重要提示:本站仅作 Skill 资源导航与收录,正文以 GitHub 原仓库为准,版权归原项目所有。
以下为摘要预览,完整内容请查看 GitHub 原文。
Hunting For Spearphishing Indicators
When to Use
- When proactively hunting for indicators of hunting for spearphishing indicators in the environment
- After threat intelligence indicates active campaigns using these techniques
- During incident response to scope compromise related to these techniques
- When EDR or SIEM alerts trigger on related indicators
- During periodic security assessments and purple team exercises
Prerequisites
- EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
- SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
- Sysmon deployed with comprehensive configuration
- Windows Security Event Log forwarding enabled
- Threat intelligence feeds for IOC correlation
Workflow
- Formulate Hypothesis: Define a testable hypothesis based on threat intelligence or ATT&CK gap analysis.
- Identify Data Sources: Determine which logs and telemetry are needed to validate or refute the hypothesis.
- Execute Queries: Run detection queries against SIEM and EDR platforms to collect relevant events.
- Analyze Results: Examine query results for anomalies, correlating across multiple data sources.
- **Va…
以下为摘要预览,完整内容请查看 GitHub 原文。
搜索鱼叉式钓鱼指示特征
使用场景
- 在环境中主动搜索鱼叉式钓鱼指示特征时
- 在威胁情报显示存在使用这些技术的活跃攻击活动后
- 在事件响应过程中,对与这些技术相关的入侵范围进行评估时
- 当 EDR 或 SIEM 针对相关指示特征触发告警时
- 在定期安全评估和紫队演练期间
先决条件
- 具备进程和网络遥测能力的 EDR 平台(CrowdStrike、MDE、SentinelOne)
- 已接入相关日志数据的 SIEM(Splunk、Elastic、Sentinel)
- 已部署配置完善的 Sysmon
- 已启用 Windows 安全事件日志转发
- 用于 IOC 关联分析的威胁情报源
工作流程
- 形成假设:基于威胁情报或 ATT&CK 差距分析提出可验证的假设。
- 识别数据源:确定验证或反驳该假设所需的日志和遥测数据。
- 执行查询:在 SIEM 和 EDR 平台中运行检测查询以收集相关事件。
- 分析结果:检查查询结果中的异常,并在多个数据源之间进行关联。
- 验证发现:通过上下文分析区分真实阳性与误报。
- 关联活动:将发现结果与更广泛的攻击链和威胁行为者 TTP 相关联。
- 记录与报告:记录发现结果,更新检测规则,并建议响应措施。
关键概念
| 概念 | 描述 |
|---|
| T1566.001 | 鱼叉式钓鱼附件 |
| T1566.002 | 鱼叉式钓鱼链接 |
| T1566.003 | 通过服务的鱼叉式钓鱼 |
工具与系统
| 工具 | 用途 |
|---|
| CrowdStrike Falcon | EDR 遥测与威胁检测 |
| Microsoft Defender for Endpoint | 使用 KQL 的高级搜寻 |
| Splunk Enterprise | 使用 SPL 查询进行 SIEM 日志分析 |
| Elastic Security | 检测规则与调查时间线 |
| Sysmon | 详细的 Windows 事件监控 |
| Velociraptor | 端点证据收集与搜寻 |
| Sigma Rules | 跨平台检测规则格式 |
常见场景
- 场景 1:启用宏的 Excel 执行 PowerShell 下载器
- 场景 2:利用 HTML smuggling 投递包含 LNK 载荷的 ISO 文件
- 场景 3:伪装为 SharePoint 通知的凭据钓鱼链接
- 场景 4:PDF 附件中的二维码钓鱼
输出格式
Hunt ID: TH-HUNT…