2023-01-10 2019å¹´4æï½9æã®ãã¤ã¼ãããã¾ã¨ãã¦ãã¾ãã DFIRé¢é£ 侵害æç¡ãç°¡æã«èª¿æ»ãã Linux ã³ãã³ã15é¸ DNS éä¿¡ããæªæ§ãªéä¿¡ãè¦ã¤ãã調æ»è¦³ç¹ AmCache ã«é¢ãã ANSSI ã®å ±åæ¸ NTFS Journal Forensics ããã°ã©ã ãå®è¡ããããã¨ãã£ã¦ãããã"å©ç¨ãããã©ãã"ã¯å¥åé¡ Volatilityï¼Windows 10 ã®ã¡ã¢ãªå§ç¸®ã¸ã®å¯¾å¿ ã¡ã¼ã«ã«å«ã¾ããä¸è¦ããã¨æ°ã¥ããªãã¿ã¤ã ã¹ã¿ã³ãã®è¦ã¤ãæ¹ ã¤ãã³ããã°ã®ã¿ã¤ã ã¹ã¿ã³ãã«ã¤ã㦠KAPEã使ã£ã¦ã¿ã¤ã ã©ã¤ã³ãä½æãããã¥ã¼ããªã¢ã« ã¹ã¬ãããã³ãã£ã³ã°ã«æç¨ãªæ¤ç´¢ã¯ã¨ãªã®ä¸è¦§ Sysmon ã® DNS ã¯ã¨ãªå¨ãã®ãã°ã«ã¤ã㦠WMI é¢é£ã®æ°¸ç¶åæ å ± WMI Event Subscription ã®è§£æ Windows10 ã®ã¨ã©ã¼å ±åãã¡ã¤ã«ï¼*.WE
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}