ãã®èšäºã¯ãSysmon ã®è
åšåæã«é¢ããã·ãªãŒãºã®æåã®éšåã§ãã ã·ãªãŒãºã®ä»ã®ãã¹ãŠã®éšå:
ããŒã 1: Sysmon ãã°åæã®æŠèŠ ïŒç§ãã¡ã¯ããã«ããïŒ
ããŒã 2: Sysmon ã€ãã³ã ããŒã¿ã䜿çšããŠè
åšãç¹å®ãã
ããŒã 3. ã°ã©ãã䜿çšãã Sysmon ã®è
åšã®è©³çŽ°ãªåæ
æ
å ±ã»ãã¥ãªãã£ã®åéã§åããŠããå Žåã¯ãé²è¡äžã®æ»æãç解ããå¿
èŠãããããšãå€ãã§ãããã ãã§ã«èšç·Žãããç®ãæã£ãŠããå Žåã¯ããçã®ãæªåŠçã®ãã°ã§éæšæºã®ã¢ã¯ãã£ãã㣠(ããšãã°ãå®è¡ãããŠãã PowerShell ã¹ã¯ãªãããªã©) ãæ¢ãããšãã§ããŸãã
Sysmon ãã°ã«è¡šç€ºãããè
åšã®èåŸã«ããåºæ¬çãªèãæ¹ãç解ãããã§ãã? ã¬ã€ããããŠã³ããŒã
ã·ãªãŒãºã®æåã®éšåã§ã¯ãSysmon ããã®åºæ¬æ
å ±ã䜿çšããŠäœãã§ããããèŠãŠãããŸãã ããŒã XNUMX ã§ã¯ã芪ããã»ã¹æ
å ±ãæ倧éã«æŽ»çšããŠãè
åšã°ã©ããšåŒã°ããããè€éãªã³ã³ãã©ã€ã¢ã³ã¹æ§é ãäœæããŸãã XNUMX çªç®ã®ããŒãã§ã¯ãè
åšã°ã©ããã¹ãã£ã³ããã°ã©ãã®ãéã¿ããåæããããšã§ç°åžžãªã¢ã¯ãã£ããã£ãæ€çŽ¢ããåçŽãªã¢ã«ãŽãªãºã ãèŠãŠãããŸãã ãããŠæçµçã«ã¯ããã¡ããšãã (ãããŠãããããã) 確çè«çãªè
åšæ€åºæ¹æ³ãåŸãããŸãã
ããŒã 1: Sysmon ãã°åæã®æŠèŠ
ã€ãã³ã ãã°ã®è€éããç解ããã®ã«äœã圹ç«ã¡ãŸãã? æçµçã«ã¯ SIEM ã§ãã ã€ãã³ããæ£èŠåãããã®åŸã®åæãç°¡çŽ åããŸãã ããããå°ãªããšãæåã¯ãããŸã§ããå¿ èŠã¯ãããŸããã æåã¯ãSIEM ã®åçãç解ããã«ã¯ãçŽ æŽãããç¡æã® Sysmon ãŠãŒãã£ãªãã£ãè©Šãã ãã§ååã§ãã ãããŠã圌女ã¯é©ãã»ã©ä»äºãããããã®ã§ãã é 匵ããã€ã¯ããœããïŒ
Sysmonã«ã¯ã©ã®ãããªæ©èœããããŸãã?
ã€ãŸããããã»ã¹ã«é¢ããæçšã§èªã¿ãããæ å ±ã§ã (äžã®å³ãåç §)ã Windows ã€ãã³ã ãã°ã«ã¯å«ãŸããŠããªãæçšãªè©³çŽ°ãå€æ°èŠã€ãããŸãããæãéèŠãªã®ã¯æ¬¡ã®ãã£ãŒã«ãã§ãã
- ããã»ã¹ ID (XNUMX é²æ°ã§ã¯ãªã XNUMX é²æ°!)
- 芪ããã»ã¹ID
- ããã»ã¹ã®ã³ãã³ãã©ã€ã³
- 芪ããã»ã¹ã®ã³ãã³ãã©ã€ã³
- ãã¡ã€ã«ã€ã¡ãŒãžã®ããã·ã¥
- ãã¡ã€ã«ã€ã¡ãŒãžå
Sysmon ã¯ããã€ã¹ ãã©ã€ããŒãšãµãŒãã¹ã®äž¡æ¹ãšããŠã€ã³ã¹ããŒã«ãããŸã - 詳现
Sysmon ã¯ãåºç€ãšãªãããã»ã¹ãç解ããã®ã«åœ¹ç«ã€æçšãª (ãã³ããŒãèšãããã«ãå®çšçãª) æ
å ±ãæäŸããããšã§ãé£èºçãªé²æ©ãéããŠããŸãã ããšãã°ãç§å¯ã®ã»ãã·ã§ã³ãéå§ããŸãã
Windows ãã°ã«ã¯ããã»ã¹ã«é¢ããæ å ±ã衚瀺ãããŸãããã»ãšãã©åœ¹ã«ç«ã¡ãŸããã ããã«ããã»ã¹ ID ã XNUMX é²æ°ã§è¡šç€ºããŸãã
ãããã³ã°ã®åºæ¬ãç解ããŠããå°éã® IT ãããã§ãã·ã§ãã«ã«ãšã£ãŠãã³ãã³ã ã©ã€ã³ã¯çãããã¯ãã§ãã cmd.exe ã䜿çšããŠå¥ã®ã³ãã³ããå®è¡ããåºåãå¥åŠãªååã®ãã¡ã€ã«ã«ãªãã€ã¬ã¯ãããããšã¯ãæããã«ç£èŠããã³å¶åŸ¡ãœãããŠã§ã¢ã®åäœãšäŒŒãŠããŸãã
ããã§ãåçã® Sysmon ãšã³ããªãèŠãŠãã©ã®çšåºŠã®è¿œå æ
å ±ãåŸããããã«æ³šç®ããŠã¿ãŸãããã
Sysmon ã®æ©èœã XNUMX ã€ã®ã¹ã¯ãªãŒã³ã·ã§ããã§è¡šç€º: ããã»ã¹ã«é¢ãã詳现æ å ±ãèªã¿ããã圢åŒã§è¡šç€º
ã³ãã³ã ã©ã€ã³ã ãã§ãªãããã¡ã€ã«åãå®è¡å¯èœã¢ããªã±ãŒã·ã§ã³ãžã®ãã¹ãWindows ãèªèããŠããå
容 (ãWindows ã³ãã³ã ããã»ããµã)ãèå¥åã衚瀺ãããŸãã 芪㮠ããã»ã¹ãã³ãã³ãã©ã€ã³ 芪ãcmd ã·ã§ã«ãèµ·åãããã®ãããã³èŠªããã»ã¹ã®å®éã®ãã¡ã€ã«åã ãã¹ãŠã XNUMX ãæã«ã€ãã«ïŒ
Sysmon ãã°ããããçããã°ã§ç¢ºèªããããã®äžå¯©ãªã³ãã³ã ã©ã€ã³ã¯ãåŸæ¥å¡ã®éåžžã®äœæ¥ã®çµæã§ã¯ãªãå¯èœæ§ãé«ããšçµè«ä»ããããšãã§ããŸãã ããã©ãããããã㯠C2 ã«äŒŒãããã»ã¹ (åè¿°ããããã« wmiexec) ã«ãã£ãŠçæãããWMI ãµãŒãã¹ ããã»ã¹ (WmiPrvSe) ã«ãã£ãŠçŽæ¥çæãããŸããã ããã§ããªã¢ãŒãã®æ»æè
ãŸãã¯å
éšé¢ä¿è
ãäŒæ¥ã€ã³ãã©ã¹ãã©ã¯ãã£ããã¹ãããŠããããšã瀺ãå
åãåŸãããŸããã
Get-Sysmonlogs ã®çŽ¹ä»
ãã¡ãããSysmon ããã°ã XNUMX ãæã«ãŸãšããã®ã¯çŽ æŽãããããšã§ãã ãã ããPowerShell ã³ãã³ããªã©ã䜿çšããŠãããã°ã©ã ã§åã
ã®ãã° ãã£ãŒã«ãã«ã¢ã¯ã»ã¹ã§ããã°ãããããããã«è¯ããªãã§ãããã ãã®å Žåãæœåšçãªè
åšã®æ€çŽ¢ãèªååããå°ã㪠PowerShell ã¹ã¯ãªãããäœæã§ããŸãã
ãã®ãããªèããæã£ãã®ã¯ç§ãæåã§ã¯ãããŸããã§ããã ãã©ãŒã©ã ã®æçš¿ã GitHub ã§ã¯ã
ãŸã倧äºãªã®ã¯ããŒã å
$events = Get-WinEvent -LogName "Microsoft-Windows-Sysmon/Operational" | where { $_.id -eq 1 -or $_.id -eq 11}
ã³ãã³ããèªåã§ãã¹ããããå Žåã¯ã$events é åã®æåã®èŠçŽ ã§ãã $events[0].Message ã®å 容ã衚瀺ããããšã§ãéåžžã«åçŽãªåœ¢åŒã®äžé£ã®ããã¹ãæååãåºåã§ããŸãã Sysmon ãã£ãŒã«ããã³ãã³ããã®åŸã«å€ãã®ãã®ã
äžæ³ïŒ Sysmon ãã°ã JSON 察å¿åœ¢åŒã§åºåãã
ããªããç§ãšåãããšãèããŠããŸããïŒ ããå°ãåªåããã°ãåºåã JSON 圢åŒã®æååã«å€æãã匷åãªã³ãã³ãã䜿çšã㊠PS ãªããžã§ã¯ãã«çŽæ¥èªã¿èŸŒãããšãã§ããŸãã
次ã®ããŒãã§ã¯ãå€æçšã® PowerShell ã³ãŒãã瀺ããŸã (éåžžã«ç°¡åã§ã)ã ããã§ã¯ãPS ã¢ãžã¥ãŒã«ãšããŠã€ã³ã¹ããŒã«ãã get-sysmonlogs ãšããæ°ããã³ãã³ãã§äœãã§ããããèŠãŠã¿ãŸãããã
äžäŸ¿ãªã€ãã³ã ãã° ã€ã³ã¿ãŒãã§ã€ã¹ãéã㊠Sysmon ãã°åæãæ·±ãæãäžãã代ããã«ãPowerShell ã»ãã·ã§ã³ããçŽæ¥å¢åã¢ã¯ãã£ããã£ãç°¡åã«æ€çŽ¢ããããPS ã³ãã³ãã䜿çšãããã§ããŸãã
WMI çµç±ã§èµ·åããã cmd ã·ã§ã«ã®ãªã¹ãã ç¬èªã® Get-Sysmonlogs ããŒã ã«ããå®äŸ¡ãªè åšåæ
çŽ æŽãããïŒ Sysmon ãã°ãããŒã¿ããŒã¹ã®ããã«ããŒãªã³ã°ããããŒã«ãäœæããŸããã ç§ãã¡ã®èšäºã§ã¯ã
Sysmonãšã°ã©ãåæ
äžæ©äžãã£ãŠãä»äœæãããã®ã«ã€ããŠèããŠã¿ãŸãããã åºæ¬çã«ãPowerShell ãéã㊠Windows ã€ãã³ã ããŒã¿ããŒã¹ã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸããã åã«è¿°ã¹ãããã«ãParentProcessId ãä»ããŠã¬ã³ãŒãéã«æ¥ç¶ãŸãã¯é¢ä¿ããããããããã»ã¹ã®å®å šãªéå±€ãååŸã§ããŸãã
ã·ãªãŒãºãèªãã ããšã®ããæ¹ãªã
ããããGet-Sysmonlogs ã³ãã³ããšãæ¬æã®åŸåã§èª¬æããè¿œå ã®ããŒã¿æ§é (ãã¡ããã°ã©ã) ã䜿çšãããšãè
åšãæ€åºããå®çšçãªæ¹æ³ãåŸãããŸããå¿
èŠãªã®ã¯ãæ£ããé ç¹æ€çŽ¢ãå®è¡ããããšã ãã§ãã
DYI ããã° ãããžã§ã¯ãã§ã¯åžžã«ããã§ããããã«ãå°èŠæš¡ã§è
åšã®è©³çŽ°ãåæããã°ããã»ã©ããšã³ã¿ãŒãã©ã€ãº ã¬ãã«ã§ã®è
åšã®æ€åºãããã«è€éã§ããããç解ã§ããããã«ãªããŸãã ãããŠããã®æèã¯éåžžã«é«ãã 倧äºãªãã€ã³ã.
ãã®èšäºã®åŸåã§ã¯ãæåã®èå³æ·±ãè€éãªåé¡ã«ééããŸããããã§ã¯ãSysmon ã€ãã³ããçžäºã«æ¥ç¶ããŠãããè€éãªæ§é ãäœãå§ããŸãã
åºæïŒ habr.com