Symantec EDR ๋กœ๊ทธ ์ˆ˜์ง‘

๋‹ค์Œ์—์„œ ์ง€์›:

์ด ๋ฌธ์„œ์—์„œ๋Š” Bindplane์„ ์‚ฌ์šฉํ•˜์—ฌ Symantec Endpoint Detection and Response (EDR) ๋กœ๊ทธ๋ฅผ Google Security Operations์— ์ˆ˜์ง‘ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค. ํŒŒ์„œ๋Š” JSON ๋˜๋Š” CEF ํ˜•์‹์˜ ๋กœ๊ทธ๋ฅผ ์ฒ˜๋ฆฌํ•ฉ๋‹ˆ๋‹ค. ํ•„๋“œ๋ฅผ ์ถ”์ถœํ•˜๊ณ  UDM์— ๋งคํ•‘ํ•˜๋ฉฐ ๋กœ๊ทธ ์ฝ˜ํ…์ธ ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ์ด๋ฒคํŠธ ์œ ํ˜• ๋ถ„๋ฅ˜๋ฅผ ์‹คํ–‰ํ•˜์—ฌ ๋„คํŠธ์›Œํฌ ์—ฐ๊ฒฐ, ํ”„๋กœ์„ธ์Šค ์ด๋ฒคํŠธ, ํŒŒ์ผ ์‹œ์Šคํ…œ ํ™œ๋™, ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ์ž‘์—…, ์‚ฌ์šฉ์ž ๋กœ๊ทธ์ธ/๋กœ๊ทธ์•„์›ƒ ์ด๋ฒคํŠธ๋ฅผ ์ฒ˜๋ฆฌํ•ฉ๋‹ˆ๋‹ค.

์‹œ์ž‘ํ•˜๊ธฐ ์ „์—

  • Google SecOps ์ธ์Šคํ„ด์Šค๊ฐ€ ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
  • Windows 2016 ์ด์ƒ ๋˜๋Š” systemd๊ฐ€ ์„ค์น˜๋œ Linux ํ˜ธ์ŠคํŠธ๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
  • ํ”„๋ก์‹œ ๋’ค์—์„œ ์‹คํ–‰ํ•˜๋Š” ๊ฒฝ์šฐ ๋ฐฉํ™”๋ฒฝ ํฌํŠธ๊ฐ€ ์—ด๋ ค ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
  • Symantec EDR์— ๋Œ€ํ•œ ๊ถŒํ•œ ์•ก์„ธ์Šค ๊ถŒํ•œ์ด ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

Google SecOps ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ ๊ฐ€์ ธ์˜ค๊ธฐ

  1. Google SecOps ์ฝ˜์†”์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. SIEM ์„ค์ • > ์ˆ˜์ง‘ ์—์ด์ „ํŠธ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•ฉ๋‹ˆ๋‹ค. Bindplane์ด ์„ค์น˜๋  ์‹œ์Šคํ…œ์— ํŒŒ์ผ์„ ์•ˆ์ „ํ•˜๊ฒŒ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

Google SecOps ๊ณ ๊ฐ ID ๊ฐ€์ ธ์˜ค๊ธฐ

  1. Google SecOps ์ฝ˜์†”์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. SIEM ์„ค์ • > ํ”„๋กœํ•„๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. ์กฐ์ง ์„ธ๋ถ€์ •๋ณด ์„น์…˜์—์„œ ๊ณ ๊ฐ ID๋ฅผ ๋ณต์‚ฌํ•˜์—ฌ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

Bindplane ์—์ด์ „ํŠธ ์„ค์น˜

Windows ์„ค์น˜

  1. ๋ช…๋ น ํ”„๋กฌํ”„ํŠธ ๋˜๋Š” PowerShell์„ ๊ด€๋ฆฌ์ž๋กœ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    msiexec /i "https://github.com/observIQ/bindplane-agent/releases/latest/download/observiq-otel-collector.msi" /quiet
    

Linux ์„ค์น˜

  1. ๋ฃจํŠธ ๋˜๋Š” sudo ๊ถŒํ•œ์œผ๋กœ ํ„ฐ๋ฏธ๋„์„ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    sudo sh -c "$(curl -fsSlL https://github.com/observiq/bindplane-agent/releases/latest/download/install_unix.sh)" install_unix.sh
    

์ถ”๊ฐ€ ์„ค์น˜ ๋ฆฌ์†Œ์Šค

Syslog๋ฅผ ์ˆ˜์ง‘ํ•˜์—ฌ Google SecOps๋กœ ์ „์†กํ•˜๋„๋ก Bindplane ์—์ด์ „ํŠธ ๊ตฌ์„ฑ

  1. ๊ตฌ์„ฑ ํŒŒ์ผ์— ์•ก์„ธ์Šคํ•ฉ๋‹ˆ๋‹ค.

    1. config.yaml ํŒŒ์ผ์„ ์ฐพ์Šต๋‹ˆ๋‹ค. ์ผ๋ฐ˜์ ์œผ๋กœ Linux์—์„œ๋Š” /etc/bindplane-agent/ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ๊ณ  Windows์—์„œ๋Š” ์„ค์น˜ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์žˆ์Šต๋‹ˆ๋‹ค.
    2. ํ…์ŠคํŠธ ํŽธ์ง‘๊ธฐ (์˜ˆ: nano, vi, ๋ฉ”๋ชจ์žฅ)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํŒŒ์ผ์„ ์—ฝ๋‹ˆ๋‹ค.
  2. ๋‹ค์Œ๊ณผ ๊ฐ™์ด config.yaml ํŒŒ์ผ์„ ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค.

    receivers:
        udplog:
            # Replace the port and IP address as required
            listen_address: "0.0.0.0:514"
    
    exporters:
        chronicle/chronicle_w_labels:
            compression: gzip
            # Adjust the path to the credentials file you downloaded in Step 1
            creds: '/path/to/ingestion-authentication-file.json'
            # Replace with your actual customer ID from Step 2
            customer_id: <customer_id>
            endpoint: malachiteingestion-pa.googleapis.com
            # Add optional ingestion labels for better organization
            ingestion_labels:
                log_type: 'SYMANTEC_EDR'
                raw_log_field: body
    
    service:
        pipelines:
            logs/source0__chronicle_w_labels-0:
                receivers:
                    - udplog
                exporters:
                    - chronicle/chronicle_w_labels
    
  3. ์ธํ”„๋ผ์— ํ•„์š”ํ•œ ๋Œ€๋กœ ํฌํŠธ์™€ IP ์ฃผ์†Œ๋ฅผ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

  4. <customer_id>๋ฅผ ์‹ค์ œ ๊ณ ๊ฐ ID๋กœ ๋ฐ”๊ฟ‰๋‹ˆ๋‹ค.

  5. Google SecOps ์ˆ˜์ง‘ ์ธ์ฆ ํŒŒ์ผ ๊ฐ€์ ธ์˜ค๊ธฐ ์„น์…˜์—์„œ ์ธ์ฆ ํŒŒ์ผ์ด ์ €์žฅ๋œ ๊ฒฝ๋กœ๋กœ /path/to/ingestion-authentication-file.json๋ฅผ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.

Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜์—ฌ ๋ณ€๊ฒฝ์‚ฌํ•ญ ์ ์šฉ

  • Linux์—์„œ Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

    sudo systemctl restart bindplane-agent
    
  • Windows์—์„œ Bindplane ์—์ด์ „ํŠธ๋ฅผ ๋‹ค์‹œ ์‹œ์ž‘ํ•˜๋ ค๋ฉด ์„œ๋น„์Šค ์ฝ˜์†”์„ ์‚ฌ์šฉํ•˜๊ฑฐ๋‚˜ ๋‹ค์Œ ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค.

    net stop BindPlaneAgent && net start BindPlaneAgent
    

Symantec EDR์—์„œ Syslog ๊ตฌ์„ฑํ•˜๊ธฐ

  1. Symantec EDR ์›น UI์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.
  2. EDR ํด๋ผ์šฐ๋“œ ์ฝ˜์†”์—์„œ ํ™˜๊ฒฝ > ์„ค์ •์œผ๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  3. ์–ดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ์„ ํƒํ•œ ๋‹ค์Œ ์–ดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
  4. EDR ์–ดํ”Œ๋ผ์ด์–ธ์Šค ์ฝ˜์†”์—์„œ ์„ค์ • > ์–ดํ”Œ๋ผ์ด์–ธ์Šค๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
  5. ๊ธฐ๋ณธ ์–ดํ”Œ๋ผ์ด์–ธ์Šค ์ˆ˜์ •์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
  6. ๊ธฐ๊ธฐ ๋ชฉ๋ก์—์„œ ๊ธฐ๊ธฐ๋ฅผ ๋”๋ธ”ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
  7. Syslog ์„น์…˜์—์„œ ๊ธฐ๋ณธ๊ฐ’ ์‚ฌ์šฉ์„ ์„ ํƒ ํ•ด์ œํ•ฉ๋‹ˆ๋‹ค (์„ ํƒ๋˜์–ด ์žˆ๋Š” ๊ฒฝ์šฐ).
  8. +Syslog ์„œ๋ฒ„ ์ถ”๊ฐ€๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.
  9. ๋‹ค์Œ ๊ตฌ์„ฑ ์„ธ๋ถ€์ •๋ณด๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
    • ํ˜ธ์ŠคํŠธ: Bindplane ์—์ด์ „ํŠธ IP ์ฃผ์†Œ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค.
    • ํ”„๋กœํ† ์ฝœ: Bindplane ์—์ด์ „ํŠธ ์„œ๋ฒ„์—์„œ ๊ตฌ์„ฑ๋œ ํ”„๋กœํ† ์ฝœ์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค(์˜ˆ: UDP).
    • ํฌํŠธ: Bindplane ์—์ด์ „ํŠธ ํฌํŠธ ๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•ฉ๋‹ˆ๋‹ค(์˜ˆ: 514).
  10. ์ €์žฅ์„ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

UDM ๋งคํ•‘ ํ…Œ์ด๋ธ”

๋กœ๊ทธ ํ•„๋“œ UDM ๋งคํ•‘ ๋…ผ๋ฆฌ
actor.cmd_line principal.process.command_line ์ž‘์—…์ž ํ”„๋กœ์„ธ์Šค์— ์˜ํ•ด ์‹คํ–‰๋œ ๋ช…๋ น์ค„์ž…๋‹ˆ๋‹ค.
actor.file.md5 principal.process.file.md5 ์ž‘์—… ์ˆ˜ํ–‰์ž์˜ ์‹คํ–‰ ํŒŒ์ผ์˜ MD5 ํ•ด์‹œ์ž…๋‹ˆ๋‹ค.
actor.file.path principal.process.file.full_path ์•กํ„ฐ์˜ ์‹คํ–‰ ํŒŒ์ผ์˜ ์ „์ฒด ๊ฒฝ๋กœ์ž…๋‹ˆ๋‹ค.
actor.file.sha2 principal.process.file.sha256 ์•กํ„ฐ์˜ ์‹คํ–‰ ํŒŒ์ผ์˜ SHA256 ํ•ด์‹œ์ž…๋‹ˆ๋‹ค.
actor.pid principal.process.pid ํ–‰์œ„์ž์˜ ํ”„๋กœ์„ธ์Šค ID์ž…๋‹ˆ๋‹ค.
actor.uid principal.resource.id ๋ฐฐ์šฐ์˜ ๊ณ ์œ  ์‹๋ณ„์ž์ž…๋‹ˆ๋‹ค.
actor.user.name principal.user.userid ํ–‰์œ„์ž์˜ ์‚ฌ์šฉ์ž ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.
actor.user.sid principal.user.windows_sid ํ–‰์œ„์ž ์‚ฌ์šฉ์ž์˜ Windows SID์ž…๋‹ˆ๋‹ค.
attack.technique_name security_result.threat_name MITRE ATT&CK ๊ธฐ๋ฒ•์˜ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.
attack.technique_uid security_result.description attack.technique_name์™€ ํ•จ๊ป˜ ์‚ฌ์šฉํ•˜์—ฌ <technique_uid>: <technique_name> ํ˜•์‹์œผ๋กœ security_result.description๋ฅผ ์ฑ„์›๋‹ˆ๋‹ค.
collector_device_ip intermediary.ip ์ˆ˜์ง‘๊ธฐ ๊ธฐ๊ธฐ์˜ IP ์ฃผ์†Œ์ž…๋‹ˆ๋‹ค.
collector_device_name intermediary.hostname ์ˆ˜์ง‘๊ธฐ ๊ธฐ๊ธฐ์˜ ํ˜ธ์ŠคํŠธ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.
collector_name intermediary.resource.name ์ˆ˜์ง‘๊ธฐ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.
collector_uid intermediary.resource.id ์ˆ˜์ง‘๊ธฐ์˜ ๊ณ ์œ  ์‹๋ณ„์ž์ž…๋‹ˆ๋‹ค.
connection.bytes_download network.received_bytes ์—ฐ๊ฒฐ์—์„œ ๋‹ค์šด๋กœ๋“œ๋œ ๋ฐ”์ดํŠธ ์ˆ˜์ž…๋‹ˆ๋‹ค.
connection.bytes_upload network.sent_bytes ์—ฐ๊ฒฐ์—์„œ ์—…๋กœ๋“œ๋œ ๋ฐ”์ดํŠธ ์ˆ˜์ž…๋‹ˆ๋‹ค.
connection.direction_id network.direction ๋„คํŠธ์›Œํฌ ์—ฐ๊ฒฐ์˜ ๋ฐฉํ–ฅ (1์€ ์ธ๋ฐ”์šด๋“œ, 2๋Š” ์•„์›ƒ๋ฐ”์šด๋“œ)์ž…๋‹ˆ๋‹ค.
connection.dst_ip target.ip ์—ฐ๊ฒฐ์˜ ๋Œ€์ƒ IP ์ฃผ์†Œ์ž…๋‹ˆ๋‹ค.
connection.dst_port target.port ์—ฐ๊ฒฐ์˜ ๋Œ€์ƒ ํฌํŠธ์ž…๋‹ˆ๋‹ค.
connection.src_ip principal.ip ์—ฐ๊ฒฐ์˜ ์†Œ์Šค IP ์ฃผ์†Œ์ž…๋‹ˆ๋‹ค.
connection.src_name principal.hostname ์—ฐ๊ฒฐ์˜ ์†Œ์Šค ํ˜ธ์ŠคํŠธ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.
connection.src_port principal.port ์—ฐ๊ฒฐ์˜ ์†Œ์Šค ํฌํŠธ์ž…๋‹ˆ๋‹ค.
connection.url.host target.hostname ์—ฐ๊ฒฐ URL์˜ ํ˜ธ์ŠคํŠธ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.
connection.url.scheme network.application_protocol ์—ฐ๊ฒฐ URL์˜ ์Šคํ‚ค๋งˆ์ž…๋‹ˆ๋‹ค (์˜ˆ: HTTP, HTTPS).
connection.url.text target.url ์ „์ฒด ์—ฐ๊ฒฐ URL์ž…๋‹ˆ๋‹ค.
data_source_url_domain target.url ๋ฐ์ดํ„ฐ ์†Œ์Šค URL์˜ ๋„๋ฉ”์ธ์ž…๋‹ˆ๋‹ค.
device_domain principal.administrative_domain/target.administrative_domain ๊ธฐ๊ธฐ์˜ ๋„๋ฉ”์ธ์ž…๋‹ˆ๋‹ค. connection.direction_id์™€ ๊ด€๋ จ๋œ ๋กœ์ง์— ๋”ฐ๋ผ ์ฃผ ๊ตฌ์„ฑ์› ๋˜๋Š” ๋Œ€์ƒ์— ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
device_ip principal.ip/target.ip ๊ธฐ๊ธฐ์˜ IP ์ฃผ์†Œ์ž…๋‹ˆ๋‹ค. connection.direction_id์™€ ๊ด€๋ จ๋œ ๋กœ์ง์— ๋”ฐ๋ผ ์ฃผ ๊ตฌ์„ฑ์› ๋˜๋Š” ๋Œ€์ƒ์— ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
device_name principal.hostname/target.hostname ๊ธฐ๊ธฐ์˜ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค. connection.direction_id์™€ ๊ด€๋ จ๋œ ๋กœ์ง์— ๋”ฐ๋ผ ์ฃผ ๊ตฌ์„ฑ์› ๋˜๋Š” ๋Œ€์ƒ์— ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
device_os_name principal.platform_version/target.platform_version ๊ธฐ๊ธฐ์˜ ์šด์˜์ฒด์ œ connection.direction_id์™€ ๊ด€๋ จ๋œ ๋กœ์ง์— ๋”ฐ๋ผ ์ฃผ ๊ตฌ์„ฑ์› ๋˜๋Š” ๋Œ€์ƒ์— ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
device_uid target.asset_id ๊ธฐ๊ธฐ์˜ ๊ณ ์œ  ์‹๋ณ„์ž์ด๋ฉฐ Device ID:์ด(๊ฐ€) ์•ž์— ๋ถ™์Šต๋‹ˆ๋‹ค.
directory.path target.file.full_path ๋””๋ ‰ํ„ฐ๋ฆฌ์˜ ๊ฒฝ๋กœ์ž…๋‹ˆ๋‹ค.
domain_name target.administrative_domain ๋„๋ฉ”์ธ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.
event_actor.file.path target.process.file.full_path ์ด๋ฒคํŠธ ํ–‰์œ„์ž์˜ ์‹คํ–‰ ํŒŒ์ผ ๊ฒฝ๋กœ์ž…๋‹ˆ๋‹ค.
event_actor.pid target.process.pid ์ด๋ฒคํŠธ ํ–‰์œ„์ž์˜ ํ”„๋กœ์„ธ์Šค ID์ž…๋‹ˆ๋‹ค.
event_desc metadata.description ์ด๋ฒคํŠธ์˜ ์„ค๋ช…์œผ๋กœ
externalIP target.ip ์™ธ๋ถ€ IP ์ฃผ์†Œ์ž…๋‹ˆ๋‹ค.
file.md5 target.file.md5 ํŒŒ์ผ์˜ MD5 ํ•ด์‹œ
file.path target.file.full_path ํŒŒ์ผ์˜ ๊ฒฝ๋กœ์ž…๋‹ˆ๋‹ค.
file.rep_prevalence_band additional.fields.value.number_value ํŒŒ์ผ์˜ ํ‰ํŒ ์œ ํ–‰ ๋ฒ”์œ„๋กœ, ํ‚ค prevalence_score์™€ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
file.rep_score_band additional.fields.value.number_value ํŒŒ์ผ์˜ ํ‰ํŒ ์ ์ˆ˜ ๋ฒ”์œ„๋กœ, reputation_score ํ‚ค์™€ ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
file.sha2 target.file.sha256 ํŒŒ์ผ์˜ SHA256 ํ•ด์‹œ์ž…๋‹ˆ๋‹ค.
file.size target.file.size ํŒŒ์ผ ํฌ๊ธฐ์ž…๋‹ˆ๋‹ค.
internalHost principal.hostname ๋‚ด๋ถ€ ํ˜ธ์ŠคํŠธ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.
internalIP principal.ip ๋‚ด๋ถ€ IP ์ฃผ์†Œ์ž…๋‹ˆ๋‹ค.
internal_port principal.port ๋‚ด๋ถ€ ํฌํŠธ์ž…๋‹ˆ๋‹ค.
kernel.name target.resource.name ์ปค๋„ ๊ฐ์ฒด์˜ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค. target.resource.type๋Š” MUTEX์œผ๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.
message metadata.description ๋กœ๊ทธ ๋ฉ”์‹œ์ง€์ž…๋‹ˆ๋‹ค.
module.md5 target.process.file.md5 ๋ชจ๋“ˆ์˜ MD5 ํ•ด์‹œ์ž…๋‹ˆ๋‹ค.
module.path target.process.file.full_path ๋ชจ๋“ˆ์˜ ๊ฒฝ๋กœ์ž…๋‹ˆ๋‹ค.
module.sha2 target.process.file.sha256 ๋ชจ๋“ˆ์˜ SHA256 ํ•ด์‹œ์ž…๋‹ˆ๋‹ค.
module.size target.process.file.size ๋ชจ๋“ˆ์˜ ํฌ๊ธฐ์ž…๋‹ˆ๋‹ค.
process.cmd_line target.process.command_line ํ”„๋กœ์„ธ์Šค์˜ ๋ช…๋ น์ค„์ž…๋‹ˆ๋‹ค.
process.file.md5 target.process.file.md5 ํ”„๋กœ์„ธ์Šค์˜ ์‹คํ–‰ ํŒŒ์ผ์˜ MD5 ํ•ด์‹œ์ž…๋‹ˆ๋‹ค.
process.file.path target.process.file.full_path ํ”„๋กœ์„ธ์Šค์˜ ์‹คํ–‰ ํŒŒ์ผ ๊ฒฝ๋กœ์ž…๋‹ˆ๋‹ค.
process.file.sha2 target.process.file.sha256 ํ”„๋กœ์„ธ์Šค์˜ ์‹คํ–‰ ํŒŒ์ผ์˜ SHA256 ํ•ด์‹œ์ž…๋‹ˆ๋‹ค.
process.pid target.process.pid ํ”„๋กœ์„ธ์Šค ID์ž…๋‹ˆ๋‹ค.
process.uid target.resource.id ํ”„๋กœ์„ธ์Šค์˜ ๊ณ ์œ  ์‹๋ณ„์ž์ž…๋‹ˆ๋‹ค.
process.user.name target.user.userid ํ”„๋กœ์„ธ์Šค์™€ ์—ฐ๊ฒฐ๋œ ์‚ฌ์šฉ์ž ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.
process.user.sid target.user.windows_sid ํ”„๋กœ์„ธ์Šค ์‚ฌ์šฉ์ž์˜ Windows SID์ž…๋‹ˆ๋‹ค.
product_name metadata.product_name ๋กœ๊ทธ๋ฅผ ์ƒ์„ฑํ•˜๋Š” ์ œํ’ˆ์˜ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.
product_ver metadata.product_version ๋กœ๊ทธ๋ฅผ ์ƒ์„ฑํ•˜๋Š” ์ œํ’ˆ์˜ ๋ฒ„์ „์ž…๋‹ˆ๋‹ค.
reg_key.path target.registry.registry_key ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ‚ค ๊ฒฝ๋กœ์ž…๋‹ˆ๋‹ค.
reg_value.data target.registry.registry_value_data ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ๊ฐ’ ๋ฐ์ดํ„ฐ์ž…๋‹ˆ๋‹ค.
reg_value.name target.registry.registry_value_name ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ๊ฐ’ ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.
reg_value.path target.registry.registry_key ๊ฐ’์˜ ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ‚ค ๊ฒฝ๋กœ์ž…๋‹ˆ๋‹ค.
security_result.severity security_result.severity ๋ณด์•ˆ ๊ฒฐ๊ณผ์˜ ์‹ฌ๊ฐ๋„์ž…๋‹ˆ๋‹ค. ์ˆซ์ž ๊ฐ’์—์„œ UDM ์—ด๊ฑฐํ˜•์œผ๋กœ ๋ณ€ํ™˜๋ฉ๋‹ˆ๋‹ค (์˜ˆ: 1~LOW, 5~MEDIUM, 10~LOW, 15~LOW)
session.id network.session_id ์„ธ์…˜ ID์ž…๋‹ˆ๋‹ค.
session.user.name target.user.userid ์„ธ์…˜๊ณผ ์—ฐ๊ฒฐ๋œ ์‚ฌ์šฉ์ž ์ด๋ฆ„์ž…๋‹ˆ๋‹ค.
sid principal.user.userid ๋ณด์•ˆ ์‹๋ณ„์ž (SID)์ž…๋‹ˆ๋‹ค.
status_detail security_result.summary ์ƒํƒœ์— ๋Œ€ํ•œ ์ถ”๊ฐ€ ์„ธ๋ถ€์ •๋ณด์ž…๋‹ˆ๋‹ค.
type_id metadata.product_event_type ์ด๋ฒคํŠธ ์œ ํ˜• ID์ž…๋‹ˆ๋‹ค.
user_agent_ip target.ip ์‚ฌ์šฉ์ž ์—์ด์ „ํŠธ์˜ IP ์ฃผ์†Œ์ž…๋‹ˆ๋‹ค.
user_name principal.user.userid/target.user.user_display_name ์‚ฌ์šฉ์ž ์ด๋ฆ„์ž…๋‹ˆ๋‹ค. CEF ๋˜๋Š” JSON ํŒŒ์‹ฑ๊ณผ ๊ด€๋ จ๋œ ๋กœ์ง์— ๋”ฐ๋ผ ์ฃผ ๊ตฌ์„ฑ์› ๋˜๋Š” ํƒ€๊ฒŸ์— ๋งคํ•‘๋ฉ๋‹ˆ๋‹ค.
user_uid target.user.userid ์‚ฌ์šฉ์ž์˜ ๊ณ ์œ  ์‹๋ณ„์ž์ž…๋‹ˆ๋‹ค.
uuid metadata.product_log_id ์ด๋ฒคํŠธ์˜ UUID์ž…๋‹ˆ๋‹ค.
event.idm.read_only_udm.metadata.event_timestamp event.idm.read_only_udm.metadata.event_timestamp ์ด๋ฒคํŠธ์˜ ํƒ€์ž„์Šคํƒฌํ”„์ž…๋‹ˆ๋‹ค. log_time ๋˜๋Š” CEF device_time์—์„œ ํŒŒ์ƒ๋ฉ๋‹ˆ๋‹ค.
event.idm.read_only_udm.metadata.log_type event.idm.read_only_udm.metadata.log_type ๋กœ๊ทธ ์œ ํ˜•์ž…๋‹ˆ๋‹ค. SYMANTEC_EDR๋กœ ํ•˜๋“œ์ฝ”๋”ฉ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
event.idm.read_only_udm.metadata.vendor_name event.idm.read_only_udm.metadata.vendor_name ๊ณต๊ธ‰์—…์ฒด ์ด๋ฆ„์ž…๋‹ˆ๋‹ค. Symantec๋กœ ํ•˜๋“œ์ฝ”๋”ฉ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
event.idm.read_only_udm.extensions.auth.type event.idm.read_only_udm.extensions.auth.type ์ธ์ฆ ์œ ํ˜•์ž…๋‹ˆ๋‹ค. ๋กœ๊ทธ์ธ ๋ฐ ๋กœ๊ทธ์•„์›ƒ ์ด๋ฒคํŠธ์˜ ๊ฒฝ์šฐ MACHINE๋กœ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
security_result.action security_result.action ๋ณด์•ˆ ์ด๋ฒคํŠธ์˜ ๊ฒฐ๊ณผ๋กœ ์ทจํ•ด์ง„ ์กฐ์น˜์ž…๋‹ˆ๋‹ค. ์„ฑ๊ณต์ ์ธ ๋กœ๊ทธ์ธ ๋ฐ ๋กœ๊ทธ์•„์›ƒ์˜ ๊ฒฝ์šฐ ALLOW๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.

๋„์›€์ด ๋” ํ•„์š”ํ•˜์‹ ๊ฐ€์š”? ์ปค๋ฎค๋‹ˆํ‹ฐ ํšŒ์› ๋ฐ Google SecOps ์ „๋ฌธ๊ฐ€๋กœ๋ถ€ํ„ฐ ๋‹ต๋ณ€์„ ๋ฐ›์œผ์„ธ์š”.