href="/content/fireeye-www/en_US/services/freeware/redline.html">Mandiant
RedlineTM and href="/content/fireeye-www/en_US/services/freeware/ioc-finder.html">IOC
Finder TM collect and parse a huge body of
evidence from a running system. In fact, they're based on the same
agent software as our flagship href="http://www.mandiant.com/products/platform/">Mandiant
Intelligent Response® product. During the course of their
"audits", these tools conduct comprehensive analysis of
the file system (including hashing, time stamps, parsing of PE file
structures, and digital signature checks), registry hives, processes
in memory, event logs, active network connections,DNS cache
contents,web browser history, system restore points, scheduled
tasks, prefetch entries, persistence mechanisms, and much more.
Once this data is collected, Redline and IOCFinder currently
allow you to do one of two things:
But what if you want to analyze all
of the raw evidence - not just memory or IOC hits - and do
traditional forensics and timeline analysis? That's where href="https://github.com/mandiant/AuditParser">Audit Parser
steps in. It's the newest addition to Mandiant's portfolio of href="/content/fireeye-www/en_US/services/freeware.html">free
software.
Audit Parser is simple:it takes the complex XML
data produced by Redline or IOCFinder and converts it into
human-readable tab-delimited text. You can then easily review the
output in Excel, use a dedicated CSV file viewer (we're fans of
"CSVed" and"CSVFileView"), import it into a
database, or grep / manipulate it to your heart's content.
When paired with Redline's new start-up workflow to build a
"collector" script, Audit Parser gives you a complete(and
free)live response analysis toolkit. You can customize the Redline
collector to gather as much or as little evidence as desired, run it
on your target system, and then easily review all of the results
following a quick conversion with Audit Parser.
The screen
capture below shows Audit Parser's options - it's pretty
straightforward to use:
href="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab01.jpg"> width="801" height="268"
class="alignnone size-full wp-image-3010"
title="auditparser-screengrab0"
src="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab01.jpg" />
Tabular data in Excel doesn't make for the most exciting screen
shots, but we wanted to give you a glimpse into what the output
looks like and the extent of evidence available for filtering,
sorting, and analysis:
href="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab12.jpg"> width="1024" height="254"
class="alignnone size-large wp-image-3014"
title="auditparser-screengrab1"
src="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab12-1024x254.jpg" />
href="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab2.jpg"> width="1024" height="282"
class="alignnone size-large wp-image-3015"
title="auditparser-screengrab2"
src="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab2-1024x282.jpg" />
href="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab3.jpg"> width="1024" height="165"
class="alignnone size-large wp-image-3016"
title="auditparser-screengrab3"
src="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab3-1024x165.jpg" />
href="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab4.jpg"> width="1024" height="496"
class="alignnone size-large wp-image-3017"
title="auditparser-screengrab4"
src="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab4-1024x496.jpg" />
The default "comprehensive collector" script in Redline
collects all of the artifacts listed above, as well as many
more.
But wait - that's not all! Audit Parser also contains
timeline generation functionality. Just specify a time & date
range, and it will build a sorted timeline of all file system,
registry, and event log events that occurred within that period.
Future releases will add more audit types and customizability to
this feature.
Audit Parser is written in Python and is
distributed under the Apache License. It requires the lxml ( href="http://lxml.de/">http://lxml.de/) library. We're also
distributing a Windows EXE built with Py2EXE for users that may not
have a Python environment set up. You can download the tool and
documentation on GitHub at: href="https://github.com/mandiant/AuditParser">https://github.com/mandiant/AuditParser
If you have any questions or comments, feel free to leave them
below, e-mail me (ryan [dot] kazanciyan [at] mandiant.com), or DM me
on Twitter at href="https://twitter.com/ryankaz42"
target="_blank">@ryankaz42. I'll also be at Black Hat USA next
week teaching href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_md-ir.html">Mandiant's
Incident Response course where we'll be going through an
in-depth live response analysis lab using Redline, Audit Parser, and
other forensic tools. I was on a recent M-Unition podcast discussing
the class and how it is completely revamped for 2012. You can listen
to the podcast href="https://blog.mandiant.com/archives/2942"
target="_blank">here. Hope to see you there!