我现在就在你的日志里欺骗你的分析师蒙蔽你的EDR系统.pdf

编号:981870 PDF 99页 29.13MB 下载积分:VIP专享
下载报告请您先登录!

我现在就在你的日志里欺骗你的分析师蒙蔽你的EDR系统.pdf

1、#BHUSA BlackHatEventsIm in your logs now,deceiving your analysts and blinding your EDROlaf HartongDetection Engineer and Security Researcher Purple teaming,Threat hunting Security MVPFormer documentary photographerFather of 2 boys“I like warm hugs” is Event Tracing for WindowsTodays topicscan I spoo

2、f events?can I further(ab)use this?What Can you do with/about thisWhy security products use ETWWHAT is event tracing for windows(ETW)What is Event Tracing for Windows (ETW)Event Tracing for Windows(ETW)provides a mechanism to trace and log events that are raised by user-mode applications and kernel-

3、mode drivers.It has been designed for performance monitoring and debugging.ETW is implemented in the Windows operating system and provides a fast,reliable,and versatile set of event tracing features.Its architecture consists of three primary components:The next slides provide a simplified overview o

4、f ETW,only focused on the components Ive abused.*Requires admin privileges,unless explicitly permitted*logical flowCommon ETW attackshttps:/attack.mitre.org/techniques/T1562/006/Patching the ntdll.dll EtwEventWrite function(often AMSI)Tamper with ETL files on disk or disable sessions in the registry

5、Block specific events in one process by function hookingDisable tracing sessions(requires kernel level access)Use ETWWHYsecurity products Providers can be enabled/disabled in a trace session at runtimeDynamic ControlWay more event types can be collected Coverage breathNo hooking or injection require

6、d to all processesLess intrusiveLess code in the kernel is less likely to crashStabilityETW sessions can be consumed filtered by level,keywords,etcFilteringKernel events need to be filtered after collection.ETW Sessions are buffered,callbacks are not.Process PerformanceWHY do security products use E

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(我现在就在你的日志里欺骗你的分析师蒙蔽你的EDR系统.pdf)为本站 (竿头日上) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠