[auxiliary]
第一次安裝時,在這裡遇到很多問題跟調整,有些設定會互相排斥,目前安裝新的版本是都沒遇到排斥問題,順便說明一下各項參數功能
[auxiliary_modules] 這區塊控制在分析惡意程式時,要額外啟動哪些輔助工具或日誌收集機制。
#Modules to be enabled or not inside of the VM
browser = yes * **browser**:啟用瀏覽器行為監控,追蹤惡意程式是否挾持或呼叫瀏覽器。
curtain = no * **curtain**:針對 PowerShell 的進階監控,攔截並記錄其執行的腳本與行為。
digisig = yes * **digisig**:擷取並記錄執行檔的數位簽章資訊,確認憑證真偽。
disguise = yes * **disguise**:啟用反反沙箱(Anti-Anti-VM)機制,偽裝並隱藏虛擬機特徵,避免惡意程式發現被分析而停止執行。
windows_static_route / windows_static_route_gateway:搭配 KVM dnsmasq 使用,強制將
Windows 虛擬機的網路流量導向指定的靜態閘道器(如 192.168.1.1)。
#This is only useful in case you use KVM's dnsmasq. You need to set
windows_static_route_gateway. Disguise must be enabled
windows_static_route = no
windows_static_route_gateway = 192.168.1.1
evtx = no * **evtx**:在分析結束後收集 Windows 事件檢視器(Event Logs)的 `.evtx` 日誌檔。
human_windows / human_linux:模擬真實人類操作(如隨機移動滑鼠、點擊、滾動視窗),用以欺騙需要人類互動才會觸發攻擊的惡意程式。
human_windows = yes *
human_linux = no
procmon = no * **procmon**:執行 Sysinternals Process Monitor,收集深度的檔案、登錄檔與程序活動紀錄。
recentfiles = no * **recentfiles**:收集分析期間作業系統中產生的「最近開啟檔案(Recent Files)」捷徑紀錄。
screenshots_windows / screenshots_linux / screenshots_qr:在分析過程中定時擷取作業系統畫面,並可選擇是否啟用 QR Code 辨識。
screenshots_windows = yes
screenshots_linux = yes
screenshots_qr = no
sysmon_windows / sysmon_linux:整合 Microsoft Sysmon 工具,產出高價值的端點安全遙測日誌。
sysmon_windows = no
sysmon_linux = no
tlsdump = yes
**tlsdump**:擷取 TLS 流量與密鑰,協助後續還原或解密加密的網路連線。
usage = no
**usage**:記錄分析期間的系統資源(CPU、記憶體)使用率。
file_pickup = no
**file_pickup / filecollector**:自動收集與備份惡意程式在執行期間釋放(Drop)、下載或修改的檔案。
permissions = no
**permissions**:監控並記錄系統檔案或登錄檔的權限變更行為。
pre_script / during_script:允許在分析開始前或分析進行中,於虛擬機內執行自訂的自動化腳本。
pre_script = no
during_script = no
filecollector = yes
tracee_linux:在 Linux 環境中整合 Tracee,透過 eBPF 技術收集核心層級的安全事件。
tracee_linux = no
sslkeylogfile:強制記錄系統的 SSL/TLS 對稱式金鑰日誌(SSLKEYLOGFILE),讓 Wireshark 或 NDR 平台可以解密 pcap 封包。
sslkeylogfile = no
browsermonitor:透過特製的瀏覽器擴充功能,深度監控網頁載入與 JavaScript 執行狀況。
#Requires setting up browser extension, check extra/browser_extension
browsermonitor = no
wmi_etw / dns_etw / amsi_etw / network_etw:利用 Windows 事件追蹤(ETW)機制,從系統底層擷取 WMI 查詢、DNS 請求、AMSI(反惡意軟體掃描介面)攔截紀錄與底層網路事件。
#ETW logging modules require pywintrace to be installed on the guest VM
wmi_etw = no
dns_etw = no
amsi_etw = no
network_etw = no
watchdownloads:專門監控並攔截透過瀏覽器或系統元件下載的外部檔案。
watchdownloads = no
[AzSniffer]
#Enable or disable the use of Azure Network Watcher packet capture feature, disable standard sniffer if this is in use to not create concurrent .pcap files
enabled = no
[sniffer]
# Enable or disable the use of an external sniffer (tcpdump) [yes/no].
enabled = yes
# enable remote tcpdump support
remote = no
host = root@192.168.122.1
# Specify the path to your local installation of tcpdump. Make sure this
# path is correct.
tcpdump = /usr/bin/tcpdump
# Specify the network interface name on which tcpdump should monitor the
# traffic. Make sure the interface is active.
interface = virbr1
# Specify a Berkeley packet filter to pass to tcpdump.
bpf = not arp
[gateways]
#RTR1 = 192.168.1.254
#RTR2 = 192.168.1.1
#INETSIM = 192.168.1.2
[QemuScreenshots]
# Enable or disable the use of QEMU as screenshot capture [yes/no].
# screenshots_linux and screenshots_windows must be disabled
enabled = no
[Mitmdump]
# Enable or disable the use of mitmdump (mitmproxy) to get dump.har [yes/no].
# This module requires mitmproxy to be installed see install_mitmproxy
# (https://github.com/kevoreilly/CAPEv2/blob/master/installer/cape2.sh#L1320)
enabled = no
[PolarProxy]
# Enable or disable the use of PolarProxy to get dump.pcap with decrypted TLS streams [yes/no].
# This module requires PolarProxy to be installed see install_polarproxy.
# Use add the options "polarproxy=1" when submitting a sample.
enabled = no
enabled:若沙箱建置於 Azure 雲端環境,此選項可啟用 Azure Network Watcher 進行無代理程式的封包側錄。開啟時需關閉標準 sniffer 以免衝突。
**enabled**:啟用外部封包側錄工具(通常為 tcpdump)以產生惡意程式連線的 pcap 檔。
**remote / host**:是否透過 SSH 在遠端主機(如 `root@192.168.122.1`)執行側錄。
**tcpdump**:指定 tcpdump 執行檔在伺服器上的絕對路徑。
**interface**:指定要側錄流量的虛擬網路介面卡名稱(例如 KVM 的 `virbr1` 橋接介面)。
**bpf**:設定 Berkeley Packet Filter(BPF)過濾規則。例如 `not arp` 代表在側錄時忽略無關緊要的 ARP 廣播封包,減少 pcap 檔案體積。
192.168.1.1 或偽裝網路服務 INetSim 的 IP 192.168.1.2),方便在送測不同樣本時切換網路路由策略。screenshots_linux 與 screenshots_windows 關閉。.har 格式供詳細分析。