Attack_range: ๊ธฐ๋Šฅ ์š”์ฒญ : ์‹คํŒจํ•œ Atomic Red Team ํ…Œ์ŠคํŠธ๋ฅผ ์ข…๋ฃŒํ•˜๋Š” ๊ตฌ์„ฑ ๊ฐ€๋Šฅํ•œ ์ œํ•œ ์‹œ๊ฐ„ ์ง€์—ฐ ์ถ”๊ฐ€

์— ๋งŒ๋“  2020๋…„ 02์›” 05์ผ  ยท  5์ฝ”๋ฉ˜ํŠธ  ยท  ์ถœ์ฒ˜: splunk/attack_range

์•„ํ† ๋ฏน ๋ ˆ๋“œ ํŒ€ ํ…Œ์ŠคํŠธ ์ค‘ ํ•˜๋‚˜๊ฐ€ ๋‚ด ํ…Œ์ŠคํŠธ์—์„œ ์ข…๋ฃŒ๋˜๋Š” ๋ฐ 30 ๋ถ„ ์ด์ƒ ๊ฑธ๋ฆฌ๋Š” ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. ๋ฐ˜๋“œ์‹œ ๋ฌธ์ œ๊ฐ€ ๋  ํ•„์š”๋Š” ์—†์ง€๋งŒ ํ…Œ์ŠคํŠธ ์ƒํƒœ๊ฐ€ ์‹œ๊ฐ„ ์ดˆ๊ณผ ๋  ๋•Œ๊นŒ์ง€ ๊ธฐ๋‹ค๋ฆฌ๋Š” ์‹œ๊ฐ„์„ attack.conf์—์„œ ๊ตฌ์„ฑ ํ•  ์ˆ˜์žˆ๋Š” ๊ธฐ๋Šฅ ์š”์ฒญ์„ ๋งŒ๋“ค๊ณ  ์‹ถ์Šต๋‹ˆ๋‹ค (๊ฐ€๋Šฅํ•˜๋‹ค๋ฉด). ํƒ€์ž„ ์Šคํƒฌํ”„๋Š” ๋กœ์ปฌ ํ…Œ์ŠคํŠธ์—์„œ T1071์˜ ์‹คํ–‰ ์‹œ์ž‘๊ณผ ๋์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค.

์‹œ์ž‘ : 2020-02-04 14:49:35
์ข…๋ฃŒ : 2020-02-04 15:21:35

python attack_range.py -m terraform -a simulate -st T1071 -t attack-range-windows-domain-controller

`2020-02-04 14 : 49 : 35,618-์ •๋ณด-๊ณต๊ฒฉ _ ๋ฒ”์œ„-INIT-๊ณต๊ฒฉ _ ๋ฒ”์œ„ v1

PLAY [all] * * * * * * * * * * * * * * * * * * * * * **

TASK [atomic_red_team : Atomic Red Team์„ ์„ค์น˜ํ–ˆ๋Š”์ง€ ํ™•์ธ] * * * **
ํ™•์ธ : [44.228.118.166]

์ž‘์—… [atomic_red_team : Atomic Red Team PS ๋ชจ๋“ˆ ๋ณต์‚ฌ] * * * * * * **
๋ณ€๊ฒฝ๋จ : [44.228.118.166]

์ž‘์—… [atomic_red_team : Atomic Red Team PS ๋ชจ๋“ˆ ์„ค์น˜] * * * * * **
๋ณ€๊ฒฝ๋จ : [44.228.118.166]

์ž‘์—… [atomic_red_team : ์‹คํ–‰ ์ „ ์ •๋ฆฌ C : \ Windows \ Temp] * * *
๋ณ€๊ฒฝ๋จ : [44.228.118.166]

TASK [atomic_red_team : ์‹คํ–‰ ์ „ C : \ Windows \ Temp ์žฌ์ƒ์„ฑ] * * *
๋ณ€๊ฒฝ๋จ : [44.228.118.166]

TASK [atomic_red_team : set_fact * * * * * * * * * * * * * *
ํ™•์ธ : [44.228.118.166]

์ž‘์—… [atomic_red_team : ์‹คํ–‰ ๊ธฐ๋ฒ•] * * * * * * * * * * * *
ํ™•์ธ : [44.228.118.166] => {
"๊ธฐ์ˆ ": [
"T1071"
]
}

์ž‘์—… [atomic_red_team : Atomic Red Team ์‹คํ–‰ ๋””๋ ‰ํ† ๋ฆฌ ๋งŒ๋“ค๊ธฐ] * * * *
๋ณ€๊ฒฝ๋จ : [44.228.118.166]

์ž‘์—… [atomic_red_team : ๋ชจ๋“  Atomic Red Team ํ…Œ์ŠคํŠธ ์‹คํ–‰] * * * * * * *
๊ฑด๋„ˆ ๋›ฐ๊ธฐ : [44.228.118.166]

TASK [atomic_red_team : ์ง€์ •๋œ Atomic Red Team ๊ธฐ์ˆ  ์‹คํ–‰] * * * **
๋ณ€๊ฒฝ๋จ : [44.228.118.166] => (ํ•ญ๋ชฉ = T1071)

TASK [atomic_red_team : ์‹คํ–‰ ๋กœ๊ทธ ํŒŒ์ผ ํ™•์ธ] * * * * * * * * **
ํ™•์ธ : [44.228.118.166]

TASK [atomic_red_team : ์ €์žฅ ๋กœ๊ทธ ํŒŒ์ผ] * * * * * * * * * * * * *
๋ณ€๊ฒฝ๋จ : [44.228.118.166]

TASK [atomic_red_team : ํ”„๋กœ์„ธ์Šค ์ •๋ฆฌ] * * * * * * * * * * **
๋ณ€๊ฒฝ๋จ : [44.228.118.166]

TASK [atomic_red_team : ์‹คํ–‰ ํ›„ ์ •๋ฆฌ] * * * * * * * * **
๋ณ€๊ฒฝ๋จ : [44.228.118.166]

์žฌ์ƒ ์š”์•ฝ * * * * * * * * * * * * * * * * * * * * * **
44.228.118.166 : ok = 13 changed = 9 unreachable = 0 failed = 0 skipped = 1 ๊ตฌ์กฐ ๋จ = 0 ๋ฌด์‹œ = 0

2020-02-04 15 : 21 : 35,465-INFO-attack_range-target : attack-range-windows-domain-controller์— ๋Œ€ํ•ด ์„ฑ๊ณต์ ์œผ๋กœ ์‹คํ–‰ ๋œ ๊ธฐ์ˆ  ID T1071

bug enhancement

๊ฐ€์žฅ ์œ ์šฉํ•œ ๋Œ“๊ธ€

์ƒˆ ๋ฒ„์ „์—๋Š” ์‹œ๊ฐ„ ์ œํ•œ ๋ฐ ๊ธฐํƒ€ ๋ฉ‹์ง„ ๊ธฐ๋Šฅ์ด ๋‚ด์žฅ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.
https://redcanary.com/blog/invoke-atomicredteam-leaves-the-nest/

๋ชจ๋“  5 ๋Œ“๊ธ€

@jzsplunk ๋Š” atomic red ํŒ€ ๊ทธ๋ฃน๊ณผ ์•ฝ๊ฐ„์˜ ๋Œ€ํ™”๋ฅผ ๋‚˜๋ˆด๋Š”๋ฐ, ์ด๋Š” ์šฐ๋ฆฌ๊ฐ€ ๊ธฐ์ˆ ์„ example.com ๋Œ€์‹  ์œ ํšจํ•œ ๋„๋ฉ”์ธ ์ด๋ฆ„์„ ์„ค์ •ํ•˜์ง€ ์•Š์•˜๊ธฐ ๋•Œ๋ฌธ์ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. : https : / /github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1071/T1071.yaml#L79 ๋”ฐ๋ผ์„œ 1000 ๊ฐœ์˜ ์š”์ฒญ ์‹œ๊ฐ„ ์ดˆ๊ณผ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๊ฒƒ์ด ๊ทธ ํ…Œ์ŠคํŠธ๋ฅผ ์ง€์—ฐ์‹œํ‚ค๋Š” ์›์ธ ์ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ง€๊ธˆ์€ ์šฐ๋ฆฌ๊ฐ€ํ•˜๋Š” ์ผ์ด ์•„๋‹ˆ๊ธฐ ๋•Œ๋ฌธ์— ์ด๋Ÿฌํ•œ ํ…Œ์ŠคํŠธ๋ฅผ ์‚ฌ์šฉ์ž ์ •์˜ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์ฐพ์•„์•ผํ•ฉ๋‹ˆ๋‹ค.

์ด ๋ฌธ์ œ๋Š” ์ตœ๊ทผ ํ™œ๋™์ด ์—†์—ˆ๊ธฐ ๋•Œ๋ฌธ์— ์ž๋™์œผ๋กœ ์˜ค๋ž˜๋œ ๊ฒƒ์œผ๋กœ ํ‘œ์‹œ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋” ์ด์ƒ ํ™œ๋™์ด ๋ฐœ์ƒํ•˜์ง€ ์•Š์œผ๋ฉด ํ์‡„๋ฉ๋‹ˆ๋‹ค. ๊ท€ํ•˜์˜ ๊ธฐ์—ฌ์— ๊ฐ์‚ฌ๋“œ๋ฆฝ๋‹ˆ๋‹ค.

์ƒˆ ๋ฒ„์ „์—๋Š” ์‹œ๊ฐ„ ์ œํ•œ ๋ฐ ๊ธฐํƒ€ ๋ฉ‹์ง„ ๊ธฐ๋Šฅ์ด ๋‚ด์žฅ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.
https://redcanary.com/blog/invoke-atomicredteam-leaves-the-nest/

๋‹ค์Œ ๊ธฐ์ˆ ์€ ํ˜„์žฌ ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. python attack_range.py -m terraform -a simulate -st T1086 -t attack-range-windows-domain-controller ๊ทธ๋ƒฅ ์‹คํ–‰ ์ค‘์— ์ค‘๋‹จ๋ฉ๋‹ˆ๋‹ค.

์ด ๋ฌธ์ œ๋Š” @ P4T12ICK๊ฐ€ ์ž‘์—… ํ•œ ๋ณ€๊ฒฝ ์‚ฌํ•ญ์„ ๋ณ‘ํ•ฉ ํ•œ ํ›„ ์ตœ์‹  ๊ฐœ๋ฐœ ๋ธŒ๋žœ์น˜์— ๋‚˜ํƒ€๋‚˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

์ด ํŽ˜์ด์ง€๊ฐ€ ๋„์›€์ด ๋˜์—ˆ๋‚˜์š”?
0 / 5 - 0 ๋“ฑ๊ธ‰