αžšαž”αŸ€αž”αžŠαŸ‚αž› InTrust αž’αžΆαž…αž‡αž½αž™αž€αžΆαžαŸ‹αž”αž“αŸ’αžαž™αž’αžαŸ’αžšαžΆαž“αŸƒαž€αžΆαžšαž”αŸ‰αž»αž“αž”αŸ‰αž„αž’αž“αž»αž‰αŸ’αž‰αžΆαžαžŠαŸ‚αž›αž”αžšαžΆαž‡αŸαž™αžαžΆαž˜αžšαž™αŸˆ RDP

αžšαž”αŸ€αž”αžŠαŸ‚αž› InTrust αž’αžΆαž…αž‡αž½αž™αž€αžΆαžαŸ‹αž”αž“αŸ’αžαž™αž’αžαŸ’αžšαžΆαž“αŸƒαž€αžΆαžšαž”αŸ‰αž»αž“αž”αŸ‰αž„αž’αž“αž»αž‰αŸ’αž‰αžΆαžαžŠαŸ‚αž›αž”αžšαžΆαž‡αŸαž™αžαžΆαž˜αžšαž™αŸˆ RDP

αž“αžšαžŽαžΆαž˜αŸ’αž“αžΆαž€αŸ‹αžŠαŸ‚αž›αž”αžΆαž“αž–αŸ’αž™αžΆαž™αžΆαž˜αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž“αž·αž˜αŸ’αž˜αž·αžαž“αŸ…αž€αŸ’αž“αž»αž„αž–αž–αž€ αžŠαžΉαž„αž™αŸ‰αžΆαž„αž…αŸ’αž”αžΆαžŸαŸ‹αžαžΆαž…αŸ’αžšαž€ RDP αžŸαŸ’αžαž„αŸ‹αžŠαžΆαžš αž”αŸ’αžšαžŸαž·αž“αž”αžΎαž”αžΎαž€αž‘αž»αž€ αž“αžΉαž„αžαŸ’αžšαžΌαžœαž”αžΆαž“αžœαžΆαž™αž”αŸ’αžšαž αžΆαžšαžŸαŸ’αž‘αžΎαžšαžαŸ‚αž—αŸ’αž›αžΆαž˜αŸ—αžŠαŸ„αž™αžšαž›αž€αž“αŸƒαž€αžΆαžšαž–αŸ’αž™αžΆαž™αžΆαž˜αž”αž„αŸ’αžαŸ†αž–αžΆαž€αŸ’αž™αžŸαž˜αŸ’αž„αžΆαžαŸ‹αž–αžΈαž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“ IP αž•αŸ’αžŸαŸαž„αŸ—αž‡αž»αŸ†αžœαž·αž‰αž–αž·αž—αž–αž›αŸ„αž€αŸ”

αž“αŸ…αž€αŸ’αž“αž»αž„αž’αžαŸ’αžαž”αž‘αž“αŸαŸ‡αžαŸ’αž‰αž»αŸ†αž“αžΉαž„αž”αž„αŸ’αž αžΆαž‰αž–αžΈαžšαž”αŸ€αž”αž’αŸ’αžœαžΎ αž‘αŸ†αž“αž»αž€αž…αž·αžαŸ’αž αž’αŸ’αž“αž€αž’αžΆαž…αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αž€αžΆαžšαž†αŸ’αž›αžΎαž™αžαž”αžŠαŸ„αž™αžŸαŸ’αžœαŸαž™αž”αŸ’αžšαžœαžαŸ’αžαž·αž…αŸ†αž–αŸ„αŸ‡ brute force αžŠαŸ„αž™αž”αž“αŸ’αžαŸ‚αž˜αž…αŸ’αž”αžΆαž”αŸ‹αžαŸ’αž˜αžΈαž‘αŸ…αž‡αž‰αŸ’αž‡αžΆαŸ†αž„αž—αŸ’αž›αžΎαž„αŸ” InTrust αž‚αžΊ αžœαŸαž‘αž·αž€αžΆ CLM αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž€αžΆαžšαž”αŸ’αžšαž˜αžΌαž› αžœαž·αž—αžΆαž‚ αž“αž·αž„αžšαž€αŸ’αžŸαžΆαž‘αž»αž€αž‘αž·αž“αŸ’αž“αž“αŸαž™αžŠαŸ‚αž›αž˜αž·αž“αž˜αžΆαž“αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’ αžŠαŸ‚αž›αž˜αžΆαž“αž”αŸ’αžšαžαž·αž€αž˜αŸ’αž˜αž€αŸ†αžŽαžαŸ‹αž‡αžΆαž˜αž»αž“αžšαžΆαž”αŸ‹αžšαž™αžšαž½αž…αž‘αŸ…αž αžΎαž™αž…αŸ†αž–αŸ„αŸ‡αž”αŸ’αžšαž—αŸαž‘αž•αŸ’αžŸαŸαž„αŸ—αž“αŸƒαž€αžΆαžšαžœαžΆαž™αž”αŸ’αžšαž αžΆαžšαŸ”

αž“αŸ…αž€αŸ’αž“αž»αž„ Quest InTrust αž’αŸ’αž“αž€αž’αžΆαž…αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αžŸαž€αž˜αŸ’αž˜αž—αžΆαž–αž†αŸ’αž›αžΎαž™αžαž” αž“αŸ…αž–αŸαž›αžŠαŸ‚αž›αž…αŸ’αž”αžΆαž”αŸ‹αžαŸ’αžšαžΌαžœαž”αžΆαž“αž€αŸαŸ‡αŸ” αž–αžΈαž—αŸ’αž“αžΆαž€αŸ‹αž„αžΆαžšαž”αŸ’αžšαž˜αžΌαž›αž€αŸ†αžŽαžαŸ‹αž αŸαžαž» InTrust αž‘αž‘αž½αž›αž”αžΆαž“αžŸαžΆαžšαž’αŸ†αž–αžΈαž€αžΆαžšαž”αŸ‰αž»αž“αž”αŸ‰αž„αž’αž“αž»αž‰αŸ’αž‰αžΆαžαž˜αž·αž“αž”αžΆαž“αžŸαž˜αŸ’αžšαŸαž…αž“αŸ…αž›αžΎαžŸαŸ’αžαžΆαž“αžΈαž™αž€αžΆαžšαž„αžΆαžš αž¬αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž˜αŸαŸ” αžŠαžΎαž˜αŸ’αž”αžΈαž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αž€αžΆαžšαž”αž“αŸ’αžαŸ‚αž˜αž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“ IP αžαŸ’αž˜αžΈαž‘αŸ…αž‡αž‰αŸ’αž‡αžΆαŸ†αž„αž—αŸ’αž›αžΎαž„ αž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαž…αž˜αŸ’αž›αž„αž…αŸ’αž”αžΆαž”αŸ‹αž•αŸ’αž‘αžΆαž›αŸ‹αžαŸ’αž›αž½αž“αžŠαŸ‚αž›αž˜αžΆαž“αžŸαŸ’αžšαžΆαž”αŸ‹αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αžšαž€αž˜αžΎαž›αž€αžΆαžšαž’αž“αž»αž‰αŸ’αž‰αžΆαžαžŠαŸ‚αž›αž”αžšαžΆαž‡αŸαž™αž‡αžΆαž…αŸ’αžšαžΎαž“ αž αžΎαž™αž”αžΎαž€αž…αŸ’αž”αžΆαž”αŸ‹αž…αž˜αŸ’αž›αž„αžšαž”αžŸαŸ‹αžœαžΆαžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž€αŸ‚αžŸαž˜αŸ’αžšαž½αž›αŸ–

αžšαž”αŸ€αž”αžŠαŸ‚αž› InTrust αž’αžΆαž…αž‡αž½αž™αž€αžΆαžαŸ‹αž”αž“αŸ’αžαž™αž’αžαŸ’αžšαžΆαž“αŸƒαž€αžΆαžšαž”αŸ‰αž»αž“αž”αŸ‰αž„αž’αž“αž»αž‰αŸ’αž‰αžΆαžαžŠαŸ‚αž›αž”αžšαžΆαž‡αŸαž™αžαžΆαž˜αžšαž™αŸˆ RDP

αž–αŸ’αžšαžΉαžαŸ’αžαž·αž€αžΆαžšαžŽαŸαž“αŸ…αž€αŸ’αž“αž»αž„αž€αŸ†αžŽαžαŸ‹αž αŸαžαž»αžœαžΈαž“αžŠαžΌαž”αŸ’αžšαžΎαž’αŸ’αžœαžΈαžŠαŸ‚αž›αž‚αŸαž αŸ…αžαžΆ InsertionString αŸ” αž˜αžΎαž›αž€αžΆαžšαž”αŸ’αžšαž€αž½αžαžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž›αŸαžαž€αžΌαžŠαž–αŸ’αžšαžΉαžαŸ’αžαž·αž€αžΆαžšαžŽαŸ 4625 (αž“αŸαŸ‡αž‚αžΊαž‡αžΆαž€αžΆαžšαž…αžΌαž›αž”αŸ’αžšαž–αŸαž“αŸ’αž’αžŠαŸ‚αž›αž˜αž·αž“αž‡αŸ„αž‚αž‡αŸαž™) αž αžΎαž™αž’αŸ’αž“αž€αž“αžΉαž„αžƒαžΎαž‰αžαžΆαžœαžΆαž›αžŠαŸ‚αž›αž™αžΎαž„αž…αžΆαž”αŸ‹αž’αžΆαžšαž˜αŸ’αž˜αžŽαŸαžαŸ’αžšαžΌαžœαž”αžΆαž“αžšαž€αŸ’αžŸαžΆαž‘αž»αž€αž“αŸ…αž€αŸ’αž“αž»αž„ InsertionString14 (αžˆαŸ’αž˜αŸ„αŸ‡αž€αž“αŸ’αž›αŸ‚αž„αž’αŸ’αžœαžΎαž€αžΆαžš) αž“αž·αž„ InsertionString20 (αž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“αž”αžŽαŸ’αžαžΆαž‰αž”αŸ’αžšαž—αž–)αŸ” αž“αŸ…αž–αŸαž›αžœαžΆαž™αž”αŸ’αžšαž αžΆαžšαž–αžΈαž’αŸŠαžΈαž“αž’αžΊαžŽαž·αž αžœαžΆαž›αžˆαŸ’αž˜αŸ„αŸ‡αžŸαŸ’αžαžΆαž“αžΈαž™αž€αžΆαžšαž„αžΆαžšαž“αžΉαž„αž‘αŸ†αž“αž„αž—αžΆαž‚αž…αŸ’αžšαžΎαž“αŸ” αž‘αž‘αŸ αžŠαžΌαž…αŸ’αž“αŸαŸ‡αž€αž“αŸ’αž›αŸ‚αž„αž“αŸαŸ‡αž˜αžΆαž“αžŸαžΆαžšαŸˆαžŸαŸ†αžαžΆαž“αŸ‹αž‡αŸ†αž“αž½αžŸαžαž˜αŸ’αž›αŸƒαž–αžΈαž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“αž”αžŽαŸ’αžαžΆαž‰αž”αŸ’αžšαž—αž–αŸ”

αž“αŸαŸ‡αž‚αžΊαž‡αžΆαž’αŸ’αžœαžΈαžŠαŸ‚αž›αž’αžαŸ’αžαž”αž‘αž“αŸƒαž–αŸ’αžšαžΉαžαŸ’αžαž·αž€αžΆαžšαžŽαŸ 4625 αž˜αžΎαž›αž‘αŸ…αžŠαžΌαž…αž“αŸαŸ‡:

An account failed to log on.
Subject:
	Security ID:		S-1-5-21-1135140816-2109348461-2107143693-500
	Account Name:		ALebovsky
	Account Domain:		LOGISTICS
	Logon ID:		0x2a88a
Logon Type:			2
Account For Which Logon Failed:
	Security ID:		S-1-0-0
	Account Name:		Paul
	Account Domain:		LOGISTICS
Failure Information:
	Failure Reason:		Account locked out.
	Status:			0xc0000234
	Sub Status:		0x0
Process Information:
	Caller Process ID:	0x3f8
	Caller Process Name:	C:WindowsSystem32svchost.exe
Network Information:
	Workstation Name:	DCC1
	Source Network Address:	::1
	Source Port:		0
Detailed Authentication Information:
	Logon Process:		seclogo
	Authentication Package:	Negotiate
	Transited Services:	-
	Package Name (NTLM only):	-
	Key Length:		0
This event is generated when a logon request fails. It is generated on the computer where access was attempted.
The Subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.
The Logon Type field indicates the kind of logon that was requested. The most common types are 2 (interactive) and 3 (network).
The Process Information fields indicate which account and process on the system requested the logon.
The Network Information fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.
The authentication information fields provide detailed information about this specific logon request.
	- Transited services indicate which intermediate services have participated in this logon request.
	- Package name indicates which sub-protocol was used among the NTLM protocols.
	- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.

αž›αžΎαžŸαž–αžΈαž“αŸαŸ‡ αž™αžΎαž„αž“αžΉαž„αž”αž“αŸ’αžαŸ‚αž˜αžαž˜αŸ’αž›αŸƒαž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“αž”αžŽαŸ’αžαžΆαž‰αž”αŸ’αžšαž—αž–αž‘αŸ…αž’αžαŸ’αžαž”αž‘αž–αŸ’αžšαžΉαžαŸ’αžαž·αž€αžΆαžšαžŽαŸαŸ”

αžšαž”αŸ€αž”αžŠαŸ‚αž› InTrust αž’αžΆαž…αž‡αž½αž™αž€αžΆαžαŸ‹αž”αž“αŸ’αžαž™αž’αžαŸ’αžšαžΆαž“αŸƒαž€αžΆαžšαž”αŸ‰αž»αž“αž”αŸ‰αž„αž’αž“αž»αž‰αŸ’αž‰αžΆαžαžŠαŸ‚αž›αž”αžšαžΆαž‡αŸαž™αžαžΆαž˜αžšαž™αŸˆ RDP

αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž˜αž€αž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαž”αž“αŸ’αžαŸ‚αž˜αžŸαŸ’αž‚αŸ’αžšαžΈαž”αžŠαŸ‚αž›αž“αžΉαž„αžšαžΆαžšαžΆαŸ†αž„αž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“ IP αž“αŸ…αž€αŸ’αž“αž»αž„ Windows Firewall αŸ” αžαžΆαž„αž€αŸ’αžšαŸ„αž˜αž“αŸαŸ‡αž‡αžΆαž§αž‘αžΆαž αžšαžŽαŸαžŠαŸ‚αž›αž’αžΆαž…αž”αŸ’αžšαžΎαž”αžΆαž“αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αžšαžΏαž„αž“αŸαŸ‡αŸ”

αžŸαŸ’αž‚αŸ’αžšαžΈαž”αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αžŠαŸ†αž‘αžΎαž„αž‡αž‰αŸ’αž‡αžΆαŸ†αž„αž—αŸ’αž›αžΎαž„

param(
         [Parameter(Mandatory = $true)]
         [ValidateNotNullOrEmpty()]   
         [string]
         $SourceAddress
)

$SourceAddress = $SourceAddress.Trim()
$ErrorActionPreference = 'Stop'
$ruleName = 'Quest-InTrust-Block-Failed-Logons'
$ruleDisplayName = 'Quest InTrust: Blocks IP addresses from failed logons'

function Get-BlockedIps {
    (Get-NetFirewallRule -Name $ruleName -ErrorAction SilentlyContinue | get-netfirewalladdressfilter).RemoteAddress
}

$blockedIps = Get-BlockedIps
$allIps = [array]$SourceAddress + [array]$blockedIps | Select-Object -Unique | Sort-Object

if (Get-NetFirewallRule -Name $ruleName -ErrorAction SilentlyContinue) {
    Set-NetFirewallRule -Name $ruleName -RemoteAddress $allIps
} else {
    New-NetFirewallRule -Name $ruleName -DisplayName $ruleDisplayName -Direction Inbound -Action Block -RemoteAddress $allIps
}

αž₯αž‘αžΌαžœαž“αŸαŸ‡ αž’αŸ’αž“αž€αž’αžΆαž…αž”αŸ’αžαžΌαžšαžˆαŸ’αž˜αŸ„αŸ‡αž…αŸ’αž”αžΆαž”αŸ‹ αž“αž·αž„αž€αžΆαžšαž–αž·αž–αžŽαŸŒαž“αžΆ αžŠαžΎαž˜αŸ’αž”αžΈαž‡αŸ€αžŸαžœαžΆαž„αž€αžΆαžšαž—αžΆαž“αŸ‹αž…αŸ’αžšαž›αŸ†αž“αŸ…αž–αŸαž›αž€αŸ’αžšαŸ„αž™αŸ”

αžšαž”αŸ€αž”αžŠαŸ‚αž› InTrust αž’αžΆαž…αž‡αž½αž™αž€αžΆαžαŸ‹αž”αž“αŸ’αžαž™αž’αžαŸ’αžšαžΆαž“αŸƒαž€αžΆαžšαž”αŸ‰αž»αž“αž”αŸ‰αž„αž’αž“αž»αž‰αŸ’αž‰αžΆαžαžŠαŸ‚αž›αž”αžšαžΆαž‡αŸαž™αžαžΆαž˜αžšαž™αŸˆ RDP

αž₯αž‘αžΌαžœαž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαž”αž“αŸ’αžαŸ‚αž˜αžŸαŸ’αž‚αŸ’αžšαžΈαž”αž“αŸαŸ‡αž‡αžΆαžŸαž€αž˜αŸ’αž˜αž—αžΆαž–αž†αŸ’αž›αžΎαž™αžαž”αž‘αŸ…αž“αžΉαž„αž…αŸ’αž”αžΆαž”αŸ‹ αž”αžΎαž€αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαž…αŸ’αž”αžΆαž”αŸ‹ αž“αž·αž„αž’αžΆαž“αžΆαžαžΆαž…αŸ’αž”αžΆαž”αŸ‹αžŠαŸ‚αž›αžαŸ’αžšαžΌαžœαž‚αŸ’αž“αžΆαžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αžΎαž€αž“αŸ…αž€αŸ’αž“αž»αž„αž‚αŸ„αž›αž€αžΆαžšαžŽαŸαžαŸ’αžšαž½αžαž–αž·αž“αž·αžαŸ’αž™αž–αŸαž›αžœαŸαž›αžΆαž‡αžΆαž€αŸ‹αžŸαŸ’αžαŸ‚αž„αŸ” αž—αŸ’αž“αžΆαž€αŸ‹αž„αžΆαžšαžαŸ’αžšαžΌαžœαžαŸ‚αžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αžΎαž€αžŠαžΎαž˜αŸ’αž”αžΈαžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαžŸαŸ’αž‚αŸ’αžšαžΈαž”αž†αŸ’αž›αžΎαž™αžαž” αž αžΎαž™αžαŸ’αžšαžΌαžœαžαŸ‚αž˜αžΆαž“αž”αŸ‰αžΆαžšαŸ‰αžΆαž˜αŸ‰αŸ‚αžαŸ’αžšαžαŸ’αžšαžΉαž˜αžαŸ’αžšαžΌαžœαžŠαŸ‚αž›αž”αžΆαž“αž”αž‰αŸ’αž‡αžΆαž€αŸ‹αŸ”

αžšαž”αŸ€αž”αžŠαŸ‚αž› InTrust αž’αžΆαž…αž‡αž½αž™αž€αžΆαžαŸ‹αž”αž“αŸ’αžαž™αž’αžαŸ’αžšαžΆαž“αŸƒαž€αžΆαžšαž”αŸ‰αž»αž“αž”αŸ‰αž„αž’αž“αž»αž‰αŸ’αž‰αžΆαžαžŠαŸ‚αž›αž”αžšαžΆαž‡αŸαž™αžαžΆαž˜αžšαž™αŸˆ RDP

αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αž‰αŸ’αž…αž”αŸ‹ αž…αŸ†αž“αž½αž“αž“αŸƒαž€αžΆαžšαž’αž“αž»αž‰αŸ’αž‰αžΆαžαžŠαŸ‚αž›αž˜αž·αž“αž‡αŸ„αž‚αž‡αŸαž™αž”αžΆαž“αžαž™αž…αž»αŸ‡ 80%αŸ” αž…αŸ†αžŽαŸαž‰? αž’αžŸαŸ’αž…αžΆαžšαŸ’αž™β€‹αžŽαžΆαžŸαŸ‹!

αžšαž”αŸ€αž”αžŠαŸ‚αž› InTrust αž’αžΆαž…αž‡αž½αž™αž€αžΆαžαŸ‹αž”αž“αŸ’αžαž™αž’αžαŸ’αžšαžΆαž“αŸƒαž€αžΆαžšαž”αŸ‰αž»αž“αž”αŸ‰αž„αž’αž“αž»αž‰αŸ’αž‰αžΆαžαžŠαŸ‚αž›αž”αžšαžΆαž‡αŸαž™αžαžΆαž˜αžšαž™αŸˆ RDP

αž‡αž½αž“αž€αžΆαž›αž€αžΆαžšαž€αžΎαž“αž‘αžΎαž„αžαž·αž…αžαž½αž…αž€αžΎαžαž‘αžΎαž„αž˜αŸ’αžαž„αž‘αŸ€αž αž”αŸ‰αž»αž“αŸ’αžαŸ‚αž“αŸαŸ‡αž‚αžΊαžŠαŸ„αž™αžŸαžΆαžšαžαŸ‚αž€αžΆαžšαž›αŸαž…αž‘αžΎαž„αž“αŸƒαž”αŸ’αžšαž—αž–αžαŸ’αž˜αžΈαž“αŸƒαž€αžΆαžšαžœαžΆαž™αž”αŸ’αžšαž αžΆαžšαŸ” αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž˜αž€αž’αŸ’αžœαžΈαž‚αŸ’αžšαž”αŸ‹αž™αŸ‰αžΆαž„αž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜αž’αŸ’αž›αžΆαž€αŸ‹αž…αž»αŸ‡αž˜αŸ’αžαž„αž‘αŸ€αžαŸ”

αž€αŸ’αž“αž»αž„αžšαž™αŸˆαž–αŸαž›αž˜αž½αž™αžŸαž”αŸ’αžαžΆαž αŸαž“αŸƒαž€αžΆαžšαž„αžΆαžš αž’αžΆαžŸαž™αžŠαŸ’αž‹αžΆαž“ IP αž…αŸ†αž“αž½αž“ 66 αžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αž“αŸ’αžαŸ‚αž˜αž‘αŸ…αž€αŸ’αž“αž»αž„αž…αŸ’αž”αžΆαž”αŸ‹αž‡αž‰αŸ’αž‡αžΆαŸ†αž„αž—αŸ’αž›αžΎαž„αŸ”

αžšαž”αŸ€αž”αžŠαŸ‚αž› InTrust αž’αžΆαž…αž‡αž½αž™αž€αžΆαžαŸ‹αž”αž“αŸ’αžαž™αž’αžαŸ’αžšαžΆαž“αŸƒαž€αžΆαžšαž”αŸ‰αž»αž“αž”αŸ‰αž„αž’αž“αž»αž‰αŸ’αž‰αžΆαžαžŠαŸ‚αž›αž”αžšαžΆαž‡αŸαž™αžαžΆαž˜αžšαž™αŸˆ RDP

αžαžΆαž„αž€αŸ’αžšαŸ„αž˜αž“αŸαŸ‡αž‚αžΊαž‡αžΆαžαžΆαžšαžΆαž„αžŠαŸ‚αž›αž˜αžΆαž“αžˆαŸ’αž˜αŸ„αŸ‡αž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αž‘αžΌαž‘αŸ…αž…αŸ†αž“αž½αž“ 10 αžŠαŸ‚αž›αžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αŸ’αžšαžΎαžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž€αžΆαžšαž–αŸ’αž™αžΆαž™αžΆαž˜αž’αž“αž»αž‰αŸ’αž‰αžΆαžαŸ”

αžˆαŸ’αž˜αŸ„αŸ‡αž’αŸ’αž“αž€αž”αŸ’αžšαžΎ

αž…αŸ†αž“αž½αž“

αž‡αžΆαž—αžΆαž‚αžšαž™

αž’αŸ’αž“αž€αž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαž„

1220235

40.78

αž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαž„

672109

22.46

αž’αŸ’αž“αž€β€‹αž”αŸ’αžšαžΎ

219870

7.35

αž€αž»αž„αžαžΌαžŸαžΌ

126088

4.21

contoso.com

73048

2.44

αž’αŸ’αž“αž€αž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαž„

55319

1.85

αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž”αž˜αŸ’αžšαžΎ

39403

1.32

sgazlabdc01.contoso.com

32177

1.08

αž’αŸ’αž“αž€αž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαž„

32377

1.08

sgazlabdc01

31259

1.04

αž”αŸ’αžšαžΆαž”αŸ‹αž™αžΎαž„αž“αŸ…αž€αŸ’αž“αž»αž„αž˜αžαž·αž™αŸ„αž”αž›αŸ‹αž–αžΈαžšαž”αŸ€αž”αžŠαŸ‚αž›αž’αŸ’αž“αž€αž†αŸ’αž›αžΎαž™αžαž”αž‘αŸ…αž“αžΉαž„αž€αžΆαžšαž‚αŸ†αžšαžΆαž˜αž€αŸ†αž αŸ‚αž„αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αž–αŸαžαŸŒαž˜αžΆαž“αŸ” αžαžΎβ€‹αž”αŸ’αžšαž–αŸαž“αŸ’αž’β€‹αž’αŸ’αžœαžΈβ€‹αžŠαŸ‚αž›β€‹αž’αŸ’αž“αž€β€‹αž”αŸ’αžšαžΎ αž αžΎαž™β€‹αžœαžΆβ€‹αž„αžΆαž™αžŸαŸ’αžšαž½αž›β€‹αž”αŸ‰αž»αžŽαŸ’αžŽαžΆ?

αž”αŸ’αžšαžŸαž·αž“αž”αžΎαž’αŸ’αž“αž€αž…αžΆαž”αŸ‹αž’αžΆαžšαž˜αŸ’αž˜αžŽαŸαž…αž„αŸ‹αžƒαžΎαž‰ InTrust αž“αŸ…αž€αŸ’αž“αž»αž„αžŸαž€αž˜αŸ’αž˜αž—αžΆαž–, αž‘αž»αž€αžŸαŸ†αžŽαžΎαž˜αž½αž™αŸ” αž“αŸ…αž€αŸ’αž“αž»αž„αž‘αž˜αŸ’αžšαž„αŸ‹αž˜αžαž·αžαŸ’αžšαž‘αž”αŸ‹αž“αŸ…αž›αžΎαž‚αŸαž αž‘αŸ†αž–αŸαžšαžšαž”αžŸαŸ‹αž™αžΎαž„ αž¬αžŸαžšαžŸαŸαžšαž˜αž€αžαŸ’αž‰αž»αŸ†αž€αŸ’αž“αž»αž„αžŸαžΆαžšαž•αŸ’αž‘αžΆαž›αŸ‹αžαŸ’αž›αž½αž“αŸ”

αžŸαžΌαž˜αž’αžΆαž“αž’αžαŸ’αžαž”αž‘αž•αŸ’αžŸαŸαž„αž‘αŸ€αžαžšαž”αžŸαŸ‹αž™αžΎαž„αžŸαŸ’αžαžΈαž–αžΈαžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αž–αŸαžαŸŒαž˜αžΆαž“αŸ–

αž™αžΎαž„αžšαž€αžƒαžΎαž‰αž€αžΆαžšαžœαžΆαž™αž”αŸ’αžšαž αžΆαžš ransomware αž…αžΌαž›αž”αŸ’αžšαžΎαž§αž”αž€αžšαžŽαŸαž”αž‰αŸ’αž‡αžΆαžŠαŸ‚αž“ αž“αž·αž„αž–αŸ’αž™αžΆαž™αžΆαž˜αž‘αž”αŸ‹αž‘αž›αŸ‹αž“αžΉαž„αž€αžΆαžšαžœαžΆαž™αž”αŸ’αžšαž αžΆαžšαž‘αžΆαŸ†αž„αž“αŸαŸ‡

αžαžΎαž’αŸ’αžœαžΈαžŠαŸ‚αž›αž˜αžΆαž“αž”αŸ’αžšαž™αŸ„αž‡αž“αŸαž’αžΆαž…αžαŸ’αžšαžΌαžœαž”αžΆαž“αžŸαŸ’αžšαž„αŸ‹αž…αŸαž‰αž–αžΈαž€αŸ†αžŽαžαŸ‹αž αŸαžαž»αž“αŸƒαžŸαŸ’αžαžΆαž“αžΈαž™αž€αžΆαžšαž„αžΆαžšαžŠαŸ‚αž›αž˜αžΆαž“αž˜αžΌαž›αžŠαŸ’αž‹αžΆαž“αž›αžΎαžœαžΈαž“αžŠαžΌ? (αž’αžαŸ’αžαž”αž‘αž–αŸαž‰αž“αž·αž™αž˜)

αžαžΆαž˜αžŠαžΆαž“αžœαžŠαŸ’αžαž‡αžΈαžœαž·αžαžšαž”αžŸαŸ‹αž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αžŠαŸ„αž™αž‚αŸ’αž˜αžΆαž“αžŠαž„αŸ’αž€αŸ€αž” αž¬αž€αžΆαžŸαŸ‚αžαž”αŸ†αž–αž„αŸ‹

αžαžΎαž’αŸ’αž“αž€αžŽαžΆαž”αžΆαž“αž’αŸ’αžœαžΎ? αž™αžΎαž„αž’αŸ’αžœαžΎαžŸαžœαž“αž€αž˜αŸ’αž˜αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αž–αŸαžαŸŒαž˜αžΆαž“αžŠαŸ„αž™αžŸαŸ’αžœαŸαž™αž”αŸ’αžšαžœαžαŸ’αžαž·

αžšαž”αŸ€αž”αž€αžΆαžαŸ‹αž”αž“αŸ’αžαž™αžαŸ’αž›αŸƒαžŠαžΎαž˜αž“αŸƒαž—αžΆαž–αž‡αžΆαž˜αŸ’αž…αžΆαžŸαŸ‹αž“αŸƒαž”αŸ’αžšαž–αŸαž“αŸ’αž’ SIEM αž“αž·αž„αž αŸαžαž»αž’αŸ’αžœαžΈαž”αžΆαž“αž‡αžΆαž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαž€αžΆαžš Central Log Management (CLM)

αž”αŸ’αžšαž—αž–: www.habr.com

αž”αž“αŸ’αžαŸ‚αž˜αž˜αžαž·αž™αŸ„αž”αž›αŸ‹