在安裝capev2 後,有幾個cont 需要設定的
kvm.conf (虛擬機對接配置)routing.conf (網路流量與隔離策略)auxiliary.conf (旁支觀測與封包側錄)processing.conf (情資萃取與分析引擎)web.conf (前端介面與效能負載)kvm.conf
根據 CAPEv2 官方設定檔內的註解與 KVM 環境配置規範,有以下幾項核心的修改要求與建議:
[kvm]
# Specify a comma-separated list of available machines to be used. For each
# specified ID you have to define a dedicated section containing the details
# on the respective machine. (E.g. cuckoo1,cuckoo2,cuckoo3)
machines = cuckoo1
這裡需要跟下面 [cape1] 名稱保持一致 建議改成 [cape1]
machines = cuckoo1 列表中,只指定了 cuckoo1 這一台虛擬機。下方出現的 [cape1] 區塊屬於未啟用的多餘設定,建議將整個 [cape1] 區塊刪除或完全註解,以免造成後續維護混淆。interface = virbr0
#To connect to local or remote host
dsn = qemu:///system
#To allow copy & paste. For details see example below
[cape1]
label = cape1
label 參數(例如 label = cuckoo1)必須與你在 KVM/virsh (virsh list --all) 中建立的虛擬機名稱完全一致。如果名稱不同,CAPE 將無法呼叫對應的虛擬機。platform = windows
ip = 192.168.122.105 預設IP 如果沒設別設定IP 可以保留
arch = x86
arch = x64 或 arch = x86,這是自動選擇合適分析環境的重要依據。#tags = winxp,acrobat_reader_6
強制加入 Windows 版本標籤 (Tags)
CAPEv2 官方明確標示,針對 Windows 虛擬機必須 (MUST) 在 tags 中指定系統版本(例如:winxp、win7、win10 或 win11)。這是因為 CAPE 的路由機制依賴標籤來派發樣本,某些樣本(如 MSIX 檔案)只能在 Windows 10 以上環境觸發。
修改建議: 取消 tags 欄位的註解並補上實際作業系統版本與安裝軟體。
#snapshot = Snapshot1
agent.py 的乾淨快照名稱(例如 snapshot = clean_state),以避免未來管理或覆寫快照時抓取到錯誤的機器狀態。#resultserver_ip = 192.168.122.101
192.168.122.105)。resultserver_ip 來自定義虛擬機看見的回傳 IP,官方強調必須同步修改全域的 cuckoo.conf,將裡面的 Result Server IP 綁定設定為 0.0.0.0,否則會產生網路衝突。#reserved = no
可取消註解
processing.conf
processing.conf 是 CAPEv2 決定分析深度的核心樞紐。它掌管了各項行為分析、網路側錄與靜態萃取模組的開關。官方強烈建議根據您的硬體資源與情報需求,進行以下關鍵模組的調整:
ini
[behavior]
enabled = yes
#Toggle specific modules within the BehaviorAnalysis class
anomaly = yes
processtree = yes
summary = yes
enhanced = yes
encryptedbuffers = yes
#Should the server use a compressed version of behavioural logs? This helps
#in saving space in Mongo, accelerates searchs and reduce the size of the
#final JSON report.
loop_detection = no
#The number of calls per process to process. 0 switches the limit off.
#10000 api calls should be processed in less than 2 minutes
analysis_call_limit = 0
[behavior] 區塊中,包含異常偵測 (anomaly)、處理程序樹 (processtree) 等模組預設為開啟。如果您發現分析過程經常超時或系統記憶體不足 20GB,官方建議將 ram_boost 保持為 no。若需進一步控制負載,可設定 analysis_call_limit(例如設為 10000)以限制單一處理程序攔截的 API 呼叫數量。
[virustotal]
enabled = yes
on_demand = no
timeout = 60
#remove empty detections
remove_empty = yes
#Add your VirusTotal API key here. The default API key, kindly provided
#by the VirusTotal team, should enable you with a sufficient throughput
#and while being shared with all our users, it shouldn't affect your use.
key = a0283a2c3d55728300d064874239b5346fb991317e8449fe43c902879d758088
do_file_lookup = yes
do_url_lookup = yes
enabled = yes),並確認 do_file_lookup = yes 與 do_url_lookup = yes 皆為開啟狀態。實務上,您必須將 key 欄位替換為您專屬的 VirusTotal API 金鑰,以避免使用預設金鑰時遭遇限流問題,確保樣本與 URL 分析的穩定度。
[CAPE_extractors]
enabled = yes
#Must ends with /
modules_path = custom/parsers/
#Config parsers all/core/community
parsers = all
routing.conf (網路流量與隔離策略)
此設定檔決定了惡意程式在沙箱內的網路通訊去向,是實作「Host-Only 隔離網路設計」(Day 10)與避免企業內網遭橫向移動感染的最關鍵防線。
[routing]
#Default network routing mode; "none", "internet", or "vpn_name".
route = none
internet = none
route 設為 none,這代表虛擬機不具備任何對外網路存取權限。若您的目標是觀察具備 C2(中繼站)連線行為的惡意程式,官方強烈警告:將其設定為 internet(髒線,Dirty Line)將允許惡意流量穿透您的網路,設定前須經過嚴密的架構權衡與安全隔離。[inetsim]
enabled = yes
server = 192.168.1.2
dnsport = 53
interface = virbr1
enabled = yes)來模擬網際網路服務。您必須在此精確指定 INetSim 伺服器的 IP(server)以及流量綁定的虛擬網卡(例如 interface = virbr1),藉此在絕對安全的前提下騙取惡意程式吐出後續的攻擊行為。auxiliary.conf (旁支觀測與封包側錄)
此檔案掌管沙箱外的觀測工具與虛擬機內的輔助模組。
[sniffer]
enabled = yes
#Specify the path to your local installation of tcpdump.
tcpdump = /usr/bin/tcpdump
#Specify the network interface name on which tcpdump should monitor the traffic.
interface = virbr1
bpf = not arp
[sniffer] 區塊為 enabled = yes,且 tcpdump 的絕對路徑正確無誤。最容易出錯的地方在於 interface,此處必須填寫與 kvm.conf 或 routing.conf 中相符的虛擬網卡名稱(如 virbr1),否則側錄將會捕捉不到任何有效流量。
[auxiliary_modules]
browser = yes
human_windows = yes
screenshots_windows = yes
tlsdump = yes
filecollector = yes
human_windows = yes 以模擬真實使用者的滑鼠與點擊行為。同時,啟用 screenshots_windows 與 tlsdump,有助於記錄勒索軟體的勒索畫面以及嘗試解譯加密的 TLS 傳輸流。web.conf (前端介面與效能負載)
除了提供分析師視覺化的操作介面,此檔案亦決定了系統的效能負載限制,更是 Day 14 實作「API 自動化串接」的底層支援核心。
[general]
#Limit number of results to show on webgui on search action
search_limit = 50
#If webgui response time is too long, you can disable existent_tasks and top_detections
existent_tasks = no
check_sample_in_mongodb = no
search_limit 限制在 50 筆內。若發現 Web GUI 回應過慢,則應遵循官方建議將 existent_tasks 與 check_sample_in_mongodb 設為 no,以大幅減輕資料庫的 I/O 負擔。[guacamole]
enabled = yes
mode = vnc
guacd_host = localhost
guacd_port = 4822
#VNC Performance Optimizations
vnc_color_depth = 16
vnc_cursor = local
[guacamole] 區塊並指定 mode = vnc。官方在效能優化上提供了明確指引:建議將色彩深度 vnc_color_depth 降至 16-bit 以取得最佳傳輸平衡,並將游標渲染設為 vnc_cursor = local,能有效消除遠端操作時的延遲感 (laggy)。[security]
#Can be multiple domains. Ex: domain.com,domain.net,domain.org
csrf_trusted_origins =
參考
https://cuckoo.readthedocs.io/en/latest/installation/host/configuration/