Auteur Sujet: [FireEye]New Open Source Tool: Audit Parser  (Lu 2784 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
[FireEye]New Open Source Tool: Audit Parser
« le: juillet 24, 2020, 13:00:18 »
New Open Source Tool: Audit Parser


 


          href="/content/fireeye-www/en_US/services/freeware/redline.html">Mandiant
    RedlineTM and       href="/content/fireeye-www/en_US/services/freeware/ioc-finder.html">IOC
        Finder TM collect and parse a huge body of
    evidence from a running system. In fact, they're based on the same
    agent software as our flagship       href="http://www.mandiant.com/products/platform/">Mandiant
      Intelligent Response® product. During the course of their
    "audits", these tools conduct comprehensive analysis of
    the file system (including hashing, time stamps, parsing of PE file
    structures, and digital signature checks), registry hives, processes
    in memory, event logs, active network connections,DNS cache
    contents,web browser history, system restore points, scheduled
    tasks, prefetch entries, persistence mechanisms, and much more.


   

Once this data is collected, Redline and IOCFinder currently
    allow you to do one of two things:

  • Review the contents
          of memory through a visual workflow in Redline
  • Search for
          Indicators of Compromise (IOCs) and generate a report of
        "hits"

But what if you want to analyze all
    of the raw evidence - not just memory or IOC hits - and do
    traditional forensics and timeline analysis? That's where       href="https://github.com/mandiant/AuditParser">Audit Parser
    steps in. It's the newest addition to Mandiant's portfolio of       href="/content/fireeye-www/en_US/services/freeware.html">free
  software.

Audit Parser is simple:it takes the complex XML
    data produced by Redline or IOCFinder and converts it into
    human-readable tab-delimited text. You can then easily review the
    output in Excel, use a dedicated CSV file viewer (we're fans of
    "CSVed" and"CSVFileView"), import it into a
    database, or grep / manipulate it to your heart's content.


   

When paired with Redline's new start-up workflow to build a
    "collector" script, Audit Parser gives you a complete(and
    free)live response analysis toolkit. You can customize the Redline
    collector to gather as much or as little evidence as desired, run it
    on your target system, and then easily review all of the results
    following a quick conversion with Audit Parser.

The screen
    capture below shows Audit Parser's options - it's pretty
    straightforward to use:


   
                href="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab01.jpg">          width="801" height="268"
          class="alignnone size-full wp-image-3010"
          title="auditparser-screengrab0"
  src="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab01.jpg" />


   

Tabular data in Excel doesn't make for the most exciting screen
    shots, but we wanted to give you a glimpse into what the output
    looks like and the extent of evidence available for filtering,
    sorting, and analysis:

  • A filtered view of a file system
          audit, showing complete file metadata for all PE files within
          %SYSTEMROOT% created between 2011-2012 that are not digitally
        signed.


            href="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab12.jpg">        width="1024" height="254"
        class="alignnone size-large wp-image-3014"
        title="auditparser-screengrab1"
  src="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab12-1024x254.jpg" />


   
  • A portion of a prefetch audit, showing how the contents of
          .PF files are automatically parsed to provide last time executed,
          # of times executed, and original file path metadata.


            href="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab2.jpg">        width="1024" height="282"
        class="alignnone size-large wp-image-3015"
        title="auditparser-screengrab2"
  src="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab2-1024x282.jpg" />


   
  • A portion of a full registry dump, showing review of Active
          Setup Installed Components registry keys - the data includes all
          key value / data pairs and last modified dates.


            href="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab3.jpg">        width="1024" height="165"
        class="alignnone size-large wp-image-3016"
        title="auditparser-screengrab3"
  src="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab3-1024x165.jpg" />


   
  • A portion of the parsed Windows event logs, showing review
          of process auditing events including event log source, time
          generated, event ID, and full event message contents.


            href="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab4.jpg">        width="1024" height="496"
        class="alignnone size-large wp-image-3017"
        title="auditparser-screengrab4"
  src="https://www.fireeye.com/content/dam/legacy/ammo/auditparser-screengrab4-1024x496.jpg" />


   

The default "comprehensive collector" script in Redline
    collects all of the artifacts listed above, as well as many
  more.

But wait - that's not all! Audit Parser also contains
    timeline generation functionality. Just specify a time & date
    range, and it will build a sorted timeline of all file system,
    registry, and event log events that occurred within that period.
    Future releases will add more audit types and customizability to
    this feature.

Audit Parser is written in Python and is
    distributed under the Apache License. It requires the lxml (    href="http://lxml.de/">http://lxml.de/) library. We're also
    distributing a Windows EXE built with Py2EXE for users that may not
    have a Python environment set up. You can download the tool and
    documentation on GitHub at:   href="https://github.com/mandiant/AuditParser">https://github.com/mandiant/AuditParser


   

If you have any questions or comments, feel free to leave them
    below, e-mail me (ryan [dot] kazanciyan [at] mandiant.com), or DM me
    on Twitter at       href="https://twitter.com/ryankaz42"
    target="_blank">@ryankaz42
. I'll also be at Black Hat USA next
    week teaching       href="http://blackhat.com/html/bh-us-12/training/courses/bh-us-12-training_md-ir.html">Mandiant's
      Incident Response course where we'll be going through an
    in-depth live response analysis lab using Redline, Audit Parser, and
    other forensic tools. I was on a recent M-Unition podcast discussing
    the class and how it is completely revamped for 2012. You can listen
    to the podcast       href="https://blog.mandiant.com/archives/2942"
    target="_blank">here
. Hope to see you there!


Source: New Open Source Tool: Audit Parser

Tags: