§ã¯å®éã«å®è¡ããã PowerShell ã³ãã³ãã衚瀺ãããŸãã ãã®ã€ãã³ã ã¿ã€ãã¯ãå®è¡ãããŠããäœã¬ãã« API åŒã³åºãããã°ã«èšé²ããããšãã§ããŸãããããã®ã€ãã³ãã¯é垞詳现ãšããŠèšé²ãããŸãããçãããã³ãã³ããŸãã¯ã¹ã¯ãªãããã³ãŒã ãããã¯ã§äœ¿çšãããŠããå Žåã¯ãé倧床ãèŠåãšããŠèšé²ãããŸãã
ãããã®ã€ãã³ããåéããŠåæããããã«ããŒã«ãæ§æãããšã誀æ€ç¥ã®æ°ãæžããããã«è¿œå ã®ãããã°æéãå¿ èŠã«ãªãããšã«æ³šæããŠãã ããã
æ
å ±ã»ãã¥ãªãã£ç£æ»ã®ããã«ã©ã®ãããªãã°ãåéããŠãããããŸããã®ããã«ã©ã®ãããªããŒã«ã䜿çšããŠããããã³ã¡ã³ãã§æããŠãã ããã åœç€Ÿã泚åããŠããåéã® XNUMX ã€ã¯ãæ
å ±ã»ãã¥ãªã㣠ã€ãã³ããç£æ»ããããã®ãœãªã¥ãŒã·ã§ã³ã§ãã ãã°ã®åéãšåæã®åé¡ã解決ããã«ã¯ã以äžã詳ãã調ã¹ãããšããå§ãããŸãã
åºæïŒ habr.com