Sysmon Threat Analysis Guide, ื˜ื™ื™ืœ 1

ื“ืขืจ ืึทืจื˜ื™ืงืœ ืื™ื– ื“ืขืจ ืขืจืฉื˜ืขืจ ื˜ื™ื™ืœ ืคื•ืŸ ืึท ืกืขืจื™ืข ืื•ื™ืฃ Sysmon ืกืึทืงืึธื ืข ืึทื ืึทืœื™ืกื™ืก. ืึทืœืข ืื ื“ืขืจืข ื˜ื™ื™ืœืŸ ืคื•ืŸ ื“ืขืจ ืกืขืจื™ืข:

ื˜ื™ื™ืœ 1: ื”ืงื“ืžื” ืฆื• Sysmon ืœืึธื’ ืึทื ืึทืœื™ืกื™ืก (ืื•ื ื– ื–ืขื ืขืŸ ื“ื)
ื˜ื™ื™ืœ 2: ื ื™ืฆืŸ Sysmon Event Data ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ื˜ืจืขืฅ
ื˜ื™ื™ืœ 3. ืื™ืŸ-ื˜ื™ืคืงื™ื™ึทื˜ ืึทื ืึทืœื™ืกื™ืก ืคื•ืŸ Sysmon ื˜ืจืขืฅ ื ื™ืฆืŸ ื’ืจืึทืคืก

ืื•ื™ื‘ ืื™ืจ ืึทืจื‘ืขื˜ ืื™ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื–ื™ื›ืขืจื”ื™ื™ื˜, ืื™ืจ ืžื™ืกื˜ืึธืžืข ืึธืคื˜ ื”ืึธื‘ืŸ ืฆื• ืคึฟืึทืจืฉื˜ื™ื™ืŸ ืึธื ื’ืึธื™ื ื’ ืื ืคืืœืŸ. ืื•ื™ื‘ ืื™ืจ ืฉื•ื™ืŸ ื”ืึธื‘ืŸ ืึท ื˜ืจื™ื™ื ื“ ืื•ื™ื’, ืื™ืจ ืงืขื ืขืŸ ืงื•ืงืŸ ืคึฟืึทืจ ื ื™ื˜-ื ืึธืจืžืึทืœ ื˜ืขื˜ื™ืงื™ื™ื˜ ืื™ืŸ ื“ื™ "ืจื•ื™" ืึทื ืคึผืจืึทืกืขืกื˜ ืœืึธื’ืก - ื–ืึธื’ืŸ, ืึท PowerShell ืฉืจื™ืคื˜ ืคืœื™ืกื ื“ื™ืง ืžื™ื˜ ื“ื™ DownloadString ื‘ืึทืคึฟืขืœ ืึธื“ืขืจ ืึท VBS ืฉืจื™ืคื˜ ืคึผืจื™ื˜ืขื ื“ื™ื ื’ ืฆื• ื–ื™ื™ืŸ ืึท ื•ื•ืึธืจื˜ ื˜ืขืงืข - ืคืฉื•ื˜ ืกืงืจืึธืœืœื™ื ื’ ื“ื•ืจืš ื“ื™ ืœืขืฆื˜ืข ื˜ืขื˜ื™ืงื™ื™ื˜ ืื™ืŸ ื“ื™ Windows ื’ืขืฉืขืขื ื™ืฉ ืงืœืึธืฅ. ืื‘ืขืจ ื“ืึธืก ืื™ื– ืึท ื˜ืึทืงืข ื’ืจื•ื™ืก ืงืึธืคึผื•ื•ื™ื™ื˜ื™ืง. ืฆื•ืž ื’ืœื™ืง, ืžื™ื™ืงืจืึธืกืึธืคึฟื˜ ื‘ืืฉืืคืŸ Sysmon, ื•ื•ืึธืก ืžืื›ื˜ ื‘ืึทืคืึทืœืŸ ืึทื ืึทืœื™ืกื™ืก ืคื™ืœ ื’ืจื™ื ื’ืขืจ.

ื•ื•ื™ืœืŸ ืฆื• ืคึฟืึทืจืฉื˜ื™ื™ืŸ ื“ื™ ื™ืงืขืจื“ื™ืง ื’ืขื“ืื ืงืขืŸ ื”ื™ื ื˜ืขืจ ื“ื™ ื˜ืจืขืฅ ื’ืขื•ื•ื™ื–ืŸ ืื™ืŸ ื“ื™ Sysmon ืงืœืึธืฅ? ืืจืืคืงืืคื™ืข ืื•ื ื“ื–ืขืจ ืคื™ืจืขืจ WMI events ื•ื•ื™ ืึท ืžื™ื˜ืœ ืคื•ืŸ ืกืคึผื™ื™ื™ื ื’ ืื•ืŸ ืื™ืจ ืคืึทืจืฉื˜ื™ื™ืŸ ื•ื•ื™ ื™ื ืกื™ื“ืขืจื– ืงืขื ืขืŸ ืกื•ืจืจืขืคึผื˜ื™ื˜ื™ืึธื•ืกืœื™ ืึธื‘ืกืขืจื•ื•ื™ืจืŸ ืื ื“ืขืจืข ืขืžืคึผืœื•ื™ื™ื–. ื“ืขืจ ื”ื•ื™ืคึผื˜ ืคึผืจืึธื‘ืœืขื ืžื™ื˜ ืืจื‘ืขื˜ืŸ ืžื™ื˜ ื“ื™ Windows ื’ืขืฉืขืขื ื™ืฉ ืงืœืึธืฅ ืื™ื– ื“ื™ ืคืขืœืŸ ืคื•ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืคืึธื˜ืขืจ ืคึผืจืึทืกืขืกืึทื–, ื™.ืข. ืขืก ืื™ื– ืื•ืžืžืขื’ืœืขืš ืฆื• ืคึฟืึทืจืฉื˜ื™ื™ืŸ ื“ื™ ื›ื™ื™ืขืจืึทืจืงื™ ืคื•ืŸ ืคึผืจืึทืกืขืกืึทื– ื“ืขืจืคื•ืŸ. Sysmon ืงืœืึธืฅ ืื™ื™ื ืกืŸ, ืื•ื™ืฃ ื“ื™ ืื ื“ืขืจืข ื”ืึทื ื˜, ืึทื ื˜ื”ืึทืœื˜ืŸ ื“ื™ ืคืึธื˜ืขืจ ืคึผืจืึธืฆืขืก ืฉื™ื™ึทืŸ, ื–ื™ื™ืŸ ื ืึธืžืขืŸ ืื•ืŸ ื“ื™ ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื” ืฆื• ื–ื™ื™ืŸ ืœืึธื ื˜ืฉื˜. ื“ืึทื ืงืขืŸ ื“ื™ืจ, ืžื™ื™ืงืจืึธืกืึธืคึฟื˜.

ืื™ืŸ ื“ืขืจ ืขืจืฉื˜ืขืจ ื˜ื™ื™ืœ ืคื•ืŸ ืื•ื ื“ื–ืขืจ ืกืขืจื™ืข, ืžื™ืจ ื•ื•ืขืœืŸ ืงื•ืงืŸ ืื™ืŸ ื•ื•ืึธืก ืื™ืจ ืงืขื ืขืŸ ื˜ืึธืŸ ืžื™ื˜ ื™ืงืขืจื“ื™ืง ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืคึฟื•ืŸ Sysmon. ืื™ืŸ ื˜ื™ื™ืœ XNUMX, ืžื™ืจ ื•ื•ืขืœืŸ ื ื•ืฆืŸ ื“ื™ ืคืึธื˜ืขืจ ืคึผืจืึธืฆืขืก ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืฆื• ืฉืึทืคึฟืŸ ืžืขืจ ืงืึธืžืคึผืœื™ืฆื™ืจื˜ ื”ืขืกืงืขื ืกื˜ืจืึทืงื˜ืฉืขืจื– ื‘ืืงืื ื˜ ื•ื•ื™ ืกืึทืงืึธื ืข ื’ืจืึทืคืก. ืื™ืŸ ื“ื™ ื“ืจื™ื˜ ื˜ื™ื™ืœ, ืžื™ืจ ื•ื•ืขืœืŸ ืงื•ืงืŸ ืื™ืŸ ืึท ืคึผืฉื•ื˜ ืึทืœื’ืขืจื™ื“ืึทื ื•ื•ืึธืก ืกืงืึทื ื– ืึท ืกืึทืงืึธื ืข ื’ืจืึทืคื™ืง ืฆื• ื–ื•ื›ืŸ ืคึฟืึทืจ ื•ืžื’ืขื•ื•ื™ื™ื ื˜ืœืขืš ื˜ืขื˜ื™ืงื™ื™ื˜ ื“ื•ืจืš ืึทื ืึทืœื™ื™ื–ื™ื ื’ ื“ื™ "ื•ื•ืึธื’" ืคื•ืŸ ื“ื™ ื’ืจืึทืคื™ืง. ืื•ืŸ ืื™ืŸ ื“ื™ ืกื•ืฃ, ืื™ืจ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืจื™ื•ื•ืึธืจื“ื™ื“ ืžื™ื˜ ืึท ืฆื™ื›ื˜ื™ืง (ืื•ืŸ ืคืึทืจืฉื˜ื™ื™ื™ืง) ืคึผืจืึธื‘ืึทื‘ื™ืœื™ืกื˜ื™ืง ืกืึทืงืึธื ืข ื“ื™ื˜ืขืงืฉืึทืŸ ืื•ืคึฟืŸ.

ื˜ื™ื™ืœ 1: ื”ืงื“ืžื” ืฆื• Sysmon ืœืึธื’ ืึทื ืึทืœื™ืกื™ืก

ื•ื•ืึธืก ืงืขื ืขืŸ ื”ืขืœืคึฟืŸ ืื™ืจ ืคึฟืึทืจืฉื˜ื™ื™ืŸ ื“ื™ ืงืึทืžืคึผืœืขืงืกื™ื˜ื™ื– ืคื•ืŸ ื“ื™ ื’ืขืฉืขืขื ื™ืฉ ืงืœืึธืฅ? ืœืขืกืึธืฃ - SIEM. ืขืก ื ืึธืจืžืึทืœื™ื™ื–ื™ื– ื’ืขืฉืขืขื ื™ืฉืŸ ืื•ืŸ ืกื™ืžืคึผืœืึทืคื™ื™ื– ื–ื™ื™ืขืจ ืกืึทื‘ืกืึทืงื•ื•ืึทื ื˜ ืึทื ืึทืœื™ืกื™ืก. ืื‘ืขืจ ืžื™ืจ ื“ืืจืคืŸ ื ื™ืฉื˜ ื’ื™ื™ืŸ ืื–ื•ื™ ื•ื•ื™ื™ื˜, ืืžื•ื•ื™ื™ื ื™ื’ืกื˜ื ืก ื ื™ืฉื˜ ืขืจืฉื˜. ืื™ืŸ ื“ื™ ืึธื ื”ื™ื™ื‘, ืฆื• ืคึฟืึทืจืฉื˜ื™ื™ืŸ ื“ื™ ืคึผืจื™ื ืกืึทืคึผืึทืœื– ืคื•ืŸ SIEM, ืขืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขื ื•ื’ ืฆื• ืคึผืจื•ื‘ื™ืจืŸ ื“ื™ ื•ื•ื•ื ื“ืขืจืœืขืš ืคืจื™ื™ Sysmon ื ื•ืฆืŸ. ืื•ืŸ ื–ื™ ืื™ื– ืกืึทืคึผืจื™ื™ื–ื™ื ื’ืœื™ ื’ืจื™ื ื’ ืฆื• ืึทืจื‘ืขื˜ืŸ ืžื™ื˜. ื”ืึทืœื˜ืŸ ืขืก ืึทืจื•ื™ืฃ, ืžื™ื™ืงืจืึธืกืึธืคึฟื˜!

ื•ื•ืึธืก ืคึฟืขื™ึดืงื™ื™ื˜ืŸ ื”ืื˜ Sysmon?

ืื™ืŸ ืงื•ืจืฅ - ื ื•ืฆื™ืง ืื•ืŸ ืœื™ื™ื ืขื•ื•ื“ื™ืง ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ืคึผืจืึทืกืขืกืึทื– (ื–ืขืŸ ื‘ื™ืœื“ืขืจ ืื•ื ื˜ืŸ). ืื™ืจ ื•ื•ืขื˜ ื’ืขืคึฟื™ื ืขืŸ ืึท ื‘ื™ื ื˜ืœ ืคื•ืŸ ื ื•ืฆื™ืง ื“ืขื˜ืึทื™ืœืก ื•ื•ืึธืก ื–ืขื ืขืŸ ื ื™ืฉื˜ ืื™ืŸ ื“ื™ Windows Event Log, ืึธื‘ืขืจ ื“ื™ ืžืขืจืกื˜ ื•ื•ื™ื›ื˜ื™ืง ื–ืขื ืขืŸ ื“ื™ ืคืืœื’ืขื ื“ืข ืคืขืœื“ืขืจ:

  • ืคึผืจืึธืฆืขืก ืฉื™ื™ึทืŸ (ืื™ืŸ ื“ืขืฆื™ืžืึทืœ, ื ื™ืฉื˜ ื”ืขืงืก!)
  • ืคึผืึทืจืขื ื˜ ืคึผืจืึธืฆืขืก ืฉื™ื™ึทืŸ
  • ืคึผืจืึธืฆืขืก ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื”
  • ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื” ืคื•ืŸ ื“ืขืจ ืคืึธื˜ืขืจ ืคึผืจืึธืฆืขืก
  • ื˜ืขืงืข ื‘ื™ืœื“ ื”ืึทืฉ
  • ื˜ืขืงืข ื‘ื™ืœื“ ื ืขืžืขืŸ

Sysmon ืื™ื– ืื™ื ืกื˜ืึทืœื™ืจืŸ ื‘ื™ื™ื“ืข ื•ื•ื™ ืึท ืžื™ื˜ืœ ื“ืจื™ื™ื•ื•ืขืจ ืื•ืŸ ื•ื•ื™ ืึท ื“ื™ื ืกื˜ - ืžืขืจ ื“ืขื˜ืึทื™ืœืก ื“ืึธ. ื–ื™ื™ึทืŸ ื”ื•ื™ืคึผื˜ ืžื™ื™ึทืœืข ืื™ื– ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืคื•ื ืึทื ื“ืขืจืงืœื™ื™ึทื‘ืŸ ืœืึธื’ืก ืคื•ืŸ ืขื˜ืœืขื›ืข ืงื•ื•ืืœืŸ, ืงืึธืจืึทืœื™ื™ืฉืึทืŸ ืคื•ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืื•ืŸ ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ืจื™ื–ืึทืœื˜ื™ื ื’ ื•ื•ืึทืœื•ืขืก ืฆื• ืื™ื™ืŸ ื’ืขืฉืขืขื ื™ืฉ ืงืœืึธืฅ ื˜ืขืงืข ืื•ื™ืฃ ื“ืขื ื“ืจืš ืžื™ื™ืงืจืึธืกืึธืคึฟื˜ -> Windows -> Sysmon -> ืึทืคึผืขืจื™ื™ืฉืึทื ืึทืœ. ืื™ืŸ ืžื™ื™ืŸ ืื™ื™ื’ืขื ืข ื”ืึธืจ-ืจื™ื™ื–ื™ื ื’ ื™ื ื•ื•ืขืกื˜ืึทื’ื™ื™ืฉืึทื ื– ืื™ืŸ Windows ืœืึธื’ืก, ืื™ืš ื’ืขืคึฟื•ื ืขืŸ ื–ื™ืš ืงืขืกื™ื™ื“ืขืจ ืฆื• ื‘ืึทืฉื˜ื™ืžืขืŸ ืฆื•ื•ื™ืฉืŸ, ื–ืึธื’ืŸ, ื“ื™ PowerShell ืœืึธื’ืก ื˜ืขืงืข ืื•ืŸ ื“ื™ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื˜ืขืงืข, ืคืœื™ืงื™ื ื’ ื“ื•ืจืš ื“ื™ ื’ืขืฉืขืขื ื™ืฉ ืœืึธื’ืก ืื™ืŸ ืึท ื•ื•ืึทืœื™ืึทื ื˜ ืคึผืจื•ื•ื•ืŸ ืฆื• ืขืคืขืก ืงืึธืจืึทืœื™ื™ื˜ ื“ื™ ื•ื•ืึทืœื•ืขืก ืฆื•ื•ื™ืฉืŸ ื“ื™ ืฆื•ื•ื™ื™. . ื“ืึธืก ืื™ื– ืงื™ื™ื ืžืึธืœ ืึทืŸ ื’ืจื™ื ื’ ืึทืจื‘ืขื˜, ืื•ืŸ ื•ื•ื™ ืื™ืš ืฉืคึผืขื˜ืขืจ ืื™ื™ื ื’ืขื–ืขืŸ, ืขืก ืื™ื– ื‘ืขืกืขืจ ืฆื• ืžื™ื“ ืœืึทื’ืขืจ ืึทืจื•ื™ืฃ ืžื™ื˜ ืึทืกืคึผื™ืจื™ืŸ.

Sysmon ื ืขืžื˜ ืึท ืงื•ื•ืึทื ื˜ื•ื ืฉืคึผืจื™ื ื’ืขืŸ ืคืึธืจื•ื™ืก ื“ื•ืจืš ืคึผืจืึทื•ื•ื™ื™ื“ื™ื ื’ ื ื•ืฆื™ืง (ืึธื“ืขืจ ื•ื•ื™ ื•ื•ืขื ื“ืึธืจืก ื•ื•ื™ ืฆื• ื–ืึธื’ืŸ, ืึทืงื˜ื™ืึธื ืึทื‘ืœืข) ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืฆื• ื”ืขืœืคืŸ ืคึฟืึทืจืฉื˜ื™ื™ืŸ ื“ื™ ืึทื ื“ืขืจืœื™ื™ื™ื ื’ ืคึผืจืึทืกืขืกืึทื–. ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ืื™ืš ืกื˜ืึทืจื˜ืขื“ ืึท ืกื•ื“ ืกืขืกื™ืข wmiexec, ืกื™ืžื™ืึทืœื™ื™ื˜ื™ื ื’ ื“ื™ ื‘ืึทื•ื•ืขื’ื•ื ื’ ืคื•ืŸ ืึท ืงืœื•ื’ ื™ื ืกื™ื™ื“ืขืจ ื™ืŸ ื“ืขืจ ื ืขืฅ. ื“ืึธืก ืื™ื– ื•ื•ืึธืก ืื™ืจ ื•ื•ืขื˜ ื–ืขืŸ ืื™ืŸ ื“ื™ Windows ื’ืขืฉืขืขื ื™ืฉ ืงืœืึธืฅ:

Sysmon Threat Analysis Guide, ื˜ื™ื™ืœ 1

ื“ื™ Windows ืงืœืึธืฅ ื•ื•ื™ื™ื–ื˜ ืขื˜ืœืขื›ืข ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ืขื ืคึผืจืึธืฆืขืก, ืึธื‘ืขืจ ืขืก ืื™ื– ืคื•ืŸ ืงืœื™ื™ืŸ ื ื•ืฆืŸ. ืคึผืœื•ืก ืคึผืจืึธืฆืขืก ื™ื“ืก ืื™ืŸ ื”ืขืงืกืึทื“ืขืกื™ืžืึทืœ???

ืคึฟืึทืจ ืึท ืคืึทื›ืžืึทืŸ ืขืก ืคืึทื›ืžืึทืŸ ืžื™ื˜ ืึท ืคืืจืฉื˜ืื ื“ ืคื•ืŸ ื“ื™ ื‘ืึทืกื™ืงืก ืคื•ืŸ ื›ืึทืงื™ื ื’, ื“ื™ ื‘ืึทืคึฟืขืœ ืฉื•ืจื” ื–ืึธืœ ื–ื™ื™ืŸ ืกืึทืกืคึผื™ืฉืึทืก. ื ื™ืฆืŸ cmd.exe ืฆื• ืœื•ื™ืคืŸ ืืŸ ืื ื“ืขืจ ื‘ืึทืคึฟืขืœ ืื•ืŸ ืจื™ื“ืขืจืขืงื˜ ื“ื™ ืจืขื–ื•ืœื˜ืึทื˜ ืฆื• ืึท ื˜ืขืงืข ืžื™ื˜ ืึท ืžืึธื“ื ืข ื ืึธืžืขืŸ ืื™ื– ืงืœืืจ ืขื ืœืขืš ืฆื• ื“ื™ ืึทืงืฉืึทื ื– ืคื•ืŸ ืžืึธื ื™ื˜ืึธืจื™ื ื’ ืื•ืŸ ืงืึธื ื˜ืจืึธืœ ื•ื•ื™ื™ื›ื•ื•ืืจื’ ื‘ืึทืคึฟืขืœืŸ ืื•ืŸ ืงืึธื ื˜ืจืึธืœ (C2): ืื™ืŸ ื“ืขื ื•ื•ืขื’, ืึท ืคึผืกืขื•ื•ื“ืึธ-ืฉืึธืœ ืื™ื– ื‘ืืฉืืคืŸ ืžื™ื˜ WMI ื‘ืึทื“ื™ื ื•ื ื’ืก.
ืื™ืฆื˜ ืœืึธืžื™ืจ ื ืขืžืขืŸ ืึท ืงื•ืง ืื™ืŸ ื“ื™ Sysmon ืคึผืึธื–ื™ืฆื™ืข ืขืงื•ื•ื™ื•ื•ืึทืœืขื ื˜, ื ืึธื•ื˜ื™ืกื™ื ื’ ื•ื•ื™ ืคื™ืœ ื ืึธืš ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืขืก ื’ื™ื˜ ืื•ื ื“ื–:

Sysmon Threat Analysis Guide, ื˜ื™ื™ืœ 1

Sysmon ืคึฟืขื™ึดืงื™ื™ื˜ืŸ ืื™ืŸ ืื™ื™ืŸ ืกืงืจืขืขื ืฉืึธื˜: ื“ื™ื˜ื™ื™ืœื“ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ืขื ืคึผืจืึธืฆืขืก ืื™ืŸ ืึท ืœื™ื™ื ืขื•ื•ื“ื™ืง ืคืึธืจืขื

ืื™ืจ ืงืขื ื˜ ื ื™ืฉื˜ ื‘ืœื•ื™ื– ื–ืขืŸ ื“ื™ ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื”, ืึธื‘ืขืจ ืื•ื™ืš ื“ื™ ื˜ืขืงืข ื ืึธืžืขืŸ, ื“ืขืจ ื“ืจืš ืฆื• ื“ื™ ืขืงืกืขืงื•ื˜ืึทื‘ืœืข ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ, ื•ื•ืึธืก Windows ื•ื•ื™ื™ืกื˜ ื•ื•ืขื’ืŸ ืื™ื ("ื•ื•ื™ื ื“ืึธื•ื– ืงืึทืžืึทื ื“ ืคึผืจืึทืกืขืกืขืจ"), ื“ื™ ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ืคึผืึทืจืขื ื˜ืึทืœ ืคึผืจืึธืฆืขืก, ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื” ืคืึธื˜ืขืจ, ื•ื•ืึธืก ืœืึธื ื˜ืฉื˜ ื“ื™ ืงืžื“ ืฉืึธืœ, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื“ื™ ืคืึทืงื˜ื™ืฉ ื˜ืขืงืข ื ืึธืžืขืŸ ืคื•ืŸ ื“ื™ ืคืึธื˜ืขืจ ืคึผืจืึธืฆืขืก. ืึทืœืฅ ืื™ืŸ ืื™ื™ืŸ ืึธืจื˜, ืœืขืกืึธืฃ!
ืคึฟื•ืŸ ื“ื™ Sysmon ืงืœืึธืฅ ืžื™ืจ ืงืขื ืขืŸ ืคืึทืจืขื ื“ื™ืงืŸ ืึทื– ืžื™ื˜ ืึท ื”ื•ื™ืš ืžืึทืฉืžืึธืขืก ื“ื™ ืกืึทืกืคึผื™ืฉืึทืก ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื” ื•ื•ืึธืก ืžื™ืจ ื’ืขื–ืขืŸ ืื™ืŸ ื“ื™ "ืจื•ื™" ืœืึธื’ืก ืื™ื– ื ื™ืฉื˜ ื“ืขืจ ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ื“ืขืจ ืึธื ื’ืขืฉื˜ืขืœื˜ืขืจ ืก ื ืึธืจืžืึทืœ ืึทืจื‘ืขื˜. ื’ืึทื ืฅ ืคืึทืจืงืขืจื˜, ืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ื“ื•ืจืš ืึท C2-ื•ื•ื™ ืคึผืจืึธืฆืขืก - wmiexec, ื•ื•ื™ ืื™ืš ื“ืขืจืžืื ื˜ ืคืจื™ืขืจ - ืื•ืŸ ืื™ื– ื’ืœื™ื™ืš ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ื“ื™ WMI ืกืขืจื•ื•ื™ืก ืคึผืจืึธืฆืขืก (WmiPrvSe). ืื™ืฆื˜ ืžื™ืจ ื”ืึธื‘ืŸ ืึท ื’ืจืื“ืŸ ืึทื– ืึท ื•ื•ื™ื™ึทื˜ ืึทื˜ืึทืงืขืจ ืึธื“ืขืจ ื™ื ืกื™ื™ื“ืขืจ ืื™ื– ื˜ืขืกื˜ื™ื ื’ ื“ื™ ืคึฟื™ืจืžืข ื™ื ืคืจืึทืกื˜ืจืึทืงื˜ืฉืขืจ.

ื™ื ื˜ืจืึธื•ื“ื•ืกื™ื ื’ Get-Sysmonlogs

ื“ืึธืš ืขืก ืื™ื– ื’ืจื•ื™ืก ื•ื•ืขืŸ Sysmon ืฉื˜ืขืœืŸ ื“ื™ ืœืึธื’ืก ืื™ืŸ ืื™ื™ืŸ ืึธืจื˜. ืึธื‘ืขืจ ืขืก ื•ื•ืึธืœื˜ ืžื™ืกื˜ืึธืžืข ื–ื™ื™ืŸ ืืคื™ืœื• ื‘ืขืกืขืจ ืื•ื™ื‘ ืžื™ืจ ืงืขืŸ ืึทืงืกืขืก ื™ื—ื™ื“ ืงืœืึธืฅ ืคืขืœื“ืขืจ ืคึผืจืึธื’ืจืึทืžืžืึทื˜ื™ืงืึทืœืœื™ - ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ื“ื•ืจืš PowerShell ืงืึทืžืึทื ื“ื–. ืื™ืŸ ื“ืขื ืคืึทืœ, ืื™ืจ ืงืขืŸ ืฉืจื™ื™ึทื‘ืŸ ืึท ืงืœื™ื™ืŸ PowerShell ืฉืจื™ืคื˜ ื•ื•ืึธืก ื•ื•ืึธืœื˜ ืึธื˜ืึทืžื™ื™ื˜ ื“ื™ ื–ื•ื›ืŸ ืคึฟืึทืจ ืคึผืึธื˜ืขื ืฆื™ืขืœ ื˜ืจืขืฅ!
ืื™ืš ื‘ื™ืŸ ื ื™ืฉื˜ ื’ืขื•ื•ืขืŸ ื“ืขืจ ืขืจืฉื˜ืขืจ ื•ื•ืึธืก ื”ืึธื˜ ื’ืขื”ืึทื˜ ืึทื–ืึท ื’ืขื“ืึทื ืง. ืื•ืŸ ืขืก ืื™ื– ื’ื•ื˜ ืึทื– ืื™ืŸ ืขื˜ืœืขื›ืข ืคืึธืจื•ื ืึทืจื˜ื™ืงืœืขืŸ ืื•ืŸ GitHub ืคืจืื™ืขืงื˜ืŸ ืขืก ืื™ื– ืฉื•ื™ืŸ ื“ืขืจืงืœืขืจื˜ ื•ื•ื™ ืฆื• ื ื•ืฆืŸ PowerShell ืฆื• ืคึผืึทืจืก ื“ื™ Sysmon ืงืœืึธืฅ. ืื™ืŸ ืžื™ื™ืŸ ืคืึทืœ, ืื™ืš ื’ืขื•ื•ืืœื˜ ืฆื• ื•ื™ืกืžื™ื™ื“ืŸ ืฆื• ืฉืจื™ื™ึทื‘ืŸ ื‘ืึทื–ื•ื ื“ืขืจ ืฉื•ืจื•ืช ืคื•ืŸ ืคึผืึทืจืกื™ื ื’ ืฉืจื™ืคื˜ ืคึฟืึทืจ ื™ืขื“ืขืจ Sysmon ืคืขืœื“. ืึทื–ื•ื™ ืื™ืš ื’ืขื•ื•ื™ื™ื ื˜ ื“ืขื ืคื•ื™ืœ ืžืขื ื˜ืฉ ืคึผืจื™ื ืฆื™ืคึผ ืื•ืŸ ืื™ืš ื˜ืจืึทื›ื˜ืŸ ืื™ืš ื’ืขืงื•ืžืขืŸ ืึทืจื•ื™ืฃ ืžื™ื˜ ืขืคึผืขืก ื˜ืฉื™ืงืึทื•ื•ืข ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜.
ื“ืขืจ ืขืจืฉื˜ืขืจ ื•ื•ื™ื›ื˜ื™ืง ืคื•ื ื˜ ืื™ื– ื“ื™ ืคื™ื™ื™ืงื™ื™ึทื˜ ืคื•ืŸ ื“ื™ ืžืึทื ืฉืึทืคึฟื˜ ื‘ืึทืงื•ืžืขืŸ-ื•ื•ื™ื ื•ื•ืขื ื˜ ืœื™ื™ืขื ืขืŸ Sysmon ืœืึธื’ืก, ืคื™ืœื˜ืขืจ ื“ื™ ื ื™ื™ื˜ื™ืง ื’ืขืฉืขืขื ื™ืฉืŸ ืื•ืŸ ืจืขื–ื•ืœื˜ืึทื˜ ื“ื™ ืจืขื–ื•ืœื˜ืึทื˜ ืฆื• ื“ื™ PS ื‘ื™ื™ึทื˜ืขื•ื•ื“ื™ืง, ื•ื•ื™ ื“ืึธ:

$events = Get-WinEvent  -LogName "Microsoft-Windows-Sysmon/Operational" | where { $_.id -eq 1 -or $_.id -eq 11}

ืื•ื™ื‘ ืื™ืจ ื•ื•ื™ืœืŸ ืฆื• ืคึผืจื•ื‘ื™ืจืŸ ื“ื™ ื‘ืึทืคึฟืขืœ ื–ื™ืš, ื“ื•ืจืš ื•ื•ื™ื™ึทื–ื ื“ื™ืง ื“ืขื ืื™ื ื”ืึทืœื˜ ืื™ืŸ ื“ืขืจ ืขืจืฉื˜ืขืจ ืขืœืขืžืขื ื˜ ืคื•ืŸ ื“ื™ $ events array, $ events[0]. ืึธื ื–ืึธื’, ื“ืขืจ ืจืขื–ื•ืœื˜ืึทื˜ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืึท ืกืขืจื™ืข ืคื•ืŸ โ€‹โ€‹ื˜ืขืงืกื˜ ืกื˜ืจื™ื ื’ืก ืžื™ื˜ ืึท ื–ื™ื™ืขืจ ืคึผืฉื•ื˜ ืคึฟืึธืจืžืึทื˜: ื“ื™ ื ืึธืžืขืŸ ืคื•ืŸ ื“ื™ ื‘ืึทืคึฟืขืœ. Sysmon ืคืขืœื“, ืึท ืฆื•ื•ื™ื™ืคึผื™ื ื˜ืœ, ืื•ืŸ ื“ืขืžืึธืœื˜ ื“ืขืจ ื•ื•ืขืจื˜ ื–ื™ืš.

Sysmon Threat Analysis Guide, ื˜ื™ื™ืœ 1

ื”ืืจื™ื™! ืึทืจื•ื™ืกืคื™ืจืŸ Sysmon ืงืœืึธืฅ ืื™ืŸ JSON-ื’ืจื™ื™ื˜ ืคึฟืึธืจืžืึทื˜

ืื™ืจ ื˜ืจืึทื›ื˜ืŸ ื“ื™ ื–ืขืœื‘ืข ื–ืึทืš ื•ื•ื™ ืžื™ืจ? ืžื™ื˜ ืึท ื‘ื™ืกืœ ืžืขืจ ืžื™, ืื™ืจ ืงืขื ืขืŸ ื‘ื™ื™ึทื˜ืŸ ื“ื™ ืจืขื–ื•ืœื˜ืึทื˜ ืื™ืŸ ืึท JSON ืคืึธืจืžืึทื˜ื˜ืขื“ ืฉื˜ืจื™ืงืœ ืื•ืŸ ื“ืขืžืึธืœื˜ ืœืึธื“ืŸ ืขืก ื’ืœื™ื™ืš ืื™ืŸ ืึท PS ื›ื™ื™ืคืขืฅ ืžื™ื˜ ืึท ืฉื˜ืึทืจืง ื‘ืึทืคึฟืขืœ. ืงืึธื ื•ื•ืขืจื˜ืคืจืึธื-ื“ื–ืฉืกืึธืŸ .
ืื™ืš ื•ื•ืขื˜ ื•ื•ื™ื™ึทื–ืŸ ื“ื™ PowerShell ืงืึธื“ ืคึฟืึทืจ ื“ื™ ืงืึทื ื•ื•ืขืจื–ืฉืึทืŸ - ื“ืึธืก ืื™ื– ื–ื™ื™ืขืจ ืคึผืฉื•ื˜ - ืื™ืŸ ื“ืขืจ ื•ื•ื™ื™ึทื˜ืขืจ ื˜ื™ื™ืœ. ืื™ืฆื˜, ืœืึธืžื™ืจ ื–ืขืŸ ื•ื•ืึธืก ืžื™ื™ืŸ ื ื™ื™ึทืข ื‘ืึทืคึฟืขืœ ื’ืขืจื•ืคืŸ get-sysmonlogs, ื•ื•ืึธืก ืื™ืš ืื™ื ืกื˜ืึทืœื™ืจืŸ ื•ื•ื™ ืึท ืคึผืก ืžืึธื“ื•ืœืข, ืงืขื ืขืŸ ื˜ืึธืŸ.
ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ื“ื™ื™ื•ื•ื™ื ื’ ื˜ื™ืฃ ืื™ืŸ Sysmon ืงืœืึธืฅ ืึทื ืึทืœื™ืกื™ืก ื“ื•ืจืš ืึท ื•ืžื‘ืึทืงื•ื•ืขื ื’ืขืฉืขืขื ื™ืฉ ืงืœืึธืฅ ืฆื•ื‘ื™ื ื“, ืžื™ืจ ืงืขื ืขืŸ ืขืคืขืจื˜ืœืึทืก ื–ื•ื›ืŸ ืคึฟืึทืจ ื™ื ืงืจืึทืžืขื ื˜ืึทืœ ื˜ืขื˜ื™ืงื™ื™ื˜ ื’ืœื™ื™ึทืš ืคึฟื•ืŸ ืึท PowerShell ืกืขืกื™ืข, ืื•ืŸ ื ื•ืฆืŸ ื“ื™ PS ื‘ืึทืคึฟืขืœ. ื•ื•ื• (ืึทืœื™ืึทืก - "?") ืฆื• ืคืึทืจืงื™ืจืฆืŸ ื“ื™ ื–ื•ื›ืŸ ืจืขื–ื•ืœื˜ืึทื˜ืŸ:

Sysmon Threat Analysis Guide, ื˜ื™ื™ืœ 1

ืจืฉื™ืžื” ืคื•ืŸ ืงืžื“ ืฉืขืœื– ืœืึธื ื˜ืฉื˜ ื“ื•ืจืš WMI. ืกืึทืงืึธื ืข ืึทื ืึทืœื™ืกื™ืก ืื•ื™ืฃ ื“ื™ ื‘ื™ืœื™ืง ืžื™ื˜ ืื•ื ื“ื–ืขืจ ืื™ื™ื’ืขื ืข ื‘ืึทืงื•ืžืขืŸ-Sysmonlogs ืžืึทื ืฉืึทืคึฟื˜

ื•ื•ื•ื ื“ืขืจืœืขืš! ืื™ืš ื‘ืืฉืืคืŸ ืึท ื’ืขืฆื™ื™ึทื’ ืฆื• ื‘ืึทืงื•ืžืขืŸ ื“ื™ Sysmon ืงืœืึธืฅ ื•ื•ื™ ืื•ื™ื‘ ืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ืึท ื“ืึทื˜ืึทื‘ื™ื™ืก. ืื™ืŸ ืื•ื ื“ื–ืขืจ ืึทืจื˜ื™ืงืœ ื•ื•ืขื’ืŸ IQ ืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ื‘ืืžืขืจืงื˜ ืึทื– ื“ื™ ืคื•ื ืงืฆื™ืข ื•ื•ืขื˜ ื–ื™ื™ืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ื“ื•ืจืš ื“ื™ ืงื™ืœ ื ื•ืฆืŸ ื“ื™ืกืงืจื™ื™ื‘ื“ ืื™ืŸ ืขืก, ื›ืึธื˜ืฉ ืคืึธืจืžืึทืœื™ ื ืึธืš ื“ื•ืจืš ืึท ืคืึทืงื˜ื™ืฉ ืกืงืœ-ื•ื•ื™ ืฆื•ื‘ื™ื ื“. ื™ืึธ, EQL ืขืœืขื’ืึทื ื˜, ืื‘ืข ืจ ืžื™ ืจ ืฐืขืœืข ืŸ ืื™ ื ื ื“ืจื™ื˜ืข ืŸ ื˜ืฒืœ ืจ ืื ืจื™ืจืŸ .

Sysmon ืื•ืŸ ื’ืจืึทืคื™ืง ืึทื ืึทืœื™ืกื™ืก

ื–ืืœ ืก ื˜ืจืขื˜ืŸ ืฆื•ืจื™ืง ืื•ืŸ ื˜ืจืึทื›ื˜ืŸ ื•ื•ืขื’ืŸ ื•ื•ืึธืก ืžื™ืจ ื ืึธืจ ื‘ืืฉืืคืŸ. ื™ืกืขื ืฉืึทืœื™, ืžื™ืจ ืื™ืฆื˜ ื”ืึธื‘ืŸ ืึท Windows ื’ืขืฉืขืขื ื™ืฉ ื“ืึทื˜ืึทื‘ื™ื™ืก ืฆื•ื˜ืจื™ื˜ืœืขืš ื“ื•ืจืš PowerShell. ื•ื•ื™ ืื™ืš ื‘ืืžืขืจืงื˜ ืคืจื™ืขืจ, ืขืก ื–ืขื ืขืŸ ืงืึทื ืขืงืฉืึทื ื– ืึธื“ืขืจ ื‘ืืฆื™ื•ื ื’ืขืŸ ืฆื•ื•ื™ืฉืŸ ืจืขืงืึธืจื“ืก - ื“ื•ืจืš ื“ื™ ParentProcessId - ืึทื–ื•ื™ ืึท ื’ืึทื ืฅ ื›ื™ื™ืขืจืึทืจืงื™ ืคื•ืŸ ืคึผืจืึทืกืขืกืึทื– ืงืขื ืขืŸ ื–ื™ื™ืŸ ื‘ืืงื•ืžืขืŸ.

ืื•ื™ื‘ ืื™ืจ ื”ืึธื˜ ืœื™ื™ืขื ืขืŸ ื“ื™ ืกืขืจื™ืข "ื“ื™ ืึทื“ื•ื•ืขื ื˜ื•ืจืขืก ืคื•ืŸ ื“ื™ ื™ืœื•ืกื™ื•ื• ืžืึทืœื•ื•ืึทืจืข" ืื™ืจ ื•ื•ื™ืกืŸ ืึทื– ื›ืึทืงืขืจื– ืœื™ื‘ืข ืฆื• ืฉืึทืคึฟืŸ ืงืึธืžืคึผืœืขืงืก ืžืึทืœื˜ื™-ื‘ื™ื ืข ืื ืคืืœืŸ, ืื™ืŸ ื•ื•ืึธืก ื™ืขื“ืขืจ ืคึผืจืึธืฆืขืก ืคื™ืขืกืขืก ื–ื™ื™ืŸ ืื™ื™ื’ืขื ืข ืงืœื™ื™ืŸ ืจืึธืœืข ืื•ืŸ ืคึผืจื™ืคึผืขืจื– ืึท ืกืคึผืจื™ื ื’ื‘ืึธืจื“ ืคึฟืึทืจ ื“ืขืจ ื•ื•ื™ื™ึทื˜ืขืจ ืฉืจื™ื˜. ืขืก ืื™ื– ื’ืึธืจ ืฉื•ื•ืขืจ ืฆื• ื›ืึทืคึผืŸ ืึทื–ืึท ื–ืื›ืŸ ืคืฉื•ื˜ ืคื•ืŸ ื“ื™ "ืจื•ื™" ืงืœืึธืฅ.
ืึธื‘ืขืจ ืžื™ื˜ ืžื™ื™ืŸ Get-Sysmonlogs ื‘ืึทืคึฟืขืœ ืื•ืŸ ืึทืŸ ื ืึธืš ื“ืึทื˜ืŸ ืกื˜ืจื•ืงื˜ื•ืจ ื•ื•ืึธืก ืžื™ืจ ื•ื•ืขืœืŸ ื–ืขืŸ ืฉืคึผืขื˜ืขืจ ืื™ืŸ ื“ืขื ื˜ืขืงืกื˜ (ืึท ื’ืจืึทืคื™ืง, ืคื•ืŸ ืงื•ืจืก), ืžื™ืจ ื”ืึธื‘ืŸ ืึท ืคึผืจืึทืงื˜ื™ืฉ ื•ื•ืขื’ ืฆื• ื“ืขื˜ืขืงื˜ ื˜ืจืขืฅ - ื•ื•ืึธืก ื ืึธืจ ืจื™ืงื•ื•ื™ื™ืขืจื– ื“ื™ ืจืขื›ื˜ ื•ื•ืขืจื˜ืขืงืก ื–ื•ื›ืŸ.
ื•ื•ื™ ืฉื˜ืขื ื“ื™ืง ืžื™ื˜ ืื•ื ื“ื–ืขืจ DYI ื‘ืœืึธื’ ืคึผืจืึทื“ื–ืฉืขืงืก, ื“ื™ ืžืขืจ ืื™ืจ ืึทืจื‘ืขื˜ ืื•ื™ืฃ ืึทื ืึทืœื™ื™ื–ื™ื ื’ ื“ื™ ื“ืขื˜ืึทื™ืœืก ืคื•ืŸ ื˜ืจืขืฅ ืื•ื™ืฃ ืึท ืงืœื™ื™ืŸ ื•ื•ืึธื’, ื“ื™ ืžืขืจ ืื™ืจ ื•ื•ืขื˜ ืคืึทืจืฉื˜ื™ื™ืŸ ื•ื•ื™ ืงืึธืžืคึผืœืขืงืก ืกืึทืงืึธื ืข ื“ื™ื˜ืขืงืฉืึทืŸ ืื™ื– ืื•ื™ืฃ ื“ื™ ืคืึทืจื ืขืžื•ื ื’ ืžื“ืจื’ื”. ืื•ืŸ ื“ืขื ื•ื•ื™ืกื™ืงื™ื™ึทื˜ ืื™ื– ื’ืึธืจ ื•ื•ื™ื›ื˜ื™ืง ืคื•ื ื˜.

ืžื™ืจ ื•ื•ืขืœืŸ ื˜ืจืขืคืŸ ื“ื™ ืขืจืฉื˜ืข ื˜ืฉื™ืงืึทื•ื•ืข ืงืึทืžืคึผืœืึทืงื™ื™ืฉืึทื ื– ืื™ืŸ ื“ื™ ืจื’ืข ื˜ื™ื™ืœ ืคื•ืŸ ื“ืขื ืึทืจื˜ื™ืงืœ, ื•ื•ื• ืžื™ืจ ื•ื•ืขืœืŸ ืึธื ื”ื™ื™ื‘ืŸ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ Sysmon events ืžื™ื˜ ื™ืขื“ืขืจ ืื ื“ืขืจืข ืื™ืŸ ืคื™ืœ ืžืขืจ ืงืึธืžืคึผืœื™ืฆื™ืจื˜ ืกื˜ืจืึทืงื˜ืฉืขืจื–.

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’