Sysmon Threat Analysis Guide, ื˜ื™ื™ืœ 1

Sysmon Threat Analysis Guide, ื˜ื™ื™ืœ 1

ื“ืขืจ ืึทืจื˜ื™ืงืœ ืื™ื– ื“ืขืจ ืขืจืฉื˜ืขืจ ื˜ื™ื™ืœ ืคื•ืŸ ืึท ืกืขืจื™ืข ืื•ื™ืฃ Sysmon ืกืึทืงืึธื ืข ืึทื ืึทืœื™ืกื™ืก. ืึทืœืข ืื ื“ืขืจืข ื˜ื™ื™ืœืŸ ืคื•ืŸ ื“ืขืจ ืกืขืจื™ืข:

ื˜ื™ื™ืœ 1: ื”ืงื“ืžื” ืฆื• Sysmon ืœืึธื’ ืึทื ืึทืœื™ืกื™ืก (ืื•ื ื– ื–ืขื ืขืŸ ื“ื)
ื˜ื™ื™ืœ 2: ื ื™ืฆืŸ Sysmon Event Data ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ื˜ืจืขืฅ
ื˜ื™ื™ืœ 3. ืื™ืŸ-ื˜ื™ืคืงื™ื™ึทื˜ ืึทื ืึทืœื™ืกื™ืก ืคื•ืŸ Sysmon ื˜ืจืขืฅ ื ื™ืฆืŸ ื’ืจืึทืคืก

ืื•ื™ื‘ ืื™ืจ ืึทืจื‘ืขื˜ ืื™ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื–ื™ื›ืขืจื”ื™ื™ื˜, ืื™ืจ ืžื™ืกื˜ืึธืžืข ืึธืคื˜ ื”ืึธื‘ืŸ ืฆื• ืคึฟืึทืจืฉื˜ื™ื™ืŸ ืึธื ื’ืึธื™ื ื’ ืื ืคืืœืŸ. ืื•ื™ื‘ ืื™ืจ ืฉื•ื™ืŸ ื”ืึธื‘ืŸ ืึท ื˜ืจื™ื™ื ื“ ืื•ื™ื’, ืื™ืจ ืงืขื ืขืŸ ืงื•ืงืŸ ืคึฟืึทืจ ื ื™ื˜-ื ืึธืจืžืึทืœ ื˜ืขื˜ื™ืงื™ื™ื˜ ืื™ืŸ ื“ื™ "ืจื•ื™" ืึทื ืคึผืจืึทืกืขืกื˜ ืœืึธื’ืก - ื–ืึธื’ืŸ, ืึท PowerShell ืฉืจื™ืคื˜ ืคืœื™ืกื ื“ื™ืง ืžื™ื˜ ื“ื™ DownloadString ื‘ืึทืคึฟืขืœ ืื“ืขืจ ื VBS ืกืงืจื™ืคื˜ ืคืืจืฉื˜ืขืœื˜ ืืœืก ื ื•ื•ืืจื“ ื˜ืขืงืข - ืคืฉื•ื˜ ื“ื•ืจืš ืกืงืจืืœืŸ ื“ื•ืจืš ื“ื™ ืœืขืฆื˜ืข ื˜ืขื˜ื™ืงื™ื™ื˜ ืื™ืŸ ื“ื™ ื’ืขืฉืขืขื ื™ืฉ ืœืื’ Windowsืื‘ืขืจ ื“ืึธืก ืื™ื– ืึทืŸ ืขื›ื˜ืขืจ ืงืึธืคึผื•ื•ื™ื™ื˜ื™ืง. ืฆื•ืž ื’ืœื™ืง, ื”ืึธื˜ ืžื™ื™ืงืจืึธืกืึธืคึฟื˜ ื‘ืึทืฉืึทืคึฟืŸ ืกื™ืกืžืึธืŸ, ื•ื•ืึธืก ืžืึทื›ื˜ ืึทื˜ืึทืง ืึทื ืึทืœื™ื– ืคื™ืœ ื’ืจื™ื ื’ืขืจ.

ื•ื•ื™ืœืŸ ืฆื• ืคึฟืึทืจืฉื˜ื™ื™ืŸ ื“ื™ ื™ืงืขืจื“ื™ืง ื’ืขื“ืื ืงืขืŸ ื”ื™ื ื˜ืขืจ ื“ื™ ื˜ืจืขืฅ ื’ืขื•ื•ื™ื–ืŸ ืื™ืŸ ื“ื™ Sysmon ืงืœืึธืฅ? ืืจืืคืงืืคื™ืข ืื•ื ื“ื–ืขืจ ืคื™ืจืขืจ WMI events ื•ื•ื™ ืึท ืžื™ื˜ืœ ืคื•ืŸ ืกืคึผื™ื™ื™ื ื’ ืื•ืŸ ืื™ืจ ืจืขืึทืœื™ื–ื™ืจื˜ ื•ื•ื™ ืื™ื ืกื™ื™ื“ืขืจืก ืงืขื ืขืŸ ื’ืขื”ื™ื™ื ืžืึธื ื™ื˜ืึธืจื™ืจืŸ ืึทื ื“ืขืจืข ืขืžืคึผืœื•ื™ื™ื–. ื“ื™ ื”ื•ื™ืคึผื˜ ืคึผืจืึธื‘ืœืขื ืžื™ื˜ ืืจื‘ืขื˜ืŸ ืžื™ื˜ืŸ ื’ืขืฉืขืขื ื™ืฉ ืœืึธื’. Windows ื“ื™ ืคืจืื‘ืœืขื ืื™ื– ื“ืขืจ ืžืื ื’ืœ ืื™ืŸ ืื™ื ืคืืจืžืืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ืขืœื˜ืขืจืŸ ืคืจืืฆืขืกืŸ, ื•ื•ืืก ืžื™ื™ื ื˜ ืื– ืก'ืื™ื– ืื•ืžืžืขื’ืœืขืš ืฆื• ืคืืจืฉื˜ื™ื™ืŸ ื“ื™ ืคืจืืฆืขืก ื›ื™ื™ืขืจืืจื›ื™ืข. ืกื™ืกืžืืŸ ืœืื’ ืื™ื™ื ื˜ืจืื’ืขืก, ืคื•ืŸ ื“ืขืจ ืื ื“ืขืจืขืจ ื–ื™ื™ื˜, ืื ื˜ื”ืืœื˜ืŸ ื“ื™ ืขืœื˜ืขืจืŸ ืคืจืืฆืขืก ืื™ื“ืขื ื˜ื™ืคื™ืงืืฆื™ืข, ื–ื™ื™ืŸ ื ืืžืขืŸ, ืื•ืŸ ื“ื™ ืงืืžืื ื“ ืœื™ื ื™ืข ื•ื•ืืก ื•ื•ืขืจื˜ ื’ืขืœืืคืŸ. ื ื“ืื ืง, ืžื™ื™ืงืจืืกืืคื˜.

ืื™ืŸ ื“ืขืจ ืขืจืฉื˜ืขืจ ื˜ื™ื™ืœ ืคื•ืŸ ืื•ื ื“ื–ืขืจ ืกืขืจื™ืข, ืžื™ืจ ื•ื•ืขืœืŸ ืงื•ืงืŸ ืื™ืŸ ื•ื•ืึธืก ืื™ืจ ืงืขื ืขืŸ ื˜ืึธืŸ ืžื™ื˜ ื™ืงืขืจื“ื™ืง ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืคึฟื•ืŸ Sysmon. ืื™ืŸ ื˜ื™ื™ืœ XNUMX, ืžื™ืจ ื•ื•ืขืœืŸ ื ื•ืฆืŸ ื“ื™ ืคืึธื˜ืขืจ ืคึผืจืึธืฆืขืก ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืฆื• ืฉืึทืคึฟืŸ ืžืขืจ ืงืึธืžืคึผืœื™ืฆื™ืจื˜ ื”ืขืกืงืขื ืกื˜ืจืึทืงื˜ืฉืขืจื– ื‘ืืงืื ื˜ ื•ื•ื™ ืกืึทืงืึธื ืข ื’ืจืึทืคืก. ืื™ืŸ ื“ื™ ื“ืจื™ื˜ ื˜ื™ื™ืœ, ืžื™ืจ ื•ื•ืขืœืŸ ืงื•ืงืŸ ืื™ืŸ ืึท ืคึผืฉื•ื˜ ืึทืœื’ืขืจื™ื“ืึทื ื•ื•ืึธืก ืกืงืึทื ื– ืึท ืกืึทืงืึธื ืข ื’ืจืึทืคื™ืง ืฆื• ื–ื•ื›ืŸ ืคึฟืึทืจ ื•ืžื’ืขื•ื•ื™ื™ื ื˜ืœืขืš ื˜ืขื˜ื™ืงื™ื™ื˜ ื“ื•ืจืš ืึทื ืึทืœื™ื™ื–ื™ื ื’ ื“ื™ "ื•ื•ืึธื’" ืคื•ืŸ ื“ื™ ื’ืจืึทืคื™ืง. ืื•ืŸ ืื™ืŸ ื“ื™ ืกื•ืฃ, ืื™ืจ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืจื™ื•ื•ืึธืจื“ื™ื“ ืžื™ื˜ ืึท ืฆื™ื›ื˜ื™ืง (ืื•ืŸ ืคืึทืจืฉื˜ื™ื™ื™ืง) ืคึผืจืึธื‘ืึทื‘ื™ืœื™ืกื˜ื™ืง ืกืึทืงืึธื ืข ื“ื™ื˜ืขืงืฉืึทืŸ ืื•ืคึฟืŸ.

ื˜ื™ื™ืœ 1: ื”ืงื“ืžื” ืฆื• Sysmon ืœืึธื’ ืึทื ืึทืœื™ืกื™ืก

ื•ื•ืึธืก ืงืขื ืขืŸ ื”ืขืœืคึฟืŸ ืื™ืจ ืคึฟืึทืจืฉื˜ื™ื™ืŸ ื“ื™ ืงืึทืžืคึผืœืขืงืกื™ื˜ื™ื– ืคื•ืŸ ื“ื™ ื’ืขืฉืขืขื ื™ืฉ ืงืœืึธืฅ? ืœืขืกืึธืฃ - SIEM. ืขืก ื ืึธืจืžืึทืœื™ื™ื–ื™ื– ื’ืขืฉืขืขื ื™ืฉืŸ ืื•ืŸ ืกื™ืžืคึผืœืึทืคื™ื™ื– ื–ื™ื™ืขืจ ืกืึทื‘ืกืึทืงื•ื•ืึทื ื˜ ืึทื ืึทืœื™ืกื™ืก. ืื‘ืขืจ ืžื™ืจ ื“ืืจืคืŸ ื ื™ืฉื˜ ื’ื™ื™ืŸ ืื–ื•ื™ ื•ื•ื™ื™ื˜, ืืžื•ื•ื™ื™ื ื™ื’ืกื˜ื ืก ื ื™ืฉื˜ ืขืจืฉื˜. ืื™ืŸ ื“ื™ ืึธื ื”ื™ื™ื‘, ืฆื• ืคึฟืึทืจืฉื˜ื™ื™ืŸ ื“ื™ ืคึผืจื™ื ืกืึทืคึผืึทืœื– ืคื•ืŸ SIEM, ืขืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขื ื•ื’ ืฆื• ืคึผืจื•ื‘ื™ืจืŸ ื“ื™ ื•ื•ื•ื ื“ืขืจืœืขืš ืคืจื™ื™ Sysmon ื ื•ืฆืŸ. ืื•ืŸ ื–ื™ ืื™ื– ืกืึทืคึผืจื™ื™ื–ื™ื ื’ืœื™ ื’ืจื™ื ื’ ืฆื• ืึทืจื‘ืขื˜ืŸ ืžื™ื˜. ื”ืึทืœื˜ืŸ ืขืก ืึทืจื•ื™ืฃ, ืžื™ื™ืงืจืึธืกืึธืคึฟื˜!

ื•ื•ืึธืก ืคึฟืขื™ึดืงื™ื™ื˜ืŸ ื”ืื˜ Sysmon?

ืงื•ืจืฅ ื’ืขื–ืื’ื˜, ืขืก ื’ื™ื˜ ื ื•ืฆืœืขื›ืข ืื•ืŸ ืœื™ื™ื ืขื ืข ืื™ื ืคืืจืžืืฆื™ืข ื•ื•ืขื’ืŸ ืคืจืืฆืขืกืŸ (ื–ืขื” ื‘ื™ืœื“ืขืจ ืื•ื ื˜ืŸ). ืื™ืจ ื•ื•ืขื˜ ื’ืขืคึฟื™ื ืขืŸ ื ื˜ืึธืŸ ื ื•ืฆืœืขื›ืข ืคืจื˜ื™ื ื•ื•ืึธืก ืžืขืŸ ื’ืขืคึฟื™ื ื˜ ื ื™ืฉื˜ ืื™ืŸ ื“ืขื ื’ืขืฉืขืขื ื™ืฉ ืœืึธื’. Windows, ืื‘ืขืจ ื“ื™ ื•ื•ื™ื›ื˜ื™ื’ืกื˜ืข ื–ืขื ืขืŸ ื“ื™ ืคืืœื’ื ื“ืข ืคืขืœื“ืขืจ:

  • ืคึผืจืึธืฆืขืก ืฉื™ื™ึทืŸ (ืื™ืŸ ื“ืขืฆื™ืžืึทืœ, ื ื™ืฉื˜ ื”ืขืงืก!)
  • ืคึผืึทืจืขื ื˜ ืคึผืจืึธืฆืขืก ืฉื™ื™ึทืŸ
  • ืคึผืจืึธืฆืขืก ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื”
  • ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื” ืคื•ืŸ ื“ืขืจ ืคืึธื˜ืขืจ ืคึผืจืึธืฆืขืก
  • ื˜ืขืงืข ื‘ื™ืœื“ ื”ืึทืฉ
  • ื˜ืขืงืข ื‘ื™ืœื“ ื ืขืžืขืŸ

Sysmon ืื™ื– ืื™ื ืกื˜ืึทืœื™ืจืŸ ื‘ื™ื™ื“ืข ื•ื•ื™ ืึท ืžื™ื˜ืœ ื“ืจื™ื™ื•ื•ืขืจ ืื•ืŸ ื•ื•ื™ ืึท ื“ื™ื ืกื˜ - ืžืขืจ ื“ืขื˜ืึทื™ืœืก ื“ืึธ. ื–ื™ื™ึทืŸ ื”ื•ื™ืคึผื˜ ืžื™ื™ึทืœืข ืื™ื– ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืคื•ื ืึทื ื“ืขืจืงืœื™ื™ึทื‘ืŸ ืœืึธื’ืก ืคื•ืŸ ืขื˜ืœืขื›ืข ืงื•ื•ืืœืŸ, ืงืึธืจืึทืœื™ื™ืฉืึทืŸ ืคื•ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืื•ืŸ ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ืจื™ื–ืึทืœื˜ื™ื ื’ ื•ื•ืึทืœื•ืขืก ืฆื• ืื™ื™ืŸ ื’ืขืฉืขืขื ื™ืฉ ืงืœืึธืฅ ื˜ืขืงืข ืื•ื™ืฃ ื“ืขื ื“ืจืš ืžื™ื™ืงืจืึธืกืึธืคึฟื˜ -> Windows -> ืกื™ืกืžืึธืŸ -> ืึธืคึผืขืจืึทืฆื™ืึธื ืขืœืื™ืŸ ืžืฒึทื ืข ืื™ื™ื’ืขื ืข ืœืึธื’ ืื•ื™ืกืคึฟืึธืจืฉื•ื ื’ืขืŸ Windowsื”ืึธืจ-ืจื™ื™ื–ืขื ื“ืข ื˜ืขื•ืชื™ื ื•ื•ื™ ื“ื™ ื”ืื‘ืŸ ืžื™ืš ื’ืขืžืื›ื˜ ื›ืกื“ืจ ืžื•ื–ืŸ ื•ื•ืขืงืกืœืขืŸ ืฆื•ื•ื™ืฉืŸ, ืœืžืฉืœ, ื“ื™ ืคึผืึทื•ืขืจืฉืขืœ ืœืึธื’ืก ื˜ืขืงืข ืื•ืŸ ื“ื™ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื˜ืขืงืข, ืกืงืจืึธืœืŸ ื“ื•ืจืš ื’ืขืฉืขืขื ื™ืฉ ืœืึธื’ืก ืื™ืŸ ื ื”ืขืœื“ื™ืฉืŸ ืคืืจื–ื•ืš ืฆื• ืขืคืขืก ืคืืจื‘ื™ื ื“ืŸ ื“ื™ ื•ื•ืขืจื˜ืŸ ืฆื•ื•ื™ืฉืŸ ื–ื™ื™. ื“ืืก ืื™ื– ืงื™ื™ื ืžืืœ ื ื™ืฉื˜ ืงื™ื™ืŸ ื’ืจื™ื ื’ืข ืื•ื™ืคื’ืื‘ืข, ืื•ืŸ ื•ื•ื™ ืื™ืš ื”ืื‘ ืฉืคืขื˜ืขืจ ืื™ื™ื ื’ืขื–ืขืŸ, ื•ื•ืืœื˜ ืขืก ื’ืขื•ื•ืขืŸ ื‘ืขืกืขืจ ืฆื• ืงื•ื™ืคืŸ ืืกืคึผื™ืจื™ืŸ ื’ืœื™ื™ืš.

Sysmon ื ืขืžื˜ ืึท ืงื•ื•ืึทื ื˜ื•ื ืฉืคึผืจื™ื ื’ืขืŸ ืคืึธืจื•ื™ืก ื“ื•ืจืš ืคึผืจืึทื•ื•ื™ื™ื“ื™ื ื’ ื ื•ืฆื™ืง (ืึธื“ืขืจ ื•ื•ื™ ื•ื•ืขื ื“ืึธืจืก ื•ื•ื™ ืฆื• ื–ืึธื’ืŸ, ืึทืงื˜ื™ืึธื ืึทื‘ืœืข) ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืฆื• ื”ืขืœืคืŸ ืคึฟืึทืจืฉื˜ื™ื™ืŸ ื“ื™ ืึทื ื“ืขืจืœื™ื™ื™ื ื’ ืคึผืจืึทืกืขืกืึทื–. ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ืื™ืš ืกื˜ืึทืจื˜ืขื“ ืึท ืกื•ื“ ืกืขืกื™ืข wmiexec, ืกื™ืžื•ืœื™ืจื ื“ื™ืง ื“ื™ ื‘ืึทื•ื•ืขื’ื•ื ื’ ืคื•ืŸ ืึท ืงืœื•ื’ืŸ ืื™ื ืกื™ื™ื“ืขืจ ืื™ืŸ ื ืขืฅ. ื“ืึธืก ืื™ื– ื•ื•ืึธืก ืื™ืจ ื•ื•ืขื˜ ื–ืขืŸ ืื™ืŸ ื“ืขื ื’ืขืฉืขืขื ื™ืฉ ืœืึธื’. Windows:

Sysmon Threat Analysis Guide, ื˜ื™ื™ืœ 1

ืื™ืŸ ื“ืขื ื–ืฉื•ืจื ืึทืœ Windows ืขื˜ืœืขื›ืข ืคึผืจืึธืฆืขืก ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืื™ื– ืงืขื ื˜ื™ืง, ืึธื‘ืขืจ ืขืก ืื™ื– ื ื™ืฉื˜ ื–ื™ื™ืขืจ ื ื•ืฆืœืขืš. ืื•ื™ืš, ืคึผืจืึธืฆืขืก ืื™ื“ืขื ื˜ื™ืคื™ืงืึทืฆื™ืขืก ืื™ืŸ ื”ืขืงืกืึทื“ืขืฆื™ืžืึทืœ ืคืึธืจืขื?

ืคึฟืึทืจ ืึท ืคืึทื›ืžืึทืŸ ืขืก ืคืึทื›ืžืึทืŸ ืžื™ื˜ ืึท ืคืืจืฉื˜ืื ื“ ืคื•ืŸ ื“ื™ ื‘ืึทืกื™ืงืก ืคื•ืŸ ื›ืึทืงื™ื ื’, ื“ื™ ื‘ืึทืคึฟืขืœ ืฉื•ืจื” ื–ืึธืœ ื–ื™ื™ืŸ ืกืึทืกืคึผื™ืฉืึทืก. ื ื™ืฆืŸ cmd.exe ืฆื• ืœื•ื™ืคืŸ ืืŸ ืื ื“ืขืจ ื‘ืึทืคึฟืขืœ ืื•ืŸ ืจื™ื“ืขืจืขืงื˜ ื“ื™ ืจืขื–ื•ืœื˜ืึทื˜ ืฆื• ืึท ื˜ืขืงืข ืžื™ื˜ ืึท ืžืึธื“ื ืข ื ืึธืžืขืŸ ืื™ื– ืงืœืืจ ืขื ืœืขืš ืฆื• ื“ื™ ืึทืงืฉืึทื ื– ืคื•ืŸ ืžืึธื ื™ื˜ืึธืจื™ื ื’ ืื•ืŸ ืงืึธื ื˜ืจืึธืœ ื•ื•ื™ื™ื›ื•ื•ืืจื’ ื‘ืึทืคึฟืขืœืŸ ืื•ืŸ ืงืึธื ื˜ืจืึธืœ (C2): ืื™ืŸ ื“ืขื ื•ื•ืขื’, ืึท ืคึผืกืขื•ื•ื“ืึธ-ืฉืึธืœ ืื™ื– ื‘ืืฉืืคืŸ ืžื™ื˜ WMI ื‘ืึทื“ื™ื ื•ื ื’ืก.
ืื™ืฆื˜ ืœืึธืžื™ืจ ื ืขืžืขืŸ ืึท ืงื•ืง ืื™ืŸ ื“ื™ Sysmon ืคึผืึธื–ื™ืฆื™ืข ืขืงื•ื•ื™ื•ื•ืึทืœืขื ื˜, ื ืึธื•ื˜ื™ืกื™ื ื’ ื•ื•ื™ ืคื™ืœ ื ืึธืš ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืขืก ื’ื™ื˜ ืื•ื ื“ื–:

Sysmon Threat Analysis Guide, ื˜ื™ื™ืœ 1

Sysmon ืคึฟืขื™ึดืงื™ื™ื˜ืŸ ืื™ืŸ ืื™ื™ืŸ ืกืงืจืขืขื ืฉืึธื˜: ื“ื™ื˜ื™ื™ืœื“ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ืขื ืคึผืจืึธืฆืขืก ืื™ืŸ ืึท ืœื™ื™ื ืขื•ื•ื“ื™ืง ืคืึธืจืขื

ืื™ืจ ื–ืขื˜ ื ื™ืฉื˜ ื ืึธืจ ื“ื™ ืงืึธืžืึทื ื“ ืœื™ื ื™ืข, ื ืึธืจ ืื•ื™ืš ื“ืขื ื˜ืขืงืข ื ืึธืžืขืŸ, ื“ืขื ื“ืจืš ืฆื• ื“ืขืจ ืขืงืกืขืงื•ื˜ืึทื‘ืึทืœ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ, ื•ื•ืึธืก Windows ื•ื•ื™ื™ืกื˜ ื•ื•ืขื’ืŸ ื“ืขื ("Windows "ืงืึธืžืึทื ื“ ืคึผืจืึทืกืขืกืึธืจ", ืื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืขืจ ืคึผืึทืจืขื ื˜ืึทืœ ืคึผืจืึธืฆืขืก, ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื” ืคืึธื˜ืขืจ, ื•ื•ืึธืก ืœืึธื ื˜ืฉื˜ ื“ื™ ืงืžื“ ืฉืึธืœ, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื“ื™ ืคืึทืงื˜ื™ืฉ ื˜ืขืงืข ื ืึธืžืขืŸ ืคื•ืŸ ื“ื™ ืคืึธื˜ืขืจ ืคึผืจืึธืฆืขืก. ืึทืœืฅ ืื™ืŸ ืื™ื™ืŸ ืึธืจื˜, ืœืขืกืึธืฃ!
ืคึฟื•ืŸ ื“ื™ Sysmon ืงืœืึธืฅ ืžื™ืจ ืงืขื ืขืŸ ืคืึทืจืขื ื“ื™ืงืŸ ืึทื– ืžื™ื˜ ืึท ื”ื•ื™ืš ืžืึทืฉืžืึธืขืก ื“ื™ ืกืึทืกืคึผื™ืฉืึทืก ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื” ื•ื•ืึธืก ืžื™ืจ ื’ืขื–ืขืŸ ืื™ืŸ ื“ื™ "ืจื•ื™" ืœืึธื’ืก ืื™ื– ื ื™ืฉื˜ ื“ืขืจ ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ื“ืขืจ ืึธื ื’ืขืฉื˜ืขืœื˜ืขืจ ืก ื ืึธืจืžืึทืœ ืึทืจื‘ืขื˜. ื’ืึทื ืฅ ืคืึทืจืงืขืจื˜, ืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ื“ื•ืจืš ืึท C2-ื•ื•ื™ ืคึผืจืึธืฆืขืก - wmiexec, ื•ื•ื™ ืื™ืš ื“ืขืจืžืื ื˜ ืคืจื™ืขืจ - ืื•ืŸ ืื™ื– ื’ืœื™ื™ืš ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ื“ื™ WMI ืกืขืจื•ื•ื™ืก ืคึผืจืึธืฆืขืก (WmiPrvSe). ืื™ืฆื˜ ืžื™ืจ ื”ืึธื‘ืŸ ืึท ื’ืจืื“ืŸ ืึทื– ืึท ื•ื•ื™ื™ึทื˜ ืึทื˜ืึทืงืขืจ ืึธื“ืขืจ ื™ื ืกื™ื™ื“ืขืจ ืื™ื– ื˜ืขืกื˜ื™ื ื’ ื“ื™ ืคึฟื™ืจืžืข ื™ื ืคืจืึทืกื˜ืจืึทืงื˜ืฉืขืจ.

ื™ื ื˜ืจืึธื•ื“ื•ืกื™ื ื’ Get-Sysmonlogs

ื“ืึธืš ืขืก ืื™ื– ื’ืจื•ื™ืก ื•ื•ืขืŸ Sysmon ืฉื˜ืขืœืŸ ื“ื™ ืœืึธื’ืก ืื™ืŸ ืื™ื™ืŸ ืึธืจื˜. ืึธื‘ืขืจ ืขืก ื•ื•ืึธืœื˜ ืžื™ืกื˜ืึธืžืข ื–ื™ื™ืŸ ืืคื™ืœื• ื‘ืขืกืขืจ ืื•ื™ื‘ ืžื™ืจ ืงืขืŸ ืึทืงืกืขืก ื™ื—ื™ื“ ืงืœืึธืฅ ืคืขืœื“ืขืจ ืคึผืจืึธื’ืจืึทืžืžืึทื˜ื™ืงืึทืœืœื™ - ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ื“ื•ืจืš PowerShell ืงืึทืžืึทื ื“ื–. ืื™ืŸ ื“ืขื ืคืึทืœ, ืื™ืจ ืงืขืŸ ืฉืจื™ื™ึทื‘ืŸ ืึท ืงืœื™ื™ืŸ PowerShell ืฉืจื™ืคื˜ ื•ื•ืึธืก ื•ื•ืึธืœื˜ ืึธื˜ืึทืžื™ื™ื˜ ื“ื™ ื–ื•ื›ืŸ ืคึฟืึทืจ ืคึผืึธื˜ืขื ืฆื™ืขืœ ื˜ืจืขืฅ!
ืื™ืš ื‘ื™ืŸ ื ื™ืฉื˜ ื’ืขื•ื•ืขืŸ ื“ืขืจ ืขืจืฉื˜ืขืจ ื•ื•ืึธืก ื”ืึธื˜ ื’ืขื”ืึทื˜ ืึทื–ืึท ื’ืขื“ืึทื ืง. ืื•ืŸ ืขืก ืื™ื– ื’ื•ื˜ ืึทื– ืื™ืŸ ืขื˜ืœืขื›ืข ืคืึธืจื•ื ืึทืจื˜ื™ืงืœืขืŸ ืื•ืŸ GitHub ืคืจืื™ืขืงื˜ืŸ ืขืก ืื™ื– ืฉื•ื™ืŸ ื“ืขืจืงืœืขืจื˜ ื•ื•ื™ ืฆื• ื ื•ืฆืŸ PowerShell ืฆื• ืคึผืึทืจืก ื“ื™ Sysmon ืงืœืึธืฅ. ืื™ืŸ ืžื™ื™ืŸ ืคืึทืœ, ืื™ืš ื’ืขื•ื•ืืœื˜ ืฆื• ื•ื™ืกืžื™ื™ื“ืŸ ืฆื• ืฉืจื™ื™ึทื‘ืŸ ื‘ืึทื–ื•ื ื“ืขืจ ืฉื•ืจื•ืช ืคื•ืŸ ืคึผืึทืจืกื™ื ื’ ืฉืจื™ืคื˜ ืคึฟืึทืจ ื™ืขื“ืขืจ Sysmon ืคืขืœื“. ืึทื–ื•ื™ ืื™ืš ื’ืขื•ื•ื™ื™ื ื˜ ื“ืขื ืคื•ื™ืœ ืžืขื ื˜ืฉ ืคึผืจื™ื ืฆื™ืคึผ ืื•ืŸ ืื™ืš ื˜ืจืึทื›ื˜ืŸ ืื™ืš ื’ืขืงื•ืžืขืŸ ืึทืจื•ื™ืฃ ืžื™ื˜ ืขืคึผืขืก ื˜ืฉื™ืงืึทื•ื•ืข ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜.
ื“ืขืจ ืขืจืฉื˜ืขืจ ื•ื•ื™ื›ื˜ื™ืง ืคื•ื ื˜ ืื™ื– ื“ื™ ืคื™ื™ื™ืงื™ื™ึทื˜ ืคื•ืŸ ื“ื™ ืžืึทื ืฉืึทืคึฟื˜ ื‘ืึทืงื•ืžืขืŸ-ื•ื•ื™ื ื•ื•ืขื ื˜ ืœื™ื™ืขื ืขืŸ Sysmon ืœืึธื’ืก, ืคื™ืœื˜ืขืจ ื“ื™ ื ื™ื™ื˜ื™ืง ื’ืขืฉืขืขื ื™ืฉืŸ ืื•ืŸ ืจืขื–ื•ืœื˜ืึทื˜ ื“ื™ ืจืขื–ื•ืœื˜ืึทื˜ ืฆื• ื“ื™ PS ื‘ื™ื™ึทื˜ืขื•ื•ื“ื™ืง, ื•ื•ื™ ื“ืึธ:

$events = Get-WinEvent  -LogName "Microsoft-Windows-Sysmon/Operational" | where { $_.id -eq 1 -or $_.id -eq 11}

ืื•ื™ื‘ ืื™ืจ ื•ื•ื™ืœืŸ ืฆื• ืคึผืจื•ื‘ื™ืจืŸ ื“ื™ ื‘ืึทืคึฟืขืœ ื–ื™ืš, ื“ื•ืจืš ื•ื•ื™ื™ึทื–ื ื“ื™ืง ื“ืขื ืื™ื ื”ืึทืœื˜ ืื™ืŸ ื“ืขืจ ืขืจืฉื˜ืขืจ ืขืœืขืžืขื ื˜ ืคื•ืŸ ื“ื™ $ events array, $ events[0]. ืึธื ื–ืึธื’, ื“ืขืจ ืจืขื–ื•ืœื˜ืึทื˜ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืึท ืกืขืจื™ืข ืคื•ืŸ โ€‹โ€‹ื˜ืขืงืกื˜ ืกื˜ืจื™ื ื’ืก ืžื™ื˜ ืึท ื–ื™ื™ืขืจ ืคึผืฉื•ื˜ ืคึฟืึธืจืžืึทื˜: ื“ื™ ื ืึธืžืขืŸ ืคื•ืŸ ื“ื™ ื‘ืึทืคึฟืขืœ. Sysmon ืคืขืœื“, ืึท ืฆื•ื•ื™ื™ืคึผื™ื ื˜ืœ, ืื•ืŸ ื“ืขืžืึธืœื˜ ื“ืขืจ ื•ื•ืขืจื˜ ื–ื™ืš.

Sysmon Threat Analysis Guide, ื˜ื™ื™ืœ 1

ื”ืืจื™ื™! ืึทืจื•ื™ืกืคื™ืจืŸ Sysmon ืงืœืึธืฅ ืื™ืŸ JSON-ื’ืจื™ื™ื˜ ืคึฟืึธืจืžืึทื˜

ืื™ืจ ื˜ืจืึทื›ื˜ืŸ ื“ื™ ื–ืขืœื‘ืข ื–ืึทืš ื•ื•ื™ ืžื™ืจ? ืžื™ื˜ ืึท ื‘ื™ืกืœ ืžืขืจ ืžื™, ืื™ืจ ืงืขื ืขืŸ ื‘ื™ื™ึทื˜ืŸ ื“ื™ ืจืขื–ื•ืœื˜ืึทื˜ ืื™ืŸ ืึท JSON ืคืึธืจืžืึทื˜ื˜ืขื“ ืฉื˜ืจื™ืงืœ ืื•ืŸ ื“ืขืžืึธืœื˜ ืœืึธื“ืŸ ืขืก ื’ืœื™ื™ืš ืื™ืŸ ืึท PS ื›ื™ื™ืคืขืฅ ืžื™ื˜ ืึท ืฉื˜ืึทืจืง ื‘ืึทืคึฟืขืœ. ืงืึธื ื•ื•ืขืจื˜ืคืจืึธื-ื“ื–ืฉืกืึธืŸ .
ืื™ืš ื•ื•ืขื˜ ื•ื•ื™ื™ึทื–ืŸ ื“ื™ PowerShell ืงืึธื“ ืคึฟืึทืจ ื“ื™ ืงืึทื ื•ื•ืขืจื–ืฉืึทืŸ - ื“ืึธืก ืื™ื– ื–ื™ื™ืขืจ ืคึผืฉื•ื˜ - ืื™ืŸ ื“ืขืจ ื•ื•ื™ื™ึทื˜ืขืจ ื˜ื™ื™ืœ. ืื™ืฆื˜, ืœืึธืžื™ืจ ื–ืขืŸ ื•ื•ืึธืก ืžื™ื™ืŸ ื ื™ื™ึทืข ื‘ืึทืคึฟืขืœ ื’ืขืจื•ืคืŸ get-sysmonlogs, ื•ื•ืึธืก ืื™ืš ืื™ื ืกื˜ืึทืœื™ืจืŸ ื•ื•ื™ ืึท ืคึผืก ืžืึธื“ื•ืœืข, ืงืขื ืขืŸ ื˜ืึธืŸ.
ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ื“ื™ื™ื•ื•ื™ื ื’ ื˜ื™ืฃ ืื™ืŸ Sysmon ืงืœืึธืฅ ืึทื ืึทืœื™ืกื™ืก ื“ื•ืจืš ืึท ื•ืžื‘ืึทืงื•ื•ืขื ื’ืขืฉืขืขื ื™ืฉ ืงืœืึธืฅ ืฆื•ื‘ื™ื ื“, ืžื™ืจ ืงืขื ืขืŸ ืขืคืขืจื˜ืœืึทืก ื–ื•ื›ืŸ ืคึฟืึทืจ ื™ื ืงืจืึทืžืขื ื˜ืึทืœ ื˜ืขื˜ื™ืงื™ื™ื˜ ื’ืœื™ื™ึทืš ืคึฟื•ืŸ ืึท PowerShell ืกืขืกื™ืข, ืื•ืŸ ื ื•ืฆืŸ ื“ื™ PS ื‘ืึทืคึฟืขืœ. ื•ื•ื• (ืึทืœื™ืึทืก - "?") ืฆื• ืคืึทืจืงื™ืจืฆืŸ ื“ื™ ื–ื•ื›ืŸ ืจืขื–ื•ืœื˜ืึทื˜ืŸ:

Sysmon Threat Analysis Guide, ื˜ื™ื™ืœ 1

ืจืฉื™ืžื” ืคื•ืŸ ืงืžื“ ืฉืขืœื– ืœืึธื ื˜ืฉื˜ ื“ื•ืจืš WMI. ืกืึทืงืึธื ืข ืึทื ืึทืœื™ืกื™ืก ืื•ื™ืฃ ื“ื™ ื‘ื™ืœื™ืง ืžื™ื˜ ืื•ื ื“ื–ืขืจ ืื™ื™ื’ืขื ืข ื‘ืึทืงื•ืžืขืŸ-Sysmonlogs ืžืึทื ืฉืึทืคึฟื˜

ื•ื•ื•ื ื“ืขืจืœืขืš! ืื™ืš ื‘ืืฉืืคืŸ ืึท ื’ืขืฆื™ื™ึทื’ ืฆื• ื‘ืึทืงื•ืžืขืŸ ื“ื™ Sysmon ืงืœืึธืฅ ื•ื•ื™ ืื•ื™ื‘ ืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ืึท ื“ืึทื˜ืึทื‘ื™ื™ืก. ืื™ืŸ ืื•ื ื“ื–ืขืจ ืึทืจื˜ื™ืงืœ ื•ื•ืขื’ืŸ IQ ืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ื‘ืืžืขืจืงื˜ ืึทื– ื“ื™ ืคื•ื ืงืฆื™ืข ื•ื•ืขื˜ ื–ื™ื™ืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ื“ื•ืจืš ื“ื™ ืงื™ืœ ื ื•ืฆืŸ ื“ื™ืกืงืจื™ื™ื‘ื“ ืื™ืŸ ืขืก, ื›ืึธื˜ืฉ ืคืึธืจืžืึทืœื™ ื ืึธืš ื“ื•ืจืš ืึท ืคืึทืงื˜ื™ืฉ ืกืงืœ-ื•ื•ื™ ืฆื•ื‘ื™ื ื“. ื™ืึธ, EQL ืขืœืขื’ืึทื ื˜, ืื‘ืข ืจ ืžื™ ืจ ืฐืขืœืข ืŸ ืื™ ื ื ื“ืจื™ื˜ืข ืŸ ื˜ืฒืœ ืจ ืื ืจื™ืจืŸ .

Sysmon ืื•ืŸ ื’ืจืึทืคื™ืง ืึทื ืึทืœื™ืกื™ืก

ืœืึธืžื™ืจ ื ืขืžืขืŸ ืึท ืฉืจื™ื˜ ืฆื•ืจื™ืง ืื•ืŸ ื˜ืจืึทื›ื˜ืŸ ื•ื•ืขื’ืŸ ื•ื•ืึธืก ืžื™ืจ ื”ืึธื‘ืŸ ื ืึธืจ ื•ื•ืึธืก ื‘ืึทืฉืึทืคึฟืŸ. ืื™ืŸ ืขื™ืงืจ, ืžื™ืจ ื”ืึธื‘ืŸ ืื™ืฆื˜ ืึท ื“ืึทื˜ืึทื‘ืึทื–ืข ืคึฟื•ืŸ ื’ืขืฉืขืขื ื™ืฉืŸ. Windows, ืฆื•ื˜ืจื™ื˜ืœืขืš ื“ื•ืจืš PowerShell. ื•ื•ื™ ืื™ืš ื”ืื‘ ืคืจื™ืขืจ ื‘ืืžืขืจืงื˜, ื–ืขื ืขืŸ ื“ื ืคืืจื‘ื™ื ื“ื•ื ื’ืขืŸ ืื“ืขืจ ื‘ืืฆื™ืื•ื ื’ืขืŸ ืฆื•ื•ื™ืฉืŸ ืจืขืงืืจื“ืกโ€”ื“ื•ืจืš ParentProcessIdโ€”ืื–ื•ื™ ืงืขื ื˜ ืื™ืจ ืฆื•ืจื™ืง ื‘ืืงื•ืžืขืŸ ื“ื™ ื’ืื ืฆืข ืคืจืืฆืขืก ื›ื™ื™ืขืจืึทืจื›ื™ืข.

ืื•ื™ื‘ ืื™ืจ ื”ืึธื˜ ืœื™ื™ืขื ืขืŸ ื“ื™ ืกืขืจื™ืข "ื“ื™ ืึทื“ื•ื•ืขื ื˜ื•ืจืขืก ืคื•ืŸ ื“ื™ ื™ืœื•ืกื™ื•ื• ืžืึทืœื•ื•ืึทืจืข" ืื™ืจ ื•ื•ื™ืกืŸ ืึทื– ื›ืึทืงืขืจื– ืœื™ื‘ืข ืฆื• ืฉืึทืคึฟืŸ ืงืึธืžืคึผืœืขืงืก ืžืึทืœื˜ื™-ื‘ื™ื ืข ืื ืคืืœืŸ, ืื™ืŸ ื•ื•ืึธืก ื™ืขื“ืขืจ ืคึผืจืึธืฆืขืก ืคื™ืขืกืขืก ื–ื™ื™ืŸ ืื™ื™ื’ืขื ืข ืงืœื™ื™ืŸ ืจืึธืœืข ืื•ืŸ ืคึผืจื™ืคึผืขืจื– ืึท ืกืคึผืจื™ื ื’ื‘ืึธืจื“ ืคึฟืึทืจ ื“ืขืจ ื•ื•ื™ื™ึทื˜ืขืจ ืฉืจื™ื˜. ืขืก ืื™ื– ื’ืึธืจ ืฉื•ื•ืขืจ ืฆื• ื›ืึทืคึผืŸ ืึทื–ืึท ื–ืื›ืŸ ืคืฉื•ื˜ ืคื•ืŸ ื“ื™ "ืจื•ื™" ืงืœืึธืฅ.
ืึธื‘ืขืจ ืžื™ื˜ ืžื™ื™ืŸ Get-Sysmonlogs ื‘ืึทืคึฟืขืœ ืื•ืŸ ืึทืŸ ื ืึธืš ื“ืึทื˜ืŸ ืกื˜ืจื•ืงื˜ื•ืจ ื•ื•ืึธืก ืžื™ืจ ื•ื•ืขืœืŸ ื–ืขืŸ ืฉืคึผืขื˜ืขืจ ืื™ืŸ ื“ืขื ื˜ืขืงืกื˜ (ืึท ื’ืจืึทืคื™ืง, ืคื•ืŸ ืงื•ืจืก), ืžื™ืจ ื”ืึธื‘ืŸ ืึท ืคึผืจืึทืงื˜ื™ืฉ ื•ื•ืขื’ ืฆื• ื“ืขื˜ืขืงื˜ ื˜ืจืขืฅ - ื•ื•ืึธืก ื ืึธืจ ืจื™ืงื•ื•ื™ื™ืขืจื– ื“ื™ ืจืขื›ื˜ ื•ื•ืขืจื˜ืขืงืก ื–ื•ื›ืŸ.
ื•ื•ื™ ืฉื˜ืขื ื“ื™ืง ืžื™ื˜ ืื•ื ื“ื–ืขืจ DYI ื‘ืœืึธื’ ืคึผืจืึทื“ื–ืฉืขืงืก, ื“ื™ ืžืขืจ ืื™ืจ ืึทืจื‘ืขื˜ ืื•ื™ืฃ ืึทื ืึทืœื™ื™ื–ื™ื ื’ ื“ื™ ื“ืขื˜ืึทื™ืœืก ืคื•ืŸ ื˜ืจืขืฅ ืื•ื™ืฃ ืึท ืงืœื™ื™ืŸ ื•ื•ืึธื’, ื“ื™ ืžืขืจ ืื™ืจ ื•ื•ืขื˜ ืคืึทืจืฉื˜ื™ื™ืŸ ื•ื•ื™ ืงืึธืžืคึผืœืขืงืก ืกืึทืงืึธื ืข ื“ื™ื˜ืขืงืฉืึทืŸ ืื™ื– ืื•ื™ืฃ ื“ื™ ืคืึทืจื ืขืžื•ื ื’ ืžื“ืจื’ื”. ืื•ืŸ ื“ืขื ื•ื•ื™ืกื™ืงื™ื™ึทื˜ ืื™ื– ื’ืึธืจ ื•ื•ื™ื›ื˜ื™ืง ืคื•ื ื˜.

ืžื™ืจ ื•ื•ืขืœืŸ ื˜ืจืขืคืŸ ื“ื™ ืขืจืฉื˜ืข ื˜ืฉื™ืงืึทื•ื•ืข ืงืึทืžืคึผืœืึทืงื™ื™ืฉืึทื ื– ืื™ืŸ ื“ื™ ืจื’ืข ื˜ื™ื™ืœ ืคื•ืŸ ื“ืขื ืึทืจื˜ื™ืงืœ, ื•ื•ื• ืžื™ืจ ื•ื•ืขืœืŸ ืึธื ื”ื™ื™ื‘ืŸ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ Sysmon events ืžื™ื˜ ื™ืขื“ืขืจ ืื ื“ืขืจืข ืื™ืŸ ืคื™ืœ ืžืขืจ ืงืึธืžืคึผืœื™ืฆื™ืจื˜ ืกื˜ืจืึทืงื˜ืฉืขืจื–.

ืžืงื•ืจ: www.habr.com

ืงื•ื™ืคืŸ ืคืึทืจืœืึธื–ืœืขืš ื”ืึธืกื˜ื™ื ื’ ืคึฟืึทืจ ื–ื™ื™ื˜ืœืขืš ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก ๐Ÿ”ฅ ืงื•ื™ืคื˜ ืคืึทืจืœืขืกืœืขื›ืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื”ืึธืกื˜ื™ื ื’ ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก | ProHoster