iT邦幫忙

2026 iThome 鐵人賽

DAY 16
0

[auxiliary]
第一次安裝時,在這裡遇到很多問題跟調整,有些設定會互相排斥,目前安裝新的版本是都沒遇到排斥問題,順便說明一下各項參數功能

[auxiliary_modules] 這區塊控制在分析惡意程式時,要額外啟動哪些輔助工具或日誌收集機制。

#Modules to be enabled or not inside of the VM
browser = yes  * **browser**:啟用瀏覽器行為監控,追蹤惡意程式是否挾持或呼叫瀏覽器。
curtain = no * **curtain**:針對 PowerShell 的進階監控,攔截並記錄其執行的腳本與行為。
digisig = yes * **digisig**:擷取並記錄執行檔的數位簽章資訊,確認憑證真偽。
disguise = yes * **disguise**:啟用反反沙箱(Anti-Anti-VM)機制,偽裝並隱藏虛擬機特徵,避免惡意程式發現被分析而停止執行。

windows_static_route / windows_static_route_gateway:搭配 KVM dnsmasq 使用,強制將
Windows 虛擬機的網路流量導向指定的靜態閘道器(如 192.168.1.1)。

#This is only useful in case you use KVM's dnsmasq. You need to set
windows_static_route_gateway. Disguise must be enabled
windows_static_route = no
windows_static_route_gateway = 192.168.1.1
evtx = no  * **evtx**:在分析結束後收集 Windows 事件檢視器(Event Logs)的 `.evtx` 日誌檔。

human_windows / human_linux:模擬真實人類操作(如隨機移動滑鼠、點擊、滾動視窗),用以欺騙需要人類互動才會觸發攻擊的惡意程式。

human_windows = yes  * 
human_linux = no
procmon = no * **procmon**:執行 Sysinternals Process Monitor,收集深度的檔案、登錄檔與程序活動紀錄。
recentfiles = no  * **recentfiles**:收集分析期間作業系統中產生的「最近開啟檔案(Recent Files)」捷徑紀錄。

screenshots_windows / screenshots_linux / screenshots_qr:在分析過程中定時擷取作業系統畫面,並可選擇是否啟用 QR Code 辨識。

screenshots_windows = yes
screenshots_linux = yes
screenshots_qr = no 

sysmon_windows / sysmon_linux:整合 Microsoft Sysmon 工具,產出高價值的端點安全遙測日誌。

sysmon_windows = no
sysmon_linux = no
tlsdump = yes
**tlsdump**:擷取 TLS 流量與密鑰,協助後續還原或解密加密的網路連線。
usage = no
**usage**:記錄分析期間的系統資源(CPU、記憶體)使用率。
file_pickup = no
**file_pickup / filecollector**:自動收集與備份惡意程式在執行期間釋放(Drop)、下載或修改的檔案。
permissions = no
**permissions**:監控並記錄系統檔案或登錄檔的權限變更行為。

pre_script / during_script:允許在分析開始前或分析進行中,於虛擬機內執行自訂的自動化腳本。

pre_script = no
during_script = no
filecollector = yes

tracee_linux:在 Linux 環境中整合 Tracee,透過 eBPF 技術收集核心層級的安全事件。

tracee_linux = no

sslkeylogfile:強制記錄系統的 SSL/TLS 對稱式金鑰日誌(SSLKEYLOGFILE),讓 Wireshark 或 NDR 平台可以解密 pcap 封包。

sslkeylogfile = no

browsermonitor:透過特製的瀏覽器擴充功能,深度監控網頁載入與 JavaScript 執行狀況。

#Requires setting up browser extension, check extra/browser_extension
browsermonitor = no

wmi_etw / dns_etw / amsi_etw / network_etw:利用 Windows 事件追蹤(ETW)機制,從系統底層擷取 WMI 查詢、DNS 請求、AMSI(反惡意軟體掃描介面)攔截紀錄與底層網路事件。

#ETW logging modules require pywintrace to be installed on the guest VM
wmi_etw = no
dns_etw = no
amsi_etw = no
network_etw = no

watchdownloads:專門監控並攔截透過瀏覽器或系統元件下載的外部檔案。

watchdownloads = no
[AzSniffer]
#Enable or disable the use of Azure Network Watcher packet capture feature, disable standard sniffer if this is in use to not create concurrent .pcap files
enabled = no

[sniffer]
# Enable or disable the use of an external sniffer (tcpdump) [yes/no].
enabled = yes

# enable remote tcpdump support
remote = no
host = root@192.168.122.1

# Specify the path to your local installation of tcpdump. Make sure this
# path is correct.
tcpdump = /usr/bin/tcpdump

# Specify the network interface name on which tcpdump should monitor the
# traffic. Make sure the interface is active.
interface = virbr1

# Specify a Berkeley packet filter to pass to tcpdump.
bpf = not arp

[gateways]
#RTR1 = 192.168.1.254
#RTR2 = 192.168.1.1
#INETSIM = 192.168.1.2

[QemuScreenshots]
# Enable or disable the use of QEMU as screenshot capture [yes/no].
# screenshots_linux and screenshots_windows must be disabled
enabled = no

[Mitmdump]
# Enable or disable the use of mitmdump (mitmproxy) to get dump.har [yes/no].
# This module requires mitmproxy to be installed see install_mitmproxy
# (https://github.com/kevoreilly/CAPEv2/blob/master/installer/cape2.sh#L1320)
enabled = no

[PolarProxy]
# Enable or disable the use of PolarProxy to get dump.pcap with decrypted TLS streams [yes/no].
# This module requires PolarProxy to be installed see install_polarproxy.
# Use add the options "polarproxy=1" when submitting a sample.
enabled = no

[AzSniffer] (Azure 網路封包擷取)

enabled:若沙箱建置於 Azure 雲端環境,此選項可啟用 Azure Network Watcher 進行無代理程式的封包側錄。開啟時需關閉標準 sniffer 以免衝突。

[sniffer] (本機端網路封包側錄)

**enabled**:啟用外部封包側錄工具(通常為 tcpdump)以產生惡意程式連線的 pcap 檔。
**remote / host**:是否透過 SSH 在遠端主機(如 `root@192.168.122.1`)執行側錄。
**tcpdump**:指定 tcpdump 執行檔在伺服器上的絕對路徑。
**interface**:指定要側錄流量的虛擬網路介面卡名稱(例如 KVM 的 `virbr1` 橋接介面)。
**bpf**:設定 Berkeley Packet Filter(BPF)過濾規則。例如 `not arp` 代表在側錄時忽略無關緊要的 ARP 廣播封包,減少 pcap 檔案體積。

[gateways] (網路閘道器定義)

  • 預留區塊,用於定義虛擬機可用的網路閘道器列表(如真實路由器 IP 192.168.1.1 或偽裝網路服務 INetSim 的 IP 192.168.1.2),方便在送測不同樣本時切換網路路由策略。

[QemuScreenshots] (Hypervisor 層級截圖)

  • enabled:直接從 QEMU 虛擬化底層擷取螢幕畫面,而非依賴虛擬機內的 Agent。此模式更隱蔽,但若啟用,必須將前述的 screenshots_linux 與 screenshots_windows 關閉。

[Mitmdump] (中間人流量攔截)

  • enabled:結合 mitmproxy 工具進行中間人(MITM)攻擊,攔截並解密惡意程式的 HTTP/HTTPS 流量,最終匯出為 .har 格式供詳細分析。

[PolarProxy] (TLS 流量透明代理)

  • enabled:啟用 PolarProxy 透明代理伺服器。與 Mitmdump 類似,但它專注於將攔截解密後的 TLS 明文流量直接輸出為標準的 pcap 封包檔,極大化網路鑑識(如 Malcolm NDR)的分析效益。

上一篇
[Day 15] conf 相關設定
下一篇
[Day 16] conf 設定補充 [auxiliary] part2
系列文
從情資收集到資安鑑識:30 天建構自動化威脅情資與鑑識平台 共 18 篇
圖片
  熱門推薦
圖片
{{ item.channelVendor }} | {{ item.webinarstarted }} |
{{ formatDate(item.duration) }}
直播中

尚未有邦友留言

立即登入留言