ãã ããå®éã«ã¯ããªã³ã©ã€ã³ãµã³ãããã¯ã¹ã䜿çšããŠãåé¡ã解決ã§ããªãå ŽåãããªããããŸãã ããã¯ã次ã®ãããªããŸããŸãªèŠå ãåå ã§ããå¯èœæ§ããããŸãã
-ã€ã³ã¿ãŒããããžã®ã¢ã¯ã»ã¹ãé£ãã
-çŸåšããªã³ã©ã€ã³ãµã³ãããã¯ã¹ã¯éè² è·ã«ãªã£ãŠãããåæã¯ã¿ã€ã ã¯ãªãã£ã«ã«ã§ã
-ãªã³ã©ã€ã³ãµã³ãããã¯ã¹ã§ã®å®è¡ã¯ã調æ»ãããã¡ã€ã«ã«ãã£ãŠãããã¯ãããŸã
-åæäžã«ãã¡ã€ã«ã®å®è¡ã¢ãŒããããã«åŸ®èª¿æŽããå¿ èŠããããŸããããšãã°ãèµ·åæããã®é 延æéã®å¢å
ãã®å Žåãåé¡ã®ãªãã©ã€ã³ãœãªã¥ãŒã·ã§ã³ãå©ãã«ãªããŸãã
ã»ãŒãã¹ãŠã®ãµã³ãããã¯ã¹ã®äœæ¥ã®æ¬è³ªã¯ãã·ã¹ãã ã«å ããããå€æŽã®ä»®æ³åã«ãããå¶åŸ¡ãããç°å¢ã§ã®ããã°ã©ã ã®å®è¡ãå¶éããããšã§ãã ãã¡ããããã®åé¡ã®çæ³çãªè§£æ±ºçã¯ãã¹ãããã·ã§ããã«ããŒã«ããã¯ã§ããä»®æ³ãã·ã³ã§ã³ãŒããå®è¡ããããåãããŒã«ããã¯ã®å¯èœæ§ãããã·ã¹ãã ã®ã»ã¯ã¿ãŒããšã®å®å šãªããã¯ã¢ãããããç©çãã·ã³ã§å®è¡ããããšã§ãã ãããŠãããã¯çµ¶å¯Ÿã«çå®ã§ããäžçäžã®ã¢ããªã¹ããåãããã«äœæ¥ãããã§ã«ã¬ãã¥ãŒãããªã³ã©ã€ã³ãµã³ãããã¯ã¹ãåãããã«æ©èœããŸãã ãã ãããã®å Žåãã·ã¹ãã ãã¬ãžã¹ããªãªã©ã®å€æŽã調æ»ããããã«ãã¡ã¢ãªãã³ããæåã§åé€ããã³åæããå¿ èŠããããŸãã ãã®äœæ¥ãèªåçã«å®è¡ããããã€ãã®ãœãªã¥ãŒã·ã§ã³ãæ€èšããŸãã ãŸãããŸãã¯ã»ãŒèªåçã«:)
ã¬ãã¥ãŒã§ã¯ãåçŽãªãã®ããè€éãªãã®ãã¢ã¯ã»ã¹ãããããã®ããå°é£ãªãã®ãèªåããæåã®ãã®ã«ç§»è¡ããŸãã ãã®ã¢ãããŒãã§ã¯ãéå±ãã人ã¯å»ããéèŠãªãã®ã倱ãããšã¯ãªãããã§ã:)
Buster Sandbox Analyzer + SandboxIE Complex
SandboxIEã¯ãããããäžè¬ã«å ¬éãããŠããæãææãªãµã³ãããã¯ã¹ããã°ã©ã ã®1ã€ã§ãã ããã¯ããã€ãã®èŠå ã«ãããã®ã§ãããå°ãªããšããããã®ã»ãšãã©ã¯ãèè ã«ããããã°ã©ã ã®ç¶ç¶çãªãµããŒããšæŽæ°ãããã³ã»ãŒãã¹ãŠã®æ©èœãåããç¡æã®ãŠãŒã¹ã±ãŒã¹ã®å©çšå¯èœæ§ã§ãïŒãããã«ãããç®çã«ã¯ååã§ãïŒã æãéèŠãªã®ã¯ãSandboxIEãæ©èœãæ¡åŒµãããã©ã°ã€ã³ããµããŒãããŠããããšã§ãã
ãã®ãããªãã©ã°ã€ã³ã®1ã€ã¯ã Buster Sandbox AnalyzerãŸãã¯BSAã§ãã ãã®ãã©ã°ã€ã³ã¯ããã§ã«èª¬æããCWSandboxãšã»ãŒåãããã«æ©èœããŸãã調æ»äžã®ããã»ã¹ã®ã¢ãã¬ã¹ç©ºéã«åçã©ã€ãã©ãªãåã蟌ã¿ãå®è¡äžã«APIåŒã³åºãã远跡ã§ããããã«ããŸãã ããã«ããã®ããã°ã©ã ã䜿çšãããšããããã¯ãŒã¯ã¢ã¯ãã£ããã£ãç£èŠããå€æŽããããã¡ã€ã«ããã®ä»ã®æçšãªãã®ãåæã§ããŸãã
ãã®ã·ã¹ãã ã®åäœãè©äŸ¡ããããã«ãæåã«æ§ç¯ããŸãã ããã«ãSandboxIEã«æ¬¡ã®2ã€ã®ã¢ããªã³ãããŠã³ããŒãããå¿ èŠããããŸãïŒ Block Process AccessãšAntidel ã ãããã®ãã©ã°ã€ã³ã䜿çšãããšãäžæ¹ã§ããµã³ãããã¯ã¹å€ã®ä»ã®ããã»ã¹ã®ååšãåæäžã®ããã»ã¹ããé ãããšãã§ããä»æ¹ã§ãäœæ¥äžã®ãã¡ã€ã«ã®åé€ãé²ãããšãã§ããŸãïŒäžéšã®ãããããŒãåæããå Žåã«äŸ¿å©ã§ãïŒã
次ïŒ
1. SandboxIEãã€ã³ã¹ããŒã«ããŸãã
2.ãµã³ãããã¯ã¹ããè¿œå ã®ãµã³ãããã¯ã¹ãäœæããŸã-æ°ãããµã³ãããã¯ã¹ãäœæããŸã ã ç§ã¯ãããBSAãšåŒã³ãŸãã-ããšãããªããåçŽåã®ããã«åããã®ãæã£ãŠãããšããŠãã
3.ããã°ã©ã ãŠã£ã³ããŠã®ãªã¹ãã§BSAãµã³ãããã¯ã¹ãå³ã¯ãªãã¯ãã[ ãµã³ãããã¯ã¹èšå®]ãéžæããŸãã
4.ã¯ãªãã£ã«ã«ïŒ
åäœ -ãŠã£ã³ããŠã®åšå²ã«å¢çç·ã衚瀺-èµ€ãéžæ
å埩 ã -å³æå埩-Dawãåé€ããéåžžãåäžã®ãã©ã«ããå埩äžã§ãªãããšã確èªããŸãã
åé€ -åé€ã«é¢ãããã¹ãŠã®DAWãåé€ããŸãã
å¶é -ã€ã³ã¿ãŒãããã¢ã¯ã»ã¹-ãããã°ã©ã ã¯ã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ã§ããŸããããšè¡šç€ºããããŸã§ããã¹ãŠã®ããã°ã©ã ãåé€ããŸãã ãã®ãªãã·ã§ã³ãèŠããŠãããŠãã ãã-ããã€ãã®ãã«ãŠã§ã¢ãžã®ã¢ã¯ã»ã¹ãéãå¿ èŠããããŸããããã®å Žåããã¹ããã·ã³ããã®ãã¹ãŠã®ãã¹ã¯ãŒããšæ å ±ã¯æ»æè ã«å§ããããããšã«æ³šæããŠãã ããã
å¶é -å®è¡ããã³å®è¡ã¢ã¯ã»ã¹-ãã¹ãŠèš±å¯ã
äœã¬ãã«ã®ã¢ã¯ã»ã¹ãšããŒããŠã§ã¢ -ãã¹ãŠã®ãžã£ãã¯ããŒãè±ããŸãã ããã¯éèŠã§ãããããªããšãTDSSãMebratixãMebrootãªã©ã®äœã¬ãã«ã®ãŠã€ã«ã¹ããµã³ãããã¯ã¹ããã·ã¹ãã ã«ã¯ããŒã«ãããŸãã
ä»ã®ãªãã·ã§ã³ã¯ããã©ã«ãã§æ®ããŠããå¿ èŠããããŸãã å°æ¥çã«ã¯ã奜ã¿ã«åãããŠã«ã¹ã¿ãã€ãºã§ããŸãããã¹ãŠãååã«æ確ã«ãªã£ãŠããŸãã
5. SandboxIEãã€ã³ã¹ããŒã«ãããã©ã«ããŒã«Buster Sandbox Analyzerãã©ã«ããŒãäœæããŸãããã®ãã©ã«ããŒã«ã¯ãäžèšã§ããŠã³ããŒããããã¹ãŠã®ãã®ã解åãããŸãã
6. LOG_API.DLLãã¡ã€ã«ã®ååã¯ãå¿ èŠãªååã«å€æŽãããŸãã ç§ã¯ãããLAPI.DLLãšåŒã³ãŸããã ãŸããHideDriver.sysã®ååãå€æŽããŸãã
7.ã¡ã€ã³ã®SandboxIEãŠã£ã³ããŠã§ã[ æ§æ]- [ æ§æã®ç·šé]ãéžæããŸãã éããããã¹ãããã¥ã¡ã³ãã§ã¯ããããã®æåã®ããäžã«BSAã»ã¯ã·ã§ã³ããããè¡ãè¿œå ããŠããŸãã
InjectDll=C:\Program Files\SandboxIE\Buster Sandbox Analyzer\sbiextra.dll
InjectDll=C:\Program Files\SandboxIE\Buster Sandbox Analyzer\antidel.dll
InjectDll=C:\Program Files\SandboxIE\Buster Sandbox Analyzer\LAPI.dll
OpenWinClass=TFormBSA
ãã¡ããããã¹ã¯ç°ãªãå ŽåããããŸãã ããããæ³šå ¥ãããã©ã€ãã©ãªã®é åºã¯ãã®ããã§ãªããã°ãªããŸãã ïŒ
次ã«ã GlobalSettingsã»ã¯ã·ã§ã³ãç¹ã«FileRootPathãã©ã¡ãŒã¿ãŒã«æ³šæããŠãã ããã
FileRootPath=C:\Sandbox\%SANDBOX%
ïŒããªãã«ãã£ãŠç°ãªãå ŽåããããŸãïŒã
ãã®æå³ãèŠããŠãããŠãã ããã
8.å ã®ãã¹ã«åŸã£ãŠããã¹ããã¡ã€ã«ãä¿åããŸãã SandboxIEã®ã¡ã€ã³ãŠã£ã³ããŠã§ã[ æ§æ]- [ æ§æã®åèªã¿èŸŒã¿]ãéžæããŸãã
9. SandboxIEã®ã¡ã€ã³ãŠã£ã³ããŠã§ã以äžãéžæããŸãã æ§æ -Windowsãšã¯ã¹ãããŒã©ãŒãžã®çµ±å-SandboxIE管çã®èµ·å-ããã°ã©ã ããµã³ãããã¯ã¹ã§èµ·åããããµã³ãããã¯ã¹ã§å®è¡ã ã¢ã¯ã·ã§ã³ -ãã¡ã€ã«ãšãã©ã«ããŒã®ããµã³ãããã¯ã¹ã§å®è¡ãã³ã³ããã¹ãã¡ãã¥ãŒé ç®ãè¿œå ããŸãã
10. Buster Sandbox Analyzerãå®è¡ããŸãïŒæåã§ãbsa.exeãå®è¡ããŠåãååã®ãã©ã«ããŒããã
11. [ ãªãã·ã§ã³] -[åæã¢ãŒã]-[æåããã³ãªãã·ã§ã³] -[ããã°ã©ã ãªãã·ã§ã³]-[Windows Shell Intagration]ãéžæããå³ã¯ãªãã¯ã¢ã¯ã·ã§ã³ãRun BSAããè¿œå ããŸãã
ãã¹ãŠãä»äºã®æºåãã§ããŠããŸãã
䜿ãæ¹ã¯ïŒ
1.åžžé§ã¢ã³ããŠã€ã«ã¹ãç¡å¹ã«ããŸãïŒããå ŽåïŒã
2.æ€èšäžã®ããã»ã¹ã«ããŠã¹ãåãã[ BSAã®å®è¡ ]ãå³ã¯ãªãã¯ããŸã ã BSAãŠã£ã³ããŠãéããŸãã
3. FileRootPath SandboxIEãã©ã¡ãŒã¿ãŒïŒäžèšåç §ïŒã®å€ã«äžèŽãããã©ã«ããŒãSandboxãã©ã«ããŒã§æå®ãããŠããããšã確èªããŸã ãïŒ SANDBOXïŒ ã®ä»£ããã«BSAã®ã¿ã瀺ãããŸãã ç§ã®å Žåããã©ã¡ãŒã¿ã§
FileRootPath=C:\Sandbox\%SANDBOX%
BSAã§ã¯
C:\Sandbox\BSA
4. [åæã®éå§]ãã¯ãªãã¯ããŸãã
5.æ€èšäžã®ããã»ã¹ã«ããŠã¹ãåãããµã³ãããã¯ã¹ã§ [ å®è¡ ]ãå³ã¯ãªãã¯ããŸã ã ææ¡ããããµã³ãããã¯ã¹ã®ãªã¹ãã§ãBSAãéžæããŸãã
ããã ãã§ã ããã»ã¹ãé²ã¿ãŸãã ã¡ã€ã³ã®SandboxIEãŠã£ã³ããŠã«ãBSAã®APIåŒã³åºãã®ãã°ãšã¢ã¯ãã£ããªããã»ã¹ã衚瀺ãããŸãã ããã»ã¹ãçµäºããããšãããã°ãBSAã§[åæã®ââçµäº]ãã¯ãªãã¯ããŸããã¢ã¯ãã£ããªBSAãµã³ãããã¯ã¹ã®çµäºããã°ã©ã ãå³ã¯ãªãã¯ããŠãSandboxIEã«æ·»ä»ããå¿ èŠããããŸãïŒããšãã°ããã¡ã€ã«ææè ã®å ŽåïŒã
å®äºãããšãBSAã¯ã·ã¹ãã ã®å€æŽã«é¢ãã詳现ãªã¬ããŒããçºè¡ããŸããããã¥ãŒã¢ãŒã䜿çšããŠä»ã®ã¬ããŒãã衚瀺ããããšãã§ããŸãã ã·ã¹ãã ã«WinPcapãé 眮ãããšããµã³ãããã¯ã¹ãããã±ãããã€ã³ã¿ãŒã»ããããããšãã§ããŸãããããã§ã¯ããŸãæŽçãããŠããŸãããããšãã°ãUDPãã±ããã®ããŒãœãã©ã€ãºã¯ãããŸããã ããããæ¬åœã«ãããå Žåã¯å¯èœã§ãããåæã«ãã¹ãã·ã¹ãã ã§ãã¹ãŠã®ãããã¯ãŒã¯ã¢ããªã±ãŒã·ã§ã³ãç¹ã«æ¥æµãoutæ» ããå¿ èŠããããŸãã
äœæ¥åŸãå³ããŠã¹ãã¿ã³ã§BSAãµã³ãããã¯ã¹ãã¯ãªãã¯ãããšã [ã³ã³ãã³ãã®è¡šç€º]ãéžæããäœæ¥äžã«ããã»ã¹ã«ãã£ãŠäœæãŸãã¯å€æŽããããã¹ãŠã®ãã¡ã€ã«ã確èªã§ããŸãã
BSAãã°ãšãµã³ãããã¯ã¹ãã¡ã€ã«ã¯ãæ°ãã調æ»ããã»ã¹ã次ã«éå§ããããŸã§ä¿åãããŸãã
調æ»ãããã¡ã€ã«ã«ãã£ãŠã·ã¹ãã ã«å ããããå€æŽãçŽæ¥åæã§ããããšã«æ³šæããŠãã ããã ä»®æ³åãããã¬ãžã¹ããªãCïŒ\ Sandbox \ ïŒ SANDBOXïŒ \ RegHiveã«ä¿åãããŠããå Žåããã®ã³ãã³ãã¹ã¯ãªããã䜿çšããŠãç解å¯èœãªã圢åŒã«å€æããã®ã¯éåžžã«ç°¡åã§ãã
REG LOAD HKLM\uuusandboxuuu C:\Sandbox\ DefaultBox \RegHive
REG EXPORT HKLM\uuusandboxuuu C:\Sandbox\sandbox.reg
REG UNLOAD HKLM\uuusandboxuuu
ãDefaultBoxãã¯ãã¹ãŠã®äººã«ãšã£ãŠåå¥ã®ãã®ã«ãªãããšã«çæããŠãã ããããã ããããã«ã€ããŠã¯ãã§ã«äžèšã§èª¬æããŸããã
çµæã®sandbox.regãã¡ã€ã«ã«ã¯ãã¬ãžã¹ããªã«å ããããåæã容æãªãã¹ãŠã®å€æŽãå«ãŸããŸãã
SandboxIEãããã»ã¹ã«åçã©ã€ãã©ãªãæ¿å ¥ããæ©èœã¯ãPEå®è¡å¯èœãã¡ã€ã«ãšããŠã§ã¯ãªããããã»ã¹ã¢ãã¬ã¹ç©ºéã«æ¿å ¥ãããããŸãã¯ãµãŒãã¹ãšããŠç»é²ãããã©ã€ãã©ãªãšããŠå®è¡ãããæªæã®ããã³ãŒãã«ãã£ãŠå¹æçã«äœ¿çšã§ããŸãã ããããããã¯ãŸã£ããç°ãªãå°é£ãªäŒè©±ã§ãã
ãŒãã¯ã€ã³
æªæã®ããã³ãŒãã®èª¿æ»ãèªååããããã®æãäžè¬çãªæ¹æ³ã®1ã€ã¯ãPythonã¹ã¯ãªããã䜿çšããŠLinuxã·ã¹ãã ã§å€ãã®æäœãšãŠãŒãã£ãªãã£ã®å®è¡ãçµåããããšã§ãã ããã¯ãJoxean KoretãZeroWineãããžã§ã¯ããäœæãããšãã«è¡ã£ãããšã§ãã ZeroWineã¯ãDebianã«åºã¥ããŠæ§ç¯ãããQEmuä»®æ³ãã·ã³ã€ã¡ãŒãžïŒãã ããVBoxãVMWareãå«ãä»ã®ã·ã¹ãã ã«ç°¡åã«å€æã§ããŸãïŒã§ãã æªæã®ãããã¡ã€ã«ã¯Webã€ã³ã¿ãŒãã§ã€ã¹çµç±ã§ããŠã³ããŒãã§ããŸãããã®çµæãã¯ã€ã³ç°å¢ã§å®è¡ããããã®åäœã¯Pythonã¹ã¯ãªããã«ãã£ãŠèªååãããå€æ°ã®ãŠãŒãã£ãªãã£ã«ãã£ãŠå¶åŸ¡ãããŸãã ãã®çµæããŠãŒã¶ãŒã¯åŒã³åºãããã³ãã³ããããã»ã¹ã¡ã¢ãªãã³ãããããã¯ãŒã¯ãã±ããã®ååãªã©ã«é¢ããæ å ±ãååŸã§ããŸãã
ZeroWineãããžã§ã¯ãã®ãã1ã€ã®ãé¡ãã¯ZeroWine-tryoutsã§ãã ããã€ãã®è¿œå æ©èœãå°å ¥ãããŸããã
æ®å¿µãªãããwineã䜿çšããŠããWindowsã«å¹æµãããã«ãŠã§ã¢ç°å¢ãå®å šã«äœæãããããã§ã¯ãããŸããã ãã®çµæãã³ãŒãã®å®è¡ã¯å®å šã«ç°ãªãå Žåããããå Žåã«ãã£ãŠã¯ãŸã£ããå®è¡ãããªãããšããããŸãã èè èªèº«ãã圌ã®ããã°ã©ã ã®å€ãã®æ¬ ç¹ãšãç 究äžã®ããã»ã¹ã®åŽé¢ããã¯ã€ã³ç°å¢ã§ã®å®è¡ãæ€åºããç°¡åãªæ¹æ³ãææããŠããŸãã ãŸããäœæè ã®ãŠã§ããµã€ãã®ã¹ã¯ãªãŒã³ã·ã§ããã«è¡šç€ºããããã°ã¯ãææã¡ã«ããºã ã®ç解ãšæ²»çããã»ã¹ã®èšç»ã«ã»ãšãã©åœ¹ç«ã¡ãŸããããããããã«ãŠã§ã¢ã«å¯Ÿãã眲åãŸãã¯è¡åä¿è·ãæ§ç¯ããã¢ããªã¹ãã«ãšã£ãŠèå³æ·±ããã®ã§ãã
ZeroWineã¯æšå¹Ž12æã«æŽæ°ãããŸããããå人çã«ã¯ïŒ2009幎以éïŒZeroWineã®ãã©ã€ã¢ãŠãããã奜ãã§ãã-ã¹ãã£ã³ã®ããæè»ãªèšå®ãšå¶åŸ¡ã®ããããŸãã¯å€åããã¯ç§ããå§ãŸã£ãããã§ãéåžžãæ°ããããŒãžã§ã³ãšã¯ç°ãªããŸã:)
åæ£åæã·ã¹ãã
ãããã¯ãåæçæ§è³ªã®äžã§æãæ·±å»ã§è€éãªæ±ºå®ã§ãã éåžžãåæ£ã·ã¹ãã ã¯ããµãŒããŒãšããŠæ©èœããææããWindowsã·ã¹ãã ããåä¿¡ãããã³ããšãã°ãåãå ¥ããŠåŠçããLinuxã·ã¹ãã ã§ãã ãã®ãããªã¡ã«ããºã ã¯ãä»®æ³ãã·ã³ãŸãã¯Linuxãã¹ããšã®ä»®æ³Windowsã²ã¹ãã®çžäºäœçšã®ãã¬ãŒã ã¯ãŒã¯ã§æ§ç¯ã§ããŸãã MINIBISã¯æåŸã®ååã«åºã¥ããŠæ§ç¯ãããŠããŸããUbuntuç°å¢ã§ä»®æ³Windows XPãå®è¡ããããšã«åºã¥ããŠããã®ãããªã·ã¹ãã ãå±éããããã«å¿ èŠãªãã®ããã¹ãŠèªç±ã«ããŠã³ããŒãã§ããŸãã å¥ã®èå³æ·±ãã¢ãããŒãã¯ãEtherãããžã§ã¯ãã®ããã«ãã€ããŒãã€ã¶ãŒã䜿çšããããšã§ãã
ãã ãããã®åé¡ãçå£ã«èããå Žåãæãæ£ããã¢ãããŒãã¯ã2å°ã®ç©çãã·ã³ã«åºã¥ããŠç¬èªã®ã·ã¹ãã ãæ§ç¯ããããšã§ãã ãã®å ŽåãLinuxã·ã¹ãã ã¯éåžžããããã¯ãŒã¯æ¥ç¶ãšæ å ±åŠç端æ«ã¹ããŒã·ã§ã³ã®ãšãã¥ã¬ãŒã¿ãŒãšããŠæ©èœããWindowsã¯æªæã®ããã³ãŒããå®è¡ããã調æ»å¯Ÿè±¡ã®ããŒã¹ãšããŠæ©èœããŸãã Trumanãªã©ã®æ¢è£œã®ãœãªã¥ãŒã·ã§ã³ãã REMnuxãSIFT Workstationãªã©ã®Linuxã·ã¹ãã ã®äŸã¯ããããã¯ãŒã¯äžã§èªç±ã«é åžãããŸãã
ãã¡ããããæ°ã«å ¥ãã®Linuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã«åºã¥ããŠãåæ§ã®ã·ã¹ãã ãèªåã§äœæã§ããŸãïŒUbuntuã匷ããå§ãããŸãããç§ã¯ãã®ãã¡ã³ã§ã¯ãããŸããããæ®å¿µãªããšã«ãDebianã§éçºããããçŸåšã¯ã»ãŒåžžã«Ubuntuã§ããããïŒäžèšãŸãã¯å¿ èŠã«å¿ããŠãç»åå ã®å¿ èŠãªãœãããŠã§ã¢ãšã¹ã¯ãªããããŸãã¯èªèº«ã®ç解ã«åŸã£ãŠãã ããã ãã ãããã®ãããªã·ã¹ãã ã®äœæã®èª¬æã¯éåžžã«é£ãããæéããããããããã®ãããªäœæ¥ã§èå³æ·±ãæçšãªãããžã§ã¯ããžã®ãªã³ã¯ãããã€ãæäŸããŸãã
-CïŒCãšã®éä¿¡ããã³ã¢ãžã¥ãŒã«ã®ããŠã³ããŒãã«äœ¿çšãããhttp / httpsãã©ãã£ãã¯ãååããã³åæããããã®é衚瀺ã®ãããã·ãµãŒããŒã äŸã¯Burp Suiteã§ãã
-ã€ã³ã¿ãŒãããã·ãã¥ã¬ãŒã¿ãããšãã°INetSim
-FOGãªã©ã®éäžã€ã¡ãŒãžãªã«ããªã·ã¹ãã ã
-ã¡ã¢ãªãã³ããåæããããã®ã·ã¹ãã ãããã§æãè¯ãIMHOã¯Volatality Frameworkã§ãã
-æ€åºããããã«ãŠã§ã¢ã®åé¡ãèªååããClamAVã¢ã³ããŠã€ã«ã¹ã·ã¹ãã ã ç§ã¯æ æã«åçšã¢ã³ããŠã€ã«ã¹ãäœæããŠããŸãããClamAVã®æ¹ãã¯ãŒã«ã ãšããèãïŒééã£ãŠããïŒã§ã¯ãªããåçšããŒãžã§ã³ã§ã¯å©çšã§ããªãClamAVã«èªåã®çœ²åãè¿œå ããå¯èœæ§ãããããã§ãã 極端ãªå Žåãåãç®çã§YARAã䜿çšã§ããŸãã
-JSãPDFãFlashãjavaã¹ã¯ãªããã®åæãšé£èªå解é€ãWindowsãã¡ã€ã«ã·ã¹ãã ã®è§£æããã¡ã€ã«çœ²åã®æäœãšè§£åã®ããã®ãŠãŒãã£ãªãã£-ãããã¯ãã¹ãŠãããã¯ãŒã¯äžã§å€§éã«ããããã¹ãŠãèšè¿°ããããšã¯äžå¯èœã§ãããåžžã«å¥œã¿ã®åé¡ã§ãã ç¹ã«ããã®ãããªãŠãŒãã£ãªãã£ã®å€ãã¯REMnuxãããžã§ã¯ãã®Webãµã€ãã§èšåãããŠãããããã«å«ãŸããŠããŸãã
ãã®æ¥œèŠ³çãªããŒãã§ãç§ã¯çµäºããŸããïŒïŒïŒãŸã 質åãããå Žåãç§ã®ã³ã¡ã³ãããã£ã³ã»ã«ããŸãã æåŸãŸã§ææ ¢ããŠèªãã§ããã人ã ã«æè¬ããŸã:)