Githabifizierung der Informationssicherheit

Auf dem Weg zu einem offenen, herstellerunabhängigen und Community-freundlichen Modell zur Beschleunigung des Informationssicherheitstrainings


8. Dezember 2019


John Lambert JohnLaTwC, Distinguished Engineer, Microsoft Threat Intelligence Center


Anmerkung


Die Kombination von Informationssicherheitsspezialisten innerhalb der globalen Gemeinschaft beschleunigt die fachspezifische Ausbildung.


, MITRE ATT&CK, , Sigma , Jupyter Notebooks, . .


, , , .


Alt-Text



" — , — ." —

. , . , 10 000 , . , — , , , . , , , — .


, ? , .


, , . , , . " ". : , . .



" , " —

. . - . , — . .


, , MITRE ATT&CK. , . " Windows" T1015. , , , .


Alt-Text
Alt-Text
Alt-Text


MITRE ATT&CK :


  • . ATT&CK , , , ( , , ).
  • . ATT&CK . , MITRE. ATT&CK , ( ), , .
  • . ATT&CK , ATT&CK , , , . .

. :



, MITRE ATT&CK — , , .



" " — .

— , . . . , " ". MITRE ATT&CK.


T1015, , , . cmd.exe, , , winlogon.exe SYSTEM (). .


, , , . (SIEM/LM ) .


: Splunk Search Processing Language (SPL), ElasticSearch — Domain Specific Language (DSL), Microsoft Defender ATP — Keyword Query Language (KQL). , Yara Snort ...


Sigma, , . Sigma — , (@cyb3rops) (@blubbfiction), ("") . , Sigma , Splunk, ElasticSearch, QRadar . SOC Prime - https://uncoder.io/, Sigma, . Sigma Sigma . Sigma .


Alt-Text


Sigma ATT&CK T1015, ? :


Alt-Text


Sigma, ? :


  • Sigma , ( , , MITRE ATT&CK ..). Sigma , , . , , .
  • . Sigma SIEM/LM , . . Sigma , (, , ). , Red Teaming, Sigma, Purple Teaming.
  • , , . Sigma Yara Snort.

MITRE ATT&CK , , Sigma , , - . , , .



" . ." — , " "

, , . , . . ? , ? - , ? , ?


. , - , . Jupyter Notebook.


Jupyter?


Jupyter — , , . :


  • — Notebook. , , . . Notebook , , . Notebook Python ( ) , Pandas. , Notebook . Jupyter — GitHub 5 Notebook.
  • Notebook . , . GitHub, . - Notebook, . . Notebook — , .
  • Jupyter Notebook . Jupyter Notebook - "", — , Notebook ( Python, .NET ) . Notebook Windows, Linux, Mac . , , .

Jupyter Notebook


Notebook . — , , . : PowerShell, . , Magic Unicorn, . Notebook , Base64 , . CyberChef :


Alt-Text


PowerShell, :


Alt-Text


Base64, :


Alt-Text


, :


Alt-Text


API, :


Alt-Text


, Windows API (InternetConnectA, HttpSendRequestA, ..) , (VirtualAlloc), : "Magic Unicorn — PowerShell Downgrade Attack ". — (Dave Kennedy, @HackingDave).


, Notebook, . , (Roberto Rodriguez) , Jupyter Notebook . ThreatHunterPlaybook Project Jupyter . Netscylla , Notebook . Notebook, GitHub, binder:


Alt-Text


Jupyter , , , , . , Jupyter . Jupyter Notebook .



. , , . MITRE ATT&CK , , ( Office 365), .


Alt-Text


Office 365 MITRE ATT&CK:


Alt-Text


, (Swetha Prabakaran).


(Florian Roth, @cyb3rops) Sigma GitHub. , "Pull request" — . Pull Request Sigma:


Alt-Text


— Open Security Collaborative Development (OSCD) — . 2019 , Sigma MITRE ATT&CK. Sigma 40%:


Alt-Text


.



, . , . , MITRE ATT&CK. Sigma. Jupyter Notebook.


, , CERT, , , . , , . , .


? :


  • , .
  • , — "Pull Request"
  • GitHub.com, . , GitHub, — .

Alt-Text



, , , , .


, ? :


, :



:



:



:


  • -, ATT&CK, Sigma Jupyter Notebook
  • Python Jupyter Notebook
  • , MITRE ATT&CK, Sigma Jupyter Notebook

CERT , :


  • Sigma
  • MITRE ATT&CK


(Freddy Dezeure, @FDezeure), (Florian Roth, @cyb3rops), (Thomas Patzke, @blubbfiction), (Leah Lease, @LeahLease), (Tim Burrell, @TimbMsft), (Ian Hellen, @ianhellen) (Roberto Rodriguez, @Cyb3rWard0g) , , , , (@denisbalan), (@noesall), (@zinint), (@MazahakaJay), , - (@SuslikDaRete), (@l1c3t), (@AlienJolka), Oleg Chepurchenko, Michael Tyomkin, Sveta Gaivoronski, Fanta Orr, (@yugoslavskiy) .





, . , .


ATT&CK


  • Sigma Yara
  • , TTP, MORDOR
  • ,

Sigma


  • , , (join), ;
  • ( , , "process_creation", Sysmon Event ID 1 Windows Event ID 4688)

Jupyter


  • Python
  • :
  • (IP-, , ..)
  • , ,

Source: https://habr.com/ru/post/undefined/


All Articles