JPCERT/CCã§ã¯ãã«ã¦ã¨ã¢ã«ææãã端æ«ãèµ·ç¹ã¨ãã¦ãä»ã®ç«¯æ«ã¸ã®æææ¡å¤§ããµã¼ãã¼ã¸ã®ä¾µå ¥ãªã©å é¨ã®ãããã¯ã¼ã¯å ã«ä¾µå®³ãæ¡å¤§ããäºä¾ãå¤ã確èªãã¦ãã¾ãã侵害ãåãã端æ«ã®èª¿æ»ã«ã¯ãåä½ããã¢ããªã±ã¼ã·ã§ã³ãéä¿¡ãªã©ã®è©³ç´°ãªãã°ãæ¥é ããåå¾ãã¦ãããã¨ãæã¾ãã¾ãããã®ãããªç¨éã«ä½¿ç¨ã§ãããã¼ã«ã¨ãã¦ãã¤ã¯ãã½ãã社ãæä¾ãã¦ããSysmon[1]ã¨ãããã¼ã«ãããã¾ããSysmonã¯ã端æ«ä¸ã§åä½ããã¢ããªã±ã¼ã·ã§ã³ã®æ å ±ãã¬ã¸ã¹ããªã¨ã³ããªã®ä½æãéä¿¡ãªã©Windows OSã®æ§ã ãªåä½ãã¤ãã³ããã°ã«è¨é²ãããã¼ã«ã§ãããã®Sysmonã®ãã°ã調æ»ããæãä¸è¬çãªæ¹æ³ã¯ãã¤ãã³ããã°ãããã¹ããªã©ã®å½¢å¼ã«å¤æãæ¤ç´¢ããæ¹æ³ã§ããããã®æ¹æ³ã§ã¯å¤æ°ã®ç«¯æ«ãåæã«èª¿æ»ãããã¨ã¯å°é£ã§ãã ããã§JPCERT/CCã§ã¯Sysmonã®ãã°ãä¸å 管çãããã°åæãè¿ éãã¤ããæ£ç¢º


{{#tags}}- {{label}}
{{/tags}}