ç§ãã¡ã®ISãµãŒãã¹ããã®å éšç®çã®ããã«äœ¿çšãããããžã§ã¯ãããã¬ãã¥ãŒãéå§ããããšæããŸãããããã¯å¹ åºãå°é家ã®ããã«å ±æãããŠããŸãïŒ
- OpenSOC ãµã€ããŒã»ãã¥ãªãã£ã®èŠ³ç¹ããããã°ããŒã¿ãåæããããã®ãã©ãããã©ãŒã ãããã«ã€ããŠã¯ãã§ã«Habréã§æžããŠããŸãã
- GOSINT ã ããã¯ãé«å質ã®äŸµå®³ã®ææšãåéãåŠçããœãŒããããã³ãšã¯ã¹ããŒãããããã«èšèšããããã¬ãŒã ã¯ãŒã¯ã§ãã GOSINTã®ãœãŒã¹ãšããŠãTwitterãã£ã³ãã«ãšããŸããŸãªãã£ãŒãã®äž¡æ¹ã䜿çšã§ããŸãã ã€ã³ãžã±ãŒã¿ãã«ãŠã§ã¢ã¯ãCisco UmbrellaãThreatCrowdãVirusTotalãªã©ã®å€éšãœãªã¥ãŒã·ã§ã³ã䜿çšããŠãã¹ãã§ããŸãã ã€ã³ãžã±ãŒã¿ãŒã¯CSVãŸãã¯CRITã«ãšã¯ã¹ããŒããããŸãã ãã®ãœãªã¥ãŒã·ã§ã³ã®è©³çŽ°ã«ã€ããŠã¯ã ããã°ãã芧ãã ããã
- netsarlacc ã ããã¯ãäŒæ¥ã®ã»ãã¥ãªãã£ç£èŠã»ã³ã¿ãŒãŸãã¯ã€ã³ã·ãã³ã察å¿ãµãŒãã¹ã§äœ¿çšã§ãããHTTPããã³SMTPçšã®é«æ§èœäŒæ¥ã·ã³ã¯ããŒã«ã§ãã ãã®ããŒã«ã¯ãæ¢åã®ããããã³ã°ãæ€ç«ããã£ããã£ãããŒã¿ã«ãDNS RPZãªã©ã®ãã©ãã£ãã¯ãªãã€ã¬ã¯ããœãªã¥ãŒã·ã§ã³ãšé£æºããŠæ©èœããŸãã å
žåçãªã·ããªãªã§ã¯ãnetsarlaccã¯ãŠãŒã¶ãŒã®ãªãã€ã¬ã¯ãå
ã®IP / CNAMEãšããŠæ©èœããééã£ãå Žæã«ç§»åããããšããããäœãééã£ãããšãããããšãããããŸãã
- ãã«ã¹ãã€ã㌠ããã¯ãäŒæ¥ã®Webãµã€ããšããŒã¿ã«ãæ€æ»ããŠã䟵害ãããŠãããã©ãããå€æãããã¹ãã€ããŒãã§ãã Malspiderã¯ãçµã¿èŸŒã¿ã®ã¢ã«ãŽãªãºã ãšãã³ãã¬ãŒãã䜿çšããŠãé衚瀺ã®iframeãã¹ã¯ãªããã®æ¿å ¥ïŒæ¿å ¥ïŒãé»åã¡ãŒã«ã®å±éãªã©ãæ€åºããŸãã 䟵害ããããµã€ããèŠã€ããããšã«å ããŠãMalspiderã¯äŸµå®³ã®ææšãçæããããã«ã䜿çšããããã®åŸãä»ã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã§äœ¿çšã§ããŸãã
ããå€ãã®ãªãŒãã³ãœãŒã¹ãããžã§ã¯ãã¯ãCisco IBãµãŒãã¹ã§ã¯ãªããããŸããŸãªè åšã調æ»ãã蚌æ ã®åéã調æ»ã䟵害ã®å åã®æºåãªã©ã«é¢é£ããå€ãã®ã¿ã¹ã¯ãèªååãã調æ»ãŠãããCisco Talosã«ãã£ãŠéçºãããŸããã
- ãã³ã æ»æãæ€åºãããããã¯ãŒã¯ãã©ãã£ãã¯ãåæããããã®çµ¶ããé²åããã·ã¹ãã ãããã¯ããããã¯ãŒã¯ã»ãã¥ãªãã£æ¥çã§äºå®äžã®æšæºã«ãªã£ãŠããŸãã ããã«åºã¥ããŠãåœå ã®æ»ææ€åºã·ã¹ãã ã®å€§åãæ§ç¯ãããŸããã
- ããŒã¢ã³ãã¬ãŒ ã ãããã¯ãŒã¯ãã©ãã£ãã¯ã®ç£èŠã«äœ¿çšã§ãããœãããŠã§ã¢ã¹ããªãã¿ãŒïŒã¿ããïŒãšåæ§ã«ãç°¡åã§é«éãªã¹ããã¡ãŒã
- åã³ ã ããŒã¢ã³ãã¬ãŒãšã¯ç°ãªããåã ã®ãã±ãããã»ãã·ã§ã³ã§ã¯ãªããNetflowãŸãã¯IPFIXãããã¯ãŒã¯ã¹ããªãŒã ããã£ããã£ããããŒã«ã§ãæ å ±ã»ãã¥ãªãã£ã®ç£èŠããããã¯ãŒã¯ã€ã³ã·ãã³ãã®èª¿æ»ã«äœ¿çšã§ããŸãã ãã®ããŒã«ãç©æ¥µçã«äœ¿çšããŠãæå·åããããã©ãã£ãã¯ãåæããæå·åãããŠããªãæªæã®ããã³ãŒãã®çè·¡ãæ€çŽ¢ããŸããã
- TRex ã ç¡æã®ã¹ããŒããã«ããã³ã¹ããŒãã¬ã¹ã®ã¯ã©ã€ã¢ã³ãããã³ãµãŒããŒãã©ãã£ãã¯ãžã§ãã¬ãŒã¿ãŒL4-L7ãåäžãµãŒããŒã§400ã®ã¬ããã/ç§ã«æ¡åŒµå¯èœã ãã®ããŒã«ã䜿çšããŠããµã€ããŒã»ãã¥ãªãã£ã®åéïŒDPIãITUãIPSãNATãããŒããã©ã³ãµãŒããã£ãã·ã¥ãµãŒããŒãªã©ïŒãå«ãããŸããŸãªãããã¯ãŒã¯ãœãªã¥ãŒã·ã§ã³ããã¹ãããã³æ¯èŒã§ããŸãã åã³ãšTRexãããžã§ã¯ãã¯Talosã«ãã£ãŠéçºããããã®ã§ã¯ãããŸããããå šäœåã«ããŸãé©åãããããç§ã¯ãããããã®ãªã¹ãã«å«ããŸããã
- TAXIIãã°ã¢ããã¿ ã TAXIIãµãŒãã¹ã䜿çšããŠSIEMïŒçŸåšã®SplunkãšArcsightïŒã®äœæ¥ãæ¹åãããããžã§ã¯ãã ã¢ããã¿ã¯ãè åšã䟵害ã®å åãªã©ã«é¢ããããŒã¿ãåä¿¡ããããããJSONãCEFãªã©ã®ããããããSIEM圢åŒã«å€æããŸãã
- ClamAV ããã€ã®æšéŠ¬ããŠã€ã«ã¹ãããã³ãã®ä»ã®çš®é¡ã®æªæã®ããã³ãŒããæ€åºããããã®ãŠã€ã«ã¹å¯Ÿçãšã³ãžã³ã å ã ã¯é»åã¡ãŒã«ã¹ãã£ã³çšã«èšèšãããŠããŸãããããšã³ãžã³ãšããŠä»ã®ç®çã«äœ¿çšã§ããŸãã
- ã¢ãã㌠ããŸããŸãªãã¹ããçæããæ å ±ã»ãã¥ãªãã£ã®ã³ã³ããã¹ãã§ãããã®çããåæããããšã«ããããœãããŠã§ã¢ã®è匱æ§ãæ€çŽ¢ããã³åªå é äœä»ãããããã«èšèšãããããã€ãã®ããŒã«ïŒFuzzFlowãSliceFlowãExploitFlowïŒãå«ããã¬ãŒã ã¯ãŒã¯ã
- ã¬ã€ã¶ãŒãã㯠ãã1ã€ã®Talosãã¬ãŒã ã¯ãŒã¯ã¯ãã¯ã©ã€ã¢ã³ãããŒããžã®æ»æãæ€åºããããã®åæ£ãšã³ãžã³ã§ãã
- PE-Sig ã å®è¡å¯èœãã¡ã€ã«ã®PEã»ã¯ã·ã§ã³ãåæããå®è¡å¯èœã³ãŒãã®æåãªããã«ãŒã®çœ²åãçæããããã»ã¹ãèªååããããŒã«ãClamAVãªã©ã®ããŸããŸãªãã«ãŠã§ã¢åæããŒã«ã«ããŒãã§ããŸãã
- TeslaCrypt埩å·åããŒã« ã TeslaCryptã©ã³ãµã ãŠã§ã¢ã§æå·åããããã¡ã€ã«ã埩å·åã§ããã³ãã³ãã©ã€ã³ãŠãŒãã£ãªãã£ã ãã®ãœãªã¥ãŒã·ã§ã³ã®è©³çŽ°ã«ã€ããŠã¯ã ããã°ãã芧ãã ããã
- Synful Knock Scanner ã SYNFul Knockãã«ãŠã§ã¢ã«ææããã«ãŒã¿ãŒãèå¥ãããããã¯ãŒã¯ã¹ãã£ããŒã
- LockyDump ã Lockyæªæã®ããã³ãŒãã®ãã¹ãŠã®æ¢ç¥ã®å€æŽããæ§æãã©ã¡ãŒã¿ãŒãååŸã§ãããŠãŒãã£ãªãã£ã ãã®ãœãªã¥ãŒã·ã§ã³ã®è©³çŽ°ã«ã€ããŠã¯ã ããã°ãã芧ãã ããã
- MBRãã£ã«ã¿ãŒ ã MBRïŒãã¹ã¿ãŒããŒãã¬ã³ãŒãïŒãžã®æžã蟌ã¿ãé²ãæãåçŽãªãŠãŒãã£ãªãã£ã ãã®ãœãªã¥ãŒã·ã§ã³ã®è©³çŽ°ã«ã€ããŠã¯ã ããã°ãã芧ãã ããã
- FreeSentry ç¹å®ã®ã¿ã€ãã®è匱æ§ïŒäžéšã®RCEã¯ã©ã¹ãªã©ïŒã®æªçšãè€éã«ããLLVMã³ã³ãã€ã©ãŒã®ãã©ã°ã€ã³ã ãã®ãœãªã¥ãŒã·ã§ã³ã®è©³çŽ°ã«ã€ããŠã¯ã ããã°ãã芧ãã ããã
- æåã« ã Function Identification and Recover Signature Toolã¯IDA Proã®ãã©ã°ã€ã³ã§ããããªããŒã¹ãšã³ãžãã¢ãããéãç°¡åãªéç解æãå®è¡ã§ããããã«ããŸãã ãã®ãœãªã¥ãŒã·ã§ã³ã®è©³çŽ°ã«ã€ããŠã¯ã ããã°ãã芧ãã ããã
- Flokibot æåãªZeusãã«ãŠã§ã¢ãšåãã³ãŒãã«åºã¥ããŠãFlokibotã®æªæã®ããã³ãŒãã®åæãèªååããã¹ã¯ãªããã®ã»ããã ãã®ãœãªã¥ãŒã·ã§ã³ã®è©³çŽ°ã«ã€ããŠã¯ã ããã°ãã芧ãã ããã
- ROPMEMU Volatilityã®ãã©ã°ã€ã³ãå«ããã³ãŒãã®åå©çšã䜿çšããè€éãªæ»æãåæããããã®ããŒã«ã ãã®ãœãªã¥ãŒã·ã§ã³ã®è©³çŽ°ã«ã€ããŠã¯ã ããã°ãã芧ãã ããã
- ãã¹ èªå眲åã·ã³ã»ãµã€ã¶ãŒ-æ¢åã®ãµã³ãã«ã«åºã¥ããŠãŠã€ã«ã¹å¯Ÿç眲åãèªåçæããããã®ãã¬ãŒã ã¯ãŒã¯ã ããã·ã¥ããŒã¹ã®çœ²åãšã¯ç°ãªããBASSã¯ãã³ãã¬ãŒãããŒã¹ã®çœ²åãçæãããŠã€ã«ã¹ã¢ããªã¹ãããªããŒã¹ãšã³ãžãã¢ã®æéãšãªãœãŒã¹ã解æŸããŸãã ãã®ãœãªã¥ãŒã·ã§ã³ã®è©³çŽ°ã«ã€ããŠã¯ã ããã°ãã芧ãã ããã
- PyREBox ã ããã¯ããªããŒã¹ãšã³ãžãã¢ãªã³ã°çšã®QEMUããŒã¹ã®Pythonãµã³ãããã¯ã¹ã§ãã ãã®ãœãªã¥ãŒã·ã§ã³ã®è©³çŽ°ã«ã€ããŠã¯ã ããã°ãã芧ãã ããã
- File2pcap ãã®ãŠãŒãã£ãªãã£ã䜿çšãããšãå ¥åãã¡ã€ã«ãpcapã«å€æã§ããŸãããã®ãã¡ã€ã«ã§ã¯ãæ·»ä»ãã¡ã€ã«ãšããŠã®ãœãŒã¹ãã¡ã€ã«ãHTTP / HTTP2 / FTP / SMTP / IMAP / POP3ãä»ããŠéä¿¡ãããŸãã ãã®ãœãªã¥ãŒã·ã§ã³ã®è©³çŽ°ã«ã€ããŠã¯ã ããã°ãã芧ãã ããã
- åä¹±ãã¡ã¶ãŒ ããã¯ãæ£åœãªãã©ãã£ãã¯ïŒããšãã°ããã©ãŠã¶ãŒãªã¯ãšã¹ãïŒãpcapã®åœ¢åŒã§èšé²ããã¿ãŒã²ãããã¹ãã«ç¹°ãè¿ãéä¿¡ããå¿ èŠã«å¿ããŠãã©ãã£ãã¯ãã©ã¡ãŒã¿ãŒãå€æŽããããŒãã®å¿çåäœã調ã¹ãããšãã§ãããããã¯ãŒã¯ãã¡ã¶ãŒã§ãã ãã®ãœãªã¥ãŒã·ã§ã³ã®è©³çŽ°ã«ã€ããŠã¯ã ããã°ãã芧ãã ããã
- è©æ¬º ã Pythonã§èšè¿°ãããTCPãSSLãUDPãUnixãœã±ãããRawãœã±ãããIPv6ïŒããã³ãããã®ä»»æã®çµã¿åããïŒããµããŒããããããã¯ãŒã¯ãããã·ã åæããªã³ã¶ãã©ã€ã§ã®æžãæããªã©ã®ããã«ããã©ãã£ãã¯ã.pcapãŸãã¯.fuzzer圢åŒïŒMutiny Fuzzerãšã®çµ±åçšïŒã§èšé²ã§ããŸãã ãã®ãœãªã¥ãŒã·ã§ã³ã®è©³çŽ°ã«ã€ããŠã¯ã ããã°ãã芧ãã ããã
ãã®ãµã€ããŒã»ãã¥ãªãã£åéã®ãªãŒãã³ãœãŒã¹ãããžã§ã¯ãã®ãªã¹ãã§ã¯ãå®äºã§ããŸãããã§ããŸããã æ å ±ã»ãã¥ãªãã£ãµãŒãã¹ã®å éšæŽ»åãCisco Talosã®ãã¬ãŒã ã¯ãŒã¯å ã§ã®æªæã®ããã³ãŒãã®èª¿æ»ããŸãã¯ã·ã¹ã³ãå®æœããä»ã®ãããžã§ã¯ãïŒäŸïŒåã³ãTRexïŒã®ããã«ãåžžã«æ°ãããã®ããããŸãã ãããã¯ãã¹ãŠãåœç€Ÿã®ã€ã³ã¿ãŒãããããŒãžã§è¿œè·¡ã§ããŸãã