1 of 34

February 20, 2018

Using Open Source Tools to Solve New DFIR Challenges

1

1

2 of 34

  • 12+ years of Cyber Security Project Management experience
  • 14+ years of experience working with SOCs
  • 18+ years of experience working in Cyber Security
  • Author of multiple Open Source forensics tools

My Backstory

2

3 of 34

New Challenges

What is Live Response (LR)

DFIR and LR for Everyone

Take Advantage of the Cloud

Automation Everywhere

Discussion Points

3

4 of 34

System Diversity

  • Mixed Operating Systems
    • Windows
    • Linux
    • MacOS
  • The Cloud
    • GCP
    • AWS
    • More

New Challenges

Doing More with Less

  • The Cloud
    • Monitoring
    • Collecting
    • Adjudicating

Cross Platform Tooling

  • Lack of Endpoint Detection and Response (EDR) solution that
    • Works on All Endpoints
    • Allows collection of raw data
    • Integrates with automation systems

4

5 of 34

5

What is Live Response?

Collecting and Analyzing a subset of data to quickly determine the validity and severity of a suspected malicious event

6 of 34

6

  • Login History
  • Web Browser History
  • Active Processes

What is Collected?

Clear Text

Binary Data

  • Active Network Connections
  • Installed Programs
  • List of all users

7 of 34

7

Live Response Process

Collect Data

Process Data

Analyze Data

8 of 34

Live Response vs Cold Disk/Disk Image

Live Response:

Small collection of critical artifacts

  • Enables quick investigation
  • Initial set of artifacts
    • Requires subsequent collection of suspicious files
  • Not a forensically sound collection technique

Cold Disk/Disk Image:

Block copy of the full file structure

  • Creates a delay before investigation
  • Collects all data on the target host
    • Does not require subsequent collection
  • Required for forensically sound investigation

9 of 34

DFIR and LR For Everyone

CyLR, CDQR Forensics - Virtual Machine (CCF-VM)

9

10 of 34

Logical Workflow (simple concept)

10

IR Analyst

Compromised System

CCF-VM

1) Initiate artifact collection

2) Collection direct to server

3) Perform analysis

11 of 34

Collect with CyLR

The Process

View with TimeSketch

Process with CDQR

11

12 of 34

Collect: CyLR

Collects forensic artifacts from hosts

  • Works on multiple Operating Systems
    • Windows
    • MacOS
    • Linux
  • Fast Collections
  • Supports RAW file copy on NTFS
  • In memory only collection option (writes nothing to disk)
  • Built in SFTP transmission capability

12

13 of 34

Factors in Artifact Collection

Minimize impact on target host

    • Process executions
    • Data written to:
      • Disk
      • Memory

Windows API

    • Bypass for block-level collection
    • Prevents “file locking”
    • Ensures collection of any data in slack space
    • Utilize when block-level fails

13

14 of 34

CyLR: Default Collection Artifact List

Windows

  • "%SYSTEMROOT%\System32\drivers\etc\hosts"
  • "%SYSTEMROOT%\SchedLgU.Txt"
  • "%PROGRAMDATA%\Microsoft\Windows\Start Menu\Programs\Startup"
  • "%SYSTEMROOT%\System32\config"
  • "%SYSTEMROOT%\System32\winevt\logs"
  • "%SYSTEMROOT%\Prefetch"
  • "%SYSTEMROOT%\Tasks"
  • "%SYSTEMROOT%\System32\LogFiles\W3SVC1"
  • "%SystemDrive%\$MFT"

Mac and Linux

  • /var/log"
  • "/private/var/log/"
  • "/.fseventsd"
  • "/etc/hosts.allow"
  • "/etc/hosts.deny"
  • "/etc/hosts"
  • "/System/Library/StartupItems"
  • "/System/Library/LaunchAgents"
  • "/System/Library/LaunchDaemons"
  • "/Library/LaunchAgents"
  • "/Library/LaunchDaemons"
  • "/Library/StartupItems"
  • "/etc/passwd"
  • "/etc/group"
  • All plist files
  • All .bash_history files
  • All .sh_history files

14

15 of 34

CyLR: Default Collection Demo

16 of 34

CyLR: Custom Collection Demo

17 of 34

Process: CDQR

Parses raw data from bits and bytes to words and numbers. Provides a fast, easy to use interface for Plaso.

  • Dramatically speeds up triaging by implementing a “Live Response” model of investigation
  • Parses
    • Forensic Images (dd, E01, etc)
    • Disk Images (dd, vmdk, etc)
    • Artifacts (collection of files or folders)

17

18 of 34

  1. Parser Options
    1. DATT (Do All The Things)
    2. Win
    3. Lin
    4. Mac
  2. Swiss Army Knife of DFIR:
    • Individual Artifacts: c:\Windows\System32\winevt\Logs\Security.evtx
    • Collection of Artifacts:
      1. By Folder: case1234_artifacts
      2. Inside Zip file: case1234.zip
    • Disk/VM Images: suspect_vm.vmdk

CDQR Parsers

18

19 of 34

Investigate: CSV Reports

Create one SuperTimeline

Data is parsed into a maximum of 16 special reports

Special reports group similar data together and include additional parsing to speed up analysis

19

20 of 34

CDQR Special Reports

  1. Appcompat
    1. appcompatcache
  2. Login
    • dockerjson,ssh,winlogon,utmp,utmpx
  3. Event Logs
    • winevt,winevtx
  4. File System
    • filestat,recycle_bin
  5. MFT
    • mft
  6. UsnJrnl
    • usnjrnl
  7. Internet History
    • binary_cookies,chrome_cache,chrome_preferences,,firefox_cache,firefox_cache2,java_idx,msiecf,opera_global,opera_typed_history,safari_history,chrome_cookies,chrome_extension_activity,chrome_history,firefox_cookies,firefox_downloads,firefox_history,google_drive,windows_typed_urls
  8. Prefetch
    • Prefetch
  9. Registry
    • winreg,winreg_default
  10. Scheduled Tasks
    • winjob,windows_task_cache,cron

  1. Persistence
    1. bagmru,mrulist_shell_item_list,mrulist_string,mrulistex_shell_item_list,mrulistex_string,mrulistex_string_and_shell_item,mrulistex_string_and_shell_item_list,msie_zone,mstsc_rdp,mstsc_rdp_mru,userassist,windows_boot_execute,windows_boot_verify,windows_run,windows_sam_users,windows_services,winrar_mru
  2. System Information
    • rplog,explorer_mountpoints2,explorer_programscache,windows_shutdown,windows_timezone,windows_usb_devices,windows_usbstor_devices,windows_version,network_drives,dpkg
  3. AntiVirus
    • mcafee_protection,symantec_scanlog,ccleaner
  4. Firewall
    • winfirewall,mac_appfirewall_log
  5. Mac
    • mac_keychain,mac_securityd,mactime,plist,airport,apple_id,ipod_device,macosx_bluetooth,macosx_install_history,macuser,maxos_software_update,plist_default,spotlight,spotlight_volume,time_machine,appusage,mackeeper_cache,imessage
  6. Linux
    • bsm_log,popularity_contest,selinux,zsh_extended_history

21 of 34

Example: Event Log Report.csv

22 of 34

CDQR: CDQR to CSV Reports

23 of 34

CDQR: CDQR to ElasticSearch

24 of 34

Investigate: ELK +T

Elasticsearch: Search and analytics engine

Kibana: Visualization engine for Elasticsearch data

TimeSketch: Investigative Tool that provides easy access to data as well as multi-user support and investigative aids

24

25 of 34

  1. --es_ts <Index Name> or es_kb <Index Name>
    1. Assign desired index name during execution
    2. Recommendation:
      1. Use individual indexes for each artifact set
      2. Use same prefix (such as case number) for all hosts in a case
        1. 18-001-bluehotel-$hostname
  2. Viewing reports:

CDQR

Kibana and TimeSketch

25

26 of 34

TimeSketch

26

27 of 34

Kibana

27

28 of 34

Easy Access

Simple Setup

Relatively low cost

Strong authentication methods

Multiple methods to optimize access

Take Advantage of the Cloud

28

29 of 34

Preparing for GCP Build

All instructions are in https://github.com/rough007/CCF-VM

29

30 of 34

Build CCF-VM in Cloud

30

Create GCP Data Bucket

Copy CCF-VM_3.0.tar.gz to GCP Bucket

Create GCP image

Create new CCF-VM instance (AND LOG IN)

31 of 34

In house 24/7/365 SOC is expensive

SaaS is expensive

Alert volume too high

Automation is the answer

Automation Everywhere

31

32 of 34

Data Enrichment

  • Create Ticket for each alert
  • Assign to appropriate team
  • Retrieve host information and owner from Internal IP address in alert
  • Use IOC from alert to validate with intelligence system and add data to ticket
    • Close if known FP
  • Send chat and email message directing users to ticket
  • Automatically close tickets based on user feedback

Automation Activities

Reduce Training

  • Standardization is assured
  • Teach Analysts one step that launches multiple steps
  • Focus on reviewing data, not collecting data
  • Removed communication bottlenecks (no waiting for authorization or admins to respond)

Rapid Response

  • Execute Live Response (full or targeted) using data from alert
  • Retry Live Response attempts until successful
  • Search results of Live Response and close or escalated ticket based on results
  • Automatically add data to threat intelligence system when tickets are closed

32

33 of 34

Managing Risk

Silent Failures

Infinite Loops (runaway processes)

Proprietary solutions

Automation Pitfalls

33

34 of 34

Q&A