iT邦幫忙

2026 iThome 鐵人賽

DAY 15
0

在安裝capev2 後,有幾個cont 需要設定的

  1. kvm.conf (虛擬機對接配置)
  2. routing.conf (網路流量與隔離策略)
  3. auxiliary.conf (旁支觀測與封包側錄)
  4. processing.conf (情資萃取與分析引擎)
  5. web.conf (前端介面與效能負載)

kvm.conf
根據 CAPEv2 官方設定檔內的註解與 KVM 環境配置規範,有以下幾項核心的修改要求與建議:


[kvm]
# Specify a comma-separated list of available machines to be used. For each
# specified ID you have to define a dedicated section containing the details
# on the respective machine. (E.g. cuckoo1,cuckoo2,cuckoo3)
machines = cuckoo1 
這裡需要跟下面 [cape1] 名稱保持一致 建議改成 [cape1]
  • 清理未使用的機器設定檔
    在最上方的 machines = cuckoo1 列表中,只指定了 cuckoo1 這一台虛擬機。下方出現的 [cape1] 區塊屬於未啟用的多餘設定,建議將整個 [cape1] 區塊刪除或完全註解,以免造成後續維護混淆。
interface = virbr0
#To connect to local or remote host
dsn = qemu:///system
#To allow copy & paste. For details see example below
[cape1]
label = cape1
  • 精確對應 Libvirt 標籤 (Label)
    label 參數(例如 label = cuckoo1)必須與你在 KVM/virsh (virsh list --all) 中建立的虛擬機名稱完全一致。如果名稱不同,CAPE 將無法呼叫對應的虛擬機。
platform = windows
ip = 192.168.122.105 預設IP 如果沒設別設定IP 可以保留
arch = x86
  • 系統架構 (Arch) 屬性
    這是一項必要 (Required) 條件。必須根據虛擬機實際的位元數指定 arch = x64 或 arch = x86,這是自動選擇合適分析環境的重要依據。
#tags = winxp,acrobat_reader_6

強制加入 Windows 版本標籤 (Tags)
CAPEv2 官方明確標示,針對 Windows 虛擬機必須 (MUST) 在 tags 中指定系統版本(例如:winxp、win7、win10 或 win11)。這是因為 CAPE 的路由機制依賴標籤來派發樣本,某些樣本(如 MSIX 檔案)只能在 Windows 10 以上環境觸發。
修改建議: 取消 tags 欄位的註解並補上實際作業系統版本與安裝軟體。

#snapshot = Snapshot1
  • 指定乾淨狀態的快照 (Snapshot)
    雖然是選填(留空預設使用最新快照),但官方實務建議明確指定包含且已啟動 agent.py 的乾淨快照名稱(例如 snapshot = clean_state),以避免未來管理或覆寫快照時抓取到錯誤的機器狀態。
    快照名稱必須和設定快照名稱一致
#resultserver_ip = 192.168.122.101 
  • 確保網路與回傳伺服器 (Result Server) 相容
    虛擬機必須配發一組主機 (Host) 端能夠主動連線的固定 IP(如 192.168.122.105)。
    此外,若你啟用了虛擬網路 NAT,並選擇取消註解 resultserver_ip 來自定義虛擬機看見的回傳 IP,官方強調必須同步修改全域的 cuckoo.conf,將裡面的 Result Server IP 綁定設定為 0.0.0.0,否則會產生網路衝突。
#reserved = no

可取消註解


processing.conf

processing.conf 是 CAPEv2 決定分析深度的核心樞紐。它掌管了各項行為分析、網路側錄與靜態萃取模組的開關。官方強烈建議根據您的硬體資源與情報需求,進行以下關鍵模組的調整:

ini
[behavior]
enabled = yes
#Toggle specific modules within the BehaviorAnalysis class
anomaly = yes
processtree = yes
summary = yes
enhanced = yes
encryptedbuffers = yes
#Should the server use a compressed version of behavioural logs? This helps
#in saving space in Mongo, accelerates searchs and reduce the size of the
#final JSON report.
loop_detection = no
#The number of calls per process to process. 0 switches the limit off.
#10000 api calls should be processed in less than 2 minutes
analysis_call_limit = 0
  • 動態行為監控與效能權衡 (RAM Boost)
    在 [behavior] 區塊中,包含異常偵測 (anomaly)、處理程序樹 (processtree) 等模組預設為開啟。如果您發現分析過程經常超時或系統記憶體不足 20GB,官方建議將 ram_boost 保持為 no。若需進一步控制負載,可設定 analysis_call_limit(例如設為 10000)以限制單一處理程序攔截的 API 呼叫數量。



[virustotal]
enabled = yes
on_demand = no
timeout = 60
#remove empty detections
remove_empty = yes
#Add your VirusTotal API key here. The default API key, kindly provided
#by the VirusTotal team, should enable you with a sufficient throughput
#and while being shared with all our users, it shouldn't affect your use.
key = a0283a2c3d55728300d064874239b5346fb991317e8449fe43c902879d758088
do_file_lookup = yes
do_url_lookup = yes
  • 外部威脅情資整合 (VirusTotal)
    官方建議啟用 VirusTotal 模組 (enabled = yes),並確認 do_file_lookup = yes 與 do_url_lookup = yes 皆為開啟狀態。實務上,您必須將 key 欄位替換為您專屬的 VirusTotal API 金鑰,以避免使用預設金鑰時遭遇限流問題,確保樣本與 URL 分析的穩定度。


[CAPE_extractors]
enabled = yes
#Must ends with /
modules_path = custom/parsers/
#Config parsers all/core/community
parsers = all

routing.conf (網路流量與隔離策略)
此設定檔決定了惡意程式在沙箱內的網路通訊去向,是實作「Host-Only 隔離網路設計」(Day 10)與避免企業內網遭橫向移動感染的最關鍵防線。

[routing]
#Default network routing mode; "none", "internet", or "vpn_name".
route = none
internet = none
  • 預設網路隔離(Zero-Trust Routing)
    官方預設將 route 設為 none,這代表虛擬機不具備任何對外網路存取權限。若您的目標是觀察具備 C2(中繼站)連線行為的惡意程式,官方強烈警告:將其設定為 internet(髒線,Dirty Line)將允許惡意流量穿透您的網路,設定前須經過嚴密的架構權衡與安全隔離。
[inetsim]
enabled = yes
server = 192.168.1.2
dnsport = 53
interface = virbr1
  • 本機網路模擬(Network Simulation)
    若無法提供實體髒線,官方強烈建議啟用 INetSim(enabled = yes)來模擬網際網路服務。您必須在此精確指定 INetSim 伺服器的 IP(server)以及流量綁定的虛擬網卡(例如 interface = virbr1),藉此在絕對安全的前提下騙取惡意程式吐出後續的攻擊行為。

auxiliary.conf (旁支觀測與封包側錄)
此檔案掌管沙箱外的觀測工具與虛擬機內的輔助模組。

[sniffer]
enabled = yes
#Specify the path to your local installation of tcpdump.
tcpdump = /usr/bin/tcpdump
#Specify the network interface name on which tcpdump should monitor the traffic.
interface = virbr1
bpf = not arp
  • 全域封包側錄(PCAP Capture)
    這是一項必修設定。必須確保 [sniffer] 區塊為 enabled = yes,且 tcpdump 的絕對路徑正確無誤。最容易出錯的地方在於 interface,此處必須填寫與 kvm.conf 或 routing.conf 中相符的虛擬網卡名稱(如 virbr1),否則側錄將會捕捉不到任何有效流量。


[auxiliary_modules]
browser = yes
human_windows = yes
screenshots_windows = yes
tlsdump = yes
filecollector = yes
  • 虛擬機內行為誘發與鑑識工件收集
    為了對抗具備「反沙箱(Anti-VM)」機制的惡意程式,官方建議開啟 human_windows = yes 以模擬真實使用者的滑鼠與點擊行為。同時,啟用 screenshots_windows 與 tlsdump,有助於記錄勒索軟體的勒索畫面以及嘗試解譯加密的 TLS 傳輸流。

web.conf (前端介面與效能負載)
除了提供分析師視覺化的操作介面,此檔案亦決定了系統的效能負載限制,更是 Day 14 實作「API 自動化串接」的底層支援核心。

[general]
#Limit number of results to show on webgui on search action
search_limit = 50
#If webgui response time is too long, you can disable existent_tasks and top_detections
existent_tasks = no
check_sample_in_mongodb = no
  • 資料庫負載與查詢效能調優
    當系統運作一段時間,MongoDB 資料量暴增後,官方建議將 search_limit 限制在 50 筆內。若發現 Web GUI 回應過慢,則應遵循官方建議將 existent_tasks 與 check_sample_in_mongodb 設為 no,以大幅減輕資料庫的 I/O 負擔。
[guacamole]
enabled = yes
mode = vnc
guacd_host = localhost
guacd_port = 4822
#VNC Performance Optimizations
vnc_color_depth = 16
vnc_cursor = local
  • 互動式鑑識(Interactive Analysis)與傳輸優化
    若分析師需要在拆解過程中手動介入(例如點擊惡意巨集或輸入密碼),必須啟用 [guacamole] 區塊並指定 mode = vnc。官方在效能優化上提供了明確指引:建議將色彩深度 vnc_color_depth 降至 16-bit 以取得最佳傳輸平衡,並將游標渲染設為 vnc_cursor = local,能有效消除遠端操作時的延遲感 (laggy)。
[security]
#Can be multiple domains. Ex: domain.com,domain.net,domain.org
csrf_trusted_origins =

參考
https://cuckoo.readthedocs.io/en/latest/installation/host/configuration/


上一篇
[Day 14]安裝附錄
下一篇
[Day 16] conf 設定補充 [auxiliary]
系列文
從情資收集到資安鑑識:30 天建構自動化威脅情資與鑑識平台 共 18 篇
圖片
  熱門推薦
圖片
{{ item.channelVendor }} | {{ item.webinarstarted }} |
{{ formatDate(item.duration) }}
直播中

尚未有邦友留言

立即登入留言