Cylance PROTECT ๋กœ๊ทธ ์ˆ˜์ง‘

๋‹ค์Œ์—์„œ ์ง€์›:

์ด ๋ฌธ์„œ์—์„œ๋Š” Bindplane์„ ์‚ฌ์šฉํ•˜์—ฌ Cylance PROTECT ๋กœ๊ทธ๋ฅผ Google Security Operations์— ์ˆ˜์ง‘ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค. Logstash ํŒŒ์„œ ์ฝ”๋“œ๋Š” Cylance PROTECT syslog ๋ฉ”์‹œ์ง€๋ฅผ ํ†ตํ•ฉ ๋ฐ์ดํ„ฐ ๋ชจ๋ธ (UDM)๋กœ ๋ณ€ํ™˜ํ•ฉ๋‹ˆ๋‹ค. syslog ๋ฉ”์‹œ์ง€์—์„œ ํ•„๋“œ๋ฅผ ์ถ”์ถœํ•˜๊ณ , ์ •๊ทœํ™”ํ•˜๊ณ , UDM ํ•„๋“œ์— ๋งคํ•‘ํ•˜๊ณ , ์œ„ํ˜‘ ์‹ฌ๊ฐ๋„ ๋ฐ ์นดํ…Œ๊ณ ๋ฆฌ ์ •๋ณด๋กœ ๋ฐ์ดํ„ฐ๋ฅผ ๋ณด๊ฐ•ํ•ฉ๋‹ˆ๋‹ค.

์‹œ์ž‘ํ•˜๊ธฐ ์ „์—

๋‹ค์Œ ๊ธฐ๋ณธ ์š”๊ฑด์ด ์ถฉ์กฑ๋˜์—ˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

  • Google SecOps ์ธ์Šคํ„ด์Šค
  • Windows 2016 ์ด์ƒ ๋˜๋Š” systemd๊ฐ€ ์„ค์น˜๋œ Linux ํ˜ธ์ŠคํŠธ
  • ํ”„๋ก์‹œ ๋’ค์—์„œ ์‹คํ–‰ํ•˜๋Š” ๊ฒฝ์šฐ ๋ฐฉํ™”๋ฒฝ ํฌํŠธ๊ฐ€ ์—ด๋ ค ์žˆ์Œ
  • Cylance PROTECT์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ๊ถŒํ•œ

Google SecOps ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ ๊ฐ€์ ธ์˜ค๊ธฐ

  1. Google SecOps ์ฝ˜์†”์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. SIEM ์„ค์ • > ์ˆ˜์ง‘ ์—์ด์ „ํŠธ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•ฉ๋‹ˆ๋‹ค. Bindplane์ด ์„ค์น˜๋  ์‹œ์Šคํ…œ์— ํŒŒ์ผ์„ ์•ˆ์ „ํ•˜๊ฒŒ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

Google SecOps ๊ณ ๊ฐ ID ๊ฐ€์ ธ์˜ค๊ธฐ

  1. Google SecOps ์ฝ˜์†”์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. SIEM ์„ค์ • > ํ”„๋กœํ•„๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. ์กฐ์ง ์„ธ๋ถ€์ •๋ณด ์„น์…˜์—์„œ ๊ณ ๊ฐ ID๋ฅผ ๋ณต์‚ฌํ•˜์—ฌ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

Bindplane ์—์ด์ „ํŠธ ์„ค์น˜

Windows ์„ค์น˜

  1. ๋ช…๋ น ํ”„๋กฌํ”„ํŠธ ๋˜๋Š” PowerShell์„ ๊ด€๋ฆฌ์ž๋กœ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    msiexec /i "https://github.com/observIQ/bindplane-agent/releases/latest/download/observiq-otel-collector.msi" /quiet
    

Linux ์„ค์น˜

  1. ๋ฃจํŠธ ๋˜๋Š” sudo ๊ถŒํ•œ์œผ๋กœ ํ„ฐ๋ฏธ๋„์„ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    sudo sh -c "$(curl -fsSlL https://github.com/observiq/bindplane-agent/releases/latest/download/install_unix.sh)" install_unix.sh
    

์ถ”๊ฐ€ ์„ค์น˜ ๋ฆฌ์†Œ์Šค

์ถ”๊ฐ€ ์„ค์น˜ ์˜ต์…˜์€ ์„ค์น˜ ๊ฐ€์ด๋“œ๋ฅผ ์ฐธ๊ณ ํ•˜์„ธ์š”.

Syslog๋ฅผ ์ˆ˜์ง‘ํ•˜์—ฌ Google SecOps๋กœ ์ „์†กํ•˜๋„๋ก Bindplane ์—์ด์ „ํŠธ ๊ตฌ์„ฑ

  1. ๊ตฌ์„ฑ ํŒŒ์ผ์— ์•ก์„ธ์Šคํ•ฉ๋‹ˆ๋‹ค.
    • config.yaml ํŒŒ์ผ์„ ์ฐพ์Šต๋‹ˆ๋‹ค. ์ผ๋ฐ˜์ ์œผ๋กœ Linux์—์„œ๋Š” /etc/bindplane-agent/ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ๊ณ  Windows์—์„œ๋Š” ์„ค์น˜ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ์Šต๋‹ˆ๋‹ค.
    • ํ…์ŠคํŠธ ํŽธ์ง‘๊ธฐ (์˜ˆ: nano, vi, ๋ฉ”๋ชจ์žฅ)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํŒŒ์ผ์„ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ๊ณผ ๊ฐ™์ด config.yaml ํŒŒ์ผ์„ ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค.

    receivers:
        udplog:
            # Replace the port and IP address as required
            listen_address: "0.0.0.0:514"
    
    exporters:
        chronicle/chronicle_w_labels:
            compression: gzip
            # Adjust the path to the credentials file you downloaded in Step 1
            creds_file_path: '/path/to/ingestion-authentication-file.json'
            # Replace with your actual customer ID from Step 2
            customer_id: <customer_id>
            endpoint: malachiteingestion-pa.googleapis.com
            # Add optional ingestion labels for better organization
            ingestion_labels:
                log_type: 'CYLANCE_PROTECT'
                raw_log_field: body
    
    service:
        pipelines:
            logs/source0__chronicle_w_labels-0:
                receivers:
                    - udplog
                exporters:
                    - chronicle/chronicle_w_labels
    
  3. ์ธํ”„๋ผ์— ํ•„์š”ํ•œ ๋Œ€๋กœ ํฌํŠธ์™€ IP ์ฃผ์†Œ๋ฅผ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

  4. <customer_id>๋ฅผ ์‹ค์ œ ๊ณ ๊ฐ ID๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

  5. Google SecOps ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ ๊ฐ€์ ธ์˜ค๊ธฐ ์„น์…˜์—์„œ ์ธ์ฆ ํŒŒ์ผ์ด ์ €์žฅ๋œ ๊ฒฝ๋กœ๋กœ /path/to/ingestion-authentication-file.json๋ฅผ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.

Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜์—ฌ ๋ณ€๊ฒฝ์‚ฌํ•ญ ์ ์šฉ

  • Linux์—์„œ Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    sudo systemctl restart bindplane-agent
    
  • Windows์—์„œ Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜๋ ค๋ฉด ์„œ๋น„์Šค ์ฝ˜์†”์„ ์‚ฌ์šฉํ•˜๊ฑฐ๋‚˜ ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค.

    net stop BindPlaneAgent && net start BindPlaneAgent
    

Cylance Protect์—์„œ Syslog ๊ตฌ์„ฑ

  1. Cylance ๊ด€๋ฆฌ ์ฝ˜์†”์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. ์„ค์ • > ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์œผ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. Syslog/SIEM ์ฒดํฌ๋ฐ•์Šค๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  4. ๋ชจ๋“  ์ด๋ฒคํŠธ๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  5. ๋‹ค์Œ ๊ตฌ์„ฑ ์„ธ๋ถ€์ •๋ณด๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
    • SIEM: Syslog๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
    • ํ”„๋กœํ† ์ฝœ: UDP๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
    • 2KB ์ดˆ๊ณผ ๋ฉ”์‹œ์ง€ ํ—ˆ์šฉ ์ฒดํฌ๋ฐ•์Šค๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
    • IP/๋„๋ฉ”์ธ: Bindplane ์—์ด์ „ํŠธ IP ์ฃผ์†Œ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.
    • ํฌํŠธ: Bindplane ์—์ด์ „ํŠธ ํฌํŠธ ๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค (์˜ˆ: UDP์˜ ๊ฒฝ์šฐ 514).
    • ๊ธฐ๋Šฅ: ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋กœ๊น… ์œ ํ˜•์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  6. Test Connection(์—ฐ๊ฒฐ ํ…Œ์ŠคํŠธ)์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
  7. ์ €์žฅ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

UDM ๋งคํ•‘ ํ…Œ์ด๋ธ”

๋กœ๊ทธ ํ•„๋“œ UDM ๋งคํ•‘ ๋…ผ๋ฆฌ
์—์ด์ „ํŠธ ๋ฒ„์ „ metadata.product_version Agent Version: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
Cylance ์ ์ˆ˜ security_result.severity_details Cylance Score: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
security_result.severity ๋‹ค์Œ ๋กœ์ง์— ๋”ฐ๋ผ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
- ๋†’์Œ: Cylance ์ ์ˆ˜๊ฐ€ 67๋ณด๋‹ค ํฐ ๊ฒฝ์šฐ
- ์ค‘๊ฐ„: Cylance ์ ์ˆ˜๊ฐ€ 33๋ณด๋‹ค ํฐ ๊ฒฝ์šฐ
- ๋‚ฎ์Œ: Cylance ์ ์ˆ˜๊ฐ€ 33 ์ดํ•˜์ธ ๊ฒฝ์šฐ
๊ฐ์ง€ํ•œ ์†Œ์Šค security_result.detection_fields.value Detected By: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
๊ธฐ๊ธฐ ID principal.asset_id Device Id: <value>์—์„œ ์ถ”์ถœ๋˜๊ณ  Cylance:์ด ์•ž์— ์ถ”๊ฐ€๋œ ๊ฐ’
๊ธฐ๊ธฐ ID principal.asset_id Device Ids: <value>์—์„œ ์ถ”์ถœ๋˜๊ณ  Cylance:์ด ์•ž์— ์ถ”๊ฐ€๋œ ๊ฐ’์œผ๋กœ, Device Id์ด ์—†๋Š” ๊ฒฝ์šฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
๊ธฐ๊ธฐ ์ด๋ฆ„ principal.hostname Device Name: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
๊ธฐ๊ธฐ ์ด๋ฆ„ target.hostname Device Name: <value>์—์„œ ์ถ”์ถœํ•œ ๊ฐ’์œผ๋กœ, ScriptControl๊ณผ ๊ฐ™์€ ํŠน์ • ์ด๋ฒคํŠธ ์œ ํ˜•์— ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
๊ธฐ๊ธฐ ์ด๋ฆ„ principal.hostname Device Names: <value>์—์„œ ์ถ”์ถœํ•œ ๊ฐ’์œผ๋กœ, Device Name์ด ์—†๋Š” ๊ฒฝ์šฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
์„ค๋ช… security_result.summary Description: <value>์—์„œ ์ถ”์ถœํ•œ ๊ฐ’์œผ๋กœ, OpticsCaeNetworkEvent๊ณผ ๊ฐ™์€ ํŠน์ • ์ด๋ฒคํŠธ ์œ ํ˜•์— ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
๋Œ€์ƒ IP target.ip Destination IP: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
๋Œ€์ƒ ํฌํŠธ target.port Destination Port: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
์ด๋ฒคํŠธ ID metadata.product_log_id Event Id: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
์ด๋ฒคํŠธ ์ด๋ฆ„ ํŠน์ • ์ด๋ฒคํŠธ ํ•˜์œ„ ์œ ํ˜•์„ ํ™•์ธํ•˜๊ณ  ํ•ด๋‹น ๋กœ์ง์„ ์ ์šฉํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
์ด๋ฒคํŠธ ์œ ํ˜• metadata.product_event_type Event Type: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
metadata.event_type Event Type ๋ฐ Event Name ํ•„๋“œ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ๋งคํ•‘๋˜๋ฉฐ ๊ธฐ๋ณธ๊ฐ’์€ GENERIC_EVENT์ž…๋‹ˆ๋‹ค.
ํŒŒ์ผ ์ด๋ฆ„ principal.process.file.full_path File Name: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’์œผ๋กœ, Path: <value>์™€ ๊ฒฐํ•ฉ๋˜์–ด ์ „์ฒด ๊ฒฝ๋กœ๋ฅผ ํ˜•์„ฑํ•ฉ๋‹ˆ๋‹ค.
ํŒŒ์ผ ๊ฒฝ๋กœ target.file.full_path File Path: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
์‹œ์ž‘ ํ”„๋กœ์„ธ์Šค ImageFileSha256 principal.process.file.sha256 Instigating Process ImageFileSha256: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
์‹œ์ž‘ ํ”„๋กœ์„ธ์Šค ์ด๋ฆ„ principal.process.file.full_path Instigating Process Name: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
์‹œ์ž‘ ํ”„๋กœ์„ธ์Šค ์†Œ์œ ์ž principal.user.userid Instigating Process Owner: <value>์—์„œ ์ถ”์ถœํ•œ ๊ฐ’์ž…๋‹ˆ๋‹ค. ์‚ฌ์šฉ์ž ์ด๋ฆ„์€ ์žˆ๋Š” ๊ฒฝ์šฐ //๋กœ ๋ถ„ํ• ํ•œ ํ›„ ์ถ”์ถœ๋ฉ๋‹ˆ๋‹ค.
์‹œ์ž‘ ํ”„๋กœ์„ธ์Šค ์†Œ์œ ์ž principal.administrative_domain //์ด ์žˆ๋Š” ๊ฒฝ์šฐ //๋กœ ๋ถ„ํ• ํ•˜์—ฌ Instigating Process Owner: <value>์—์„œ ์ถ”์ถœํ•œ ๋„๋ฉ”์ธ ์ด๋ฆ„
IP ์ฃผ์†Œ principal.ip IP Address: (<value>)์—์„œ ์ถ”์ถœ๋œ IP ์ฃผ์†Œ
์ธํ„ฐํ”„๋ฆฌํ„ฐ security_result.rule_labels.value Interpreter: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
์ธํ„ฐํ”„๋ฆฌํ„ฐ ๋ฒ„์ „ security_result.rule_labels.value Interpreter Version: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
๋กœ๊ทธ์ธํ•œ ์‚ฌ์šฉ์ž about.user.userid Logged On Users: (<value>)์—์„œ ์ถ”์ถœํ•œ ์‚ฌ์šฉ์ž ์ด๋ฆ„
MAC ์ฃผ์†Œ principal.mac MAC Address: (<value>)์—์„œ ์ถ”์ถœ๋˜๊ณ  ์ฝœ๋ก ์œผ๋กœ ํ˜•์‹์ด ์ง€์ •๋œ MAC ์ฃผ์†Œ
MD5 principal.process.file.md5 MD5: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
๋ฉ”์‹œ์ง€ AuditLog์™€ ๊ฐ™์€ ํŠน์ • ์ด๋ฒคํŠธ ์œ ํ˜•์˜ ๋ฐ์ดํ„ฐ๋ฅผ ์ถ”์ถœํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
OS principal.platform OS ํ•„๋“œ์— Windows๊ฐ€ ํฌํ•จ๋œ ๊ฒฝ์šฐ WINDOWS์— ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
๊ฒฝ๋กœ principal.process.file.full_path Path: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’์œผ๋กœ, File Name: <value>์™€ ๊ฒฐํ•ฉ๋˜์–ด ์ „์ฒด ๊ฒฝ๋กœ๋ฅผ ํ˜•์„ฑํ•ฉ๋‹ˆ๋‹ค.
์ •์ฑ… ์ด๋ฆ„ security_result.rule_name Policy Name: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
ํ”„๋กœ์„ธ์Šค ID principal.process.pid Process ID: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
ํ”„๋กœ์„ธ์Šค ์ด๋ฆ„ principal.process.file.full_path Process Name: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
ํ•ด๊ฒฐ๋œ ์ฃผ์†Œ network.dns.answers.name Resolved Address: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
SHA256 principal.process.file.sha256 SHA256: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
์†Œ์Šค IP principal.ip Source IP: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’์œผ๋กœ, ํŠน์ • ์ด๋ฒคํŠธ ์œ ํ˜•์— ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
์ƒํƒœ security_result.action ๊ฐ’์— ๋”ฐ๋ผ ํŠน์ • UDM ์ž‘์—…์— ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
~Quarantined: QUARANTINE
~Cleared: ALLOW_WITH_MODIFICATION
๋Œ€์ƒ ๋„๋ฉ”์ธ ์ด๋ฆ„ network.dns.questions.name Target Domain Name: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
ํƒ€๊ฒŸ ํ”„๋กœ์„ธ์Šค ImageFileSha256 target.process.file.sha256 Target Process ImageFileSha256: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
ํƒ€๊ฒŸ ํ”„๋กœ์„ธ์Šค ์ด๋ฆ„ target.process.file.full_path Target Process Name: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
ํƒ€๊ฒŸ ํ”„๋กœ์„ธ์Šค ์†Œ์œ ์ž target.user.userid Target Process Owner: <value>์—์„œ ์ถ”์ถœํ•œ ๊ฐ’์ž…๋‹ˆ๋‹ค. ์‚ฌ์šฉ์ž ์ด๋ฆ„์€ ์žˆ๋Š” ๊ฒฝ์šฐ //๋กœ ๋ถ„ํ• ํ•œ ํ›„ ์ถ”์ถœ๋ฉ๋‹ˆ๋‹ค.
ํƒ€๊ฒŸ ํ”„๋กœ์„ธ์Šค ์†Œ์œ ์ž target.administrative_domain //์ด ์žˆ๋Š” ๊ฒฝ์šฐ //๋กœ ๋ถ„ํ• ํ•˜์—ฌ Target Process Owner: <value>์—์„œ ์ถ”์ถœํ•œ ๋„๋ฉ”์ธ ์ด๋ฆ„
ํƒ€๊ฒŸ ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ KeyPath target.registry.registry_key Target Registry KeyPath: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
์œ„ํ˜‘ ๋ถ„๋ฅ˜ security_result.threat_name Threat Classification: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
์‚ฌ์šฉ์ž principal.user.userid User: <value>์—์„œ ์ถ”์ถœํ•œ ์‚ฌ์šฉ์ž ์ด๋ฆ„(์žˆ๋Š” ๊ฒฝ์šฐ)์ด User Name๊ฐ€ ์—†๋Š” ๊ฒฝ์šฐ ์‚ฌ์šฉ๋จ
์‚ฌ์šฉ์ž principal.user.email_addresses User: <value>์—์„œ ์ถ”์ถœ๋œ ์ด๋ฉ”์ผ ์ฃผ์†Œ(์žˆ๋Š” ๊ฒฝ์šฐ). User Name์ด ์—†๋Š” ๊ฒฝ์šฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
์‚ฌ์šฉ์ž ์ด๋ฆ„ principal.user.userid User Name: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
์œ„๋ฐ˜ ์œ ํ˜• security_result.summary Violation Type: <value>์—์„œ ์ถ”์ถœ๋˜๊ณ  ExploitAttempt:์ด ์•ž์— ์ถ”๊ฐ€๋œ ๊ฐ’
์œ„๋ฐ˜ ์œ ํ˜• security_result.threat_name Violation Type: <value>์—์„œ ์ถ”์ถœ๋œ ๊ฐ’
์˜์—ญ ์ด๋ฆ„ security_result.description Zone Names: (<value>)์—์„œ ์ถ”์ถœ๋˜๊ณ  Zone_Names:์ด ์•ž์— ์ถ”๊ฐ€๋œ ๊ฐ’
metadata.vendor_name Cylance๋กœ ํ•˜๋“œ์ฝ”๋”ฉ๋จ
metadata.product_name ๋กœ๊ทธ ๋ฉ”์‹œ์ง€์—์„œ ์ถ”์ถœํ•œ ๊ฐ’(PROTECT ๋˜๋Š” OPTICS)
metadata.log_type CYLANCE_PROTECT๋กœ ํ•˜๋“œ์ฝ”๋”ฉ๋จ
network.ip_protocol OpticsCaeNetworkEvent ์ด๋ฒคํŠธ์˜ ๊ฒฝ์šฐ TCP๋กœ ํ•˜๋“œ์ฝ”๋”ฉ๋จ
network.application_protocol OpticsCaeDnsEvent ์ด๋ฒคํŠธ์˜ ๊ฒฝ์šฐ DNS๋กœ ํ•˜๋“œ์ฝ”๋”ฉ๋จ
security_result.rule_labels.key ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ํ•„๋“œ์— ๋”ฐ๋ผ Interpreter ๋˜๋Š” Interpreter Version๋กœ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
security_result.detection_fields.key Detected By๋กœ ํ•˜๋“œ์ฝ”๋”ฉ๋จ
security_result.category ์ด๋ฒคํŠธ ์œ ํ˜•์— ๋”ฐ๋ผ ๋งคํ•‘๋˜๋ฉฐ ๊ฐ€๋Šฅํ•œ ๊ฐ’์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.
- SOFTWARE_SUSPICIOUS
- AUTH_VIOLOATION
- POLICY_VIOLATION
- NETWORK_SUSPICIOUS
- EXPLOIT
- SOFTWARE_MALICIOUS
security_result.action ์ด๋ฒคํŠธ ์œ ํ˜• ๋ฐ ํŠน์ • ์กฐ๊ฑด์— ๋”ฐ๋ผ ๋งคํ•‘๋˜๋ฉฐ, ๊ฐ€๋Šฅํ•œ ๊ฐ’์€
- ALLOW,
- BLOCK,
- QUARANTINE,
- ALLOW_WITH_MODIFICATION์ž…๋‹ˆ๋‹ค.

๋„์›€์ด ๋” ํ•„์š”ํ•˜์‹ ๊ฐ€์š”? ์ปค๋ฎค๋‹ˆํ‹ฐ ํšŒ์› ๋ฐ Google SecOps ์ „๋ฌธ๊ฐ€๋กœ๋ถ€ํ„ฐ ๋‹ต๋ณ€์„ ๋ฐ›์œผ์„ธ์š”.