1. lsass dump

๋ณธ ํ”„๋กœ์ ํŠธ์—์„œ๋Š” mimikatz sekurlsa::logonpassword๋ฅผ ์‚ฌ์šฉํ•˜์˜€์œผ๋‚˜, ์•„๋ž˜ Event๋Š” tool์— ํ•œ์ •๋˜์ง€ ์•Š๋Š”๋‹ค.

[Victim Client] Event ID 4656 (lsass.exe Handle ์š”์ฒญ ํƒ์ง€)

โ†’ Process Information - Name์ด ์ผ๋ฐ˜์ ์œผ๋กœ lsass.exe์— ์ ‘๊ทผํ•˜๋Š” ํ”„๋กœ์„ธ์Šค๊ฐ€ ์•„๋‹Œ ๊ฒฝ์šฐ Detection

๋‹ค๋งŒ, ๋ฒ”์œ„๊ฐ€ ๋„“๊ณ  White List๋กœ ๊ด€๋ฆฌํ•  ์‹œ ์˜๋„ํ•˜์ง€ ์•Š์€ ์˜์—ญ์—์„œ ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์–ด ์ถ”๊ฐ€์ ์ธ ์—ฐ๊ตฌ๊ฐ€ ํ•„์š”ํ•  ๊ฒƒ์œผ๋กœ ๋ณด์ธ๋‹ค.

Last updated