重要提示: 本站仅作 Skill 资源导航与收录,正文以 GitHub 原仓库为准,版权归原项目所有。
以下为摘要预览,完整内容请查看 GitHub 原文。
Hunting For Webshell Activity
When to Use
When proactively hunting for indicators of hunting for webshell activity in the environment
After threat intelligence indicates active campaigns using these techniques
During incident response to scope compromise related to these techniques
When EDR or SIEM alerts trigger on related indicators
During periodic security assessments and purple team exercises
Prerequisites
EDR platform with process and network telemetry (CrowdStrike, MDE, SentinelOne)
SIEM with relevant log data ingested (Splunk, Elastic, Sentinel)
Sysmon deployed with comprehensive configuration
Windows Security Event Log forwarding enabled
Threat intelligence feeds for IOC correlation
Workflow
Formulate Hypothesis : Define a testable hypothesis based on threat intelligence or ATT&CK gap analysis.
Identify Data Sources : Determine which logs and telemetry are needed to validate or refute the hypothesis.
Execute Queries : Run detection queries against SIEM and EDR platforms to collect relevant events.
Analyze Results : Examine query results for anomalies, correlating across multiple data sources.
**Validate Finding…
以下为摘要预览,完整内容请查看 GitHub 原文。
Web Shell 活动狩猎
使用时机
在环境中主动狩猎 hunting for webshell activity 指标时
在威胁情报表明存在使用此类技术的活跃攻击活动之后
在事件响应期间,对与此类技术相关的入侵进行范围界定
当 EDR 或 SIEM 针对相关指标触发告警时
在定期的安全评估和紫队演练期间
先决条件
具备进程和网络遥测的 EDR 平台(CrowdStrike、MDE、SentinelOne)
已接入相关日志数据的 SIEM(Splunk、Elastic、Sentinel)
已部署全面配置的 Sysmon
已启用 Windows 安全事件日志转发
用于 IOC 关联的威胁情报源
工作流程
提出假设 :根据威胁情报或 ATT&CK 差距分析,定义一个可验证的假设。
识别数据源 :确定验证或反驳该假设所需的日志和遥测数据。
执行查询 :针对 SIEM 和 EDR 平台运行检测查询,以收集相关事件。
分析结果 :检查查询结果中的异常,并在多个数据源之间进行关联。
验证发现 :通过上下文分析将真正的阳性结果与误报区分开来。
关联活动 :将发现链接到更广泛的攻击链和威胁行为者 TTP。
记录与报告 :记录发现、更新检测规则并建议响应措施。
关键概念
概念 描述 T1505.003 Web Shell T1190 利用面向公众的应用 T1059.001 PowerShell
工具与系统
工具 用途 CrowdStrike Falcon EDR 遥测和威胁检测 Microsoft Defender for Endpoint 使用 KQL 进行高级狩猎 Splunk Enterprise 使用 SPL 查询进行 SIEM 日志分析 Elastic Security 检测规则与调查时间线 Sysmon 详细的 Windows 事件监控 Velociraptor 端点证据收集与狩猎 Sigma Rules 跨平台检测规则格式
常见场景
场景 1 :通过 IIS 漏洞部署 China Chopper Web Shell
场景 2 :通过易受攻击的上传点部署 ASPXSpy
场景 3 :隐藏在图像文件中的 PHP Shell
场景 4 :通过 Tomcat 管理控制台部署 JSP Shell
输出格式
…