iT邦幫忙

2026 iThome 鐵人賽

DAY 17
0

以下是該 processing.conf 設定檔中各項處理模組(Processing Modules)的詳細功能說明。這些模組負責在沙盒動態執行完畢後,解析並結構化收集到的原始數據。

核心與動態行為分析 (Core & Behavioral Analysis)

  • [analysisinfo]:收集該次分析的基本元數據(如分析 ID、時間戳記、目標檔案路徑等)。
  • [behavior]:核心行為解析模組。處理沙盒中記錄的 API 呼叫日誌,包含異常檢測 (anomaly)、行程樹關聯 (processtree) 以及行為摘要 (summary)。支援記憶體加速 (ram_boost) 與迴圈偵測 (loop_detection) 以優化大型日誌處理效能。
  • [CAPE]:CAPEv2 核心模組。負責處理動態解包後的 Payload、投放檔案 (dropped) 以及行程記憶體傾印 (procdump),並支援正則表達式特徵替換與 PE 檔快取。
  • [amsi_etw]:攔截並記錄 Windows 反惡意軟體掃描介面 (AMSI) 與事件追蹤 (ETW) 的日誌,可獲取 PowerShell 或 VBScript 在記憶體中執行時的明文指令。
  • [procmemory]:分析從虛擬機中傾印出來的惡意行程記憶體(如提取可讀字串或進行 YARA 掃描)。
  • [memory]:全機記憶體分析模組。通常結合 Volatility 框架,對虛擬機的完整記憶體映像檔進行深度鑑識。
  • [procmon]:解析 Sysinternals Process Monitor (Procmon) 所產生的系統活動日誌。
  • [tracee] / [strace]:Linux 行為追蹤模組。分別透過 Aqua Tracee 與 strace 工具收集 Linux 環境下的系統呼叫 (System Calls) 與核心事件。
  • [script_log_processing]:專門處理腳本(如 PowerShell、VBS)執行期間所產生的原生行為日誌。
  • [usage]:監控並記錄分析期間虛擬機的系統資源消耗(CPU 與記憶體)。
  • [debug]:擷取並記錄分析過程中的錯誤日誌或標準輸出,協助排解沙盒執行失敗的問題。
  • [detections]:綜合威脅判定模組。統整來自行為分析、YARA、Suricata、VirusTotal 等引擎的命中結果,產出最終警報。
  • [deduplication]:使用感知雜湊(如 ahash)比對分析過程中的螢幕截圖,自動刪除畫面重複的圖片以節省儲存空間。

網路與流量解析 (Network & Traffic)

  • [network]:網路流量分析核心。解析 PCAP 封包,支援 DNS/IP 白名單過濾 (dnswhitelist)、處理程序網路映射 (process_map),以及結合 MaxMind/IPInfo 進行 GeoIP 國家地理位置查詢。
  • [suricata]:入侵偵測模組。利用 Suricata 引擎與網路特徵碼掃描 PCAP 封包,產出警報 (eve.json) 並支援直接從流量中提取傳輸檔案。
  • [decryptpcap]:網路封包解密模組。利用 GoGoRoboCap 工具或金鑰日誌,自動解密捕捉到的 HTTPS/TLS 加密流量。
  • [dumptls]:用於提取 TLS Master Secrets 或解密後的網路流量資料。
  • [ja3]:TLS 指紋模組。透過分析 TLS 握手特徵建立用戶端 JA3/JA3S 指紋,用於識別特定的惡意軟體家族網路行為。
  • [polarproxy]:當沙盒使用 PolarProxy 攔截流量時,此模組負責將解密後的 TLS 明文封包合併回主要 PCAP 檔案中。
  • [network_etw]:透過 Windows ETW (Event Tracing for Windows) 捕捉網路連線日誌,作為傳統 PCAP 的輔助。
  • [pcapng]:啟用對 PCAPNG 新世代網路封包格式的解析支援。
  • [url_analysis]:針對以 URL 為目標的分析任務,自動對該網域執行 WHOIS 註冊資訊查詢。

靜態分析與設定提取 (Static & Config Extraction)

  • [CAPE_extractors]:CAPEv2 官方的惡意軟體設定提取器。透過 Python 解析器直接從樣本中提取 C2 伺服器、加密金鑰等資訊(支援 Lumma, Stealc 等家族)。
  • [mwcp] / [ratdecoders] / [malduck]:第三方惡意軟體設定解析框架整合。專門提取各類遠端控制木馬 (RAT) 與惡意軟體家族的內部設定檔。
  • [magika]:整合 Google Magika 深度學習模型,進行高精度的檔案類型識別,特別適合判定 PowerShell 或 INI 等容易混淆的純文字格式。
  • [trid] / [die]:靜態特徵識別模組。透過 TrID 特徵碼庫與 Detect It Easy (DiE) 偵測未知的檔案類型、編譯器特徵以及是否被加殼混淆。
  • [strings]:從樣本檔案中靜態提取可讀字串,可自訂最小字元長度 (minchars)。
  • [decompression]:自動處理並解開壓縮檔(如 ZIP、RAR),以便沙盒進一步分析內部的真實惡意檔案。
  • [vba2graph]:將 Office 文件中的惡意 VBA 巨集邏輯,透過 Graphviz 轉換為視覺化的執行流程圖。
  • [xlsdeobf]:專門針對舊版 Excel 4.0 (XLM) 巨集病毒進行語法還原與解混淆。
  • [html_scraper]:從 HTML 樣本檔案中爬取並提取潛在的惡意連結或釣魚網站特徵。

外部整合與進階處理 (Integration & Advanced Processing)

  • [virustotal]:整合 VirusTotal API。將檔案雜湊值或 URL 提交查詢,獲取全球防毒引擎的掃描結果,支援快取機制以節省 API 請求額度。
  • [threatintelligence] / [cif]:威脅情資模組。將分析中發現的 IOCs(IP、網域、雜湊)與外部威脅情資平台(如 CIF)進行交叉比對與資料豐富化。
  • [maliciousmacrobot]:整合 MMBot (MaliciousMacroBot)。利用預先訓練好的機器學習模型,判定 Office 文件中的巨集是否具有惡意特徵。
  • [boxjs]:將 JavaScript 樣本傳送至外部 Box.js 服務器進行沙盒模擬執行,以分析其動態行為與解混淆結果。
  • [similarity]:程式碼相似度引擎。將樣本特徵與現有資料庫比對,判斷其是否隸屬於已知的惡意軟體家族。
  • [reversinglabs]:整合 ReversingLabs TitaniumCore API,提供深度的靜態分析數據與檔案信譽評比。
  • [antiransomware]:防勒索軟體輔助模組。設定排除安全副檔名,並限制相同副檔名檔案的處理數量上限 (skip_number),防止勒索軟體加密大量檔案導致沙盒資源耗盡。
  • [curtain]:社群貢獻的模組,主要針對 PowerShell 執行策略與進階事件日誌進行深度分析。
# Enable or disable the available processing modules [on/off].
# If you add a custom processing module to your Cuckoo setup, you have to add
# a dedicated entry in this file, or it won't be executed.
# You can also add additional options under the section of your module and
# they will be available in your Python class.

# Community
# exclude files that doesn't match safe extension and ignore their files from processing inside of other modules like CAPE.py
[antiransomware]
enabled = no
# ignore all files with extension found more than X
skip_number = 30

# Community
[curtain]
enabled = no

# Community
[sysmon]
enabled = no

[analysisinfo]
enabled = yes

# Community
[decompression]
enabled = no

[dumptls]
enabled = no

[amsi_etw]
enabled = no

[behavior]
enabled = yes
# Toggle specific modules within the BehaviorAnalysis class
anomaly = yes
processtree = yes
summary = yes
enhanced = yes
encryptedbuffers = yes
# Should the server use a compressed version of behavioural logs? This helps
# in saving space in Mongo, accelerates searchs and reduce the size of the
# final JSON report.
loop_detection = no
# The number of calls per process to process. 0 switches the limit off.
# 10000 api calls should be processed in less than 2 minutes
analysis_call_limit = 0
# Use ram to boost processing speed. You will need more than 20GB of RAM for this feature.
# Please read "performance" section in the documentation.
ram_boost = no
# https://capev2.readthedocs.io/en/latest/usage/patterns_replacement.html
replace_patterns = no
file_activities = no
# Get network details from behavior
network_map = no

# process behavior files in ram to speedup processing a little bit?
ram_mmap = no

[tracee]
enabled = no

[strace]
enabled = no
# Toggle specific modules within the StraceAnalysis class
processtree = no
# Platform specific
platform = linux
update_file_descriptors = yes

[debug]
enabled = yes
# Amount of text (bytes)
buffer = 0

[detections]
enabled = yes
# Signatures
behavior = yes
yara = yes
suricata = yes
virustotal = no
clamav = no

# ... but this mechanism may still be switched on
[procmemory]
enabled = yes
strings = yes

[procmon]
enabled = no

[memory]
enabled = no

[usage]
enabled = no

[network]
enabled = yes
sort_pcap = no
# Which capture to analyze when decryptpcap produced additional outputs:
# auto | original | mixed | decrypted
pcapsrc = auto
# Enable mapping of network events to specific processes using behavioral analysis data
process_map = no
# Adds network connections seen in behavior but not in PCAP. Requires process_map = yes
merge_behavior_map = no
# DNS whitelisting to ignore domains/IPs configured in network.py
dnswhitelist = yes
# additional entries
dnswhitelist_file = extra/whitelist_domains.txt
ipwhitelist = yes
ipwhitelist_file = extra/whitelist_ips.txt
network_passlist = no
network_passlist_file = extra/whitelist_network.txt

# Requires geoip2 and maxmind database
country_lookup = no
# Register and download for free from
# https://www.maxmind.com/ or https://ipinfo.io/
# For maxmind use: GeoLite2 Country
# For ipinfo use: Free IP to Country + IP to ASN
maxmind_database = data/GeoLite2-Country.mmdb

[decryptpcap]
enabled = no
# Path to GoGoRoboCap binary (relative to CUCKOO_ROOT or absolute)
gogorobocap = data/gogorobocap/gogorobocap-linux-amd64
# Decryption source: auto (default), pcap_with_keylog, or sslproxy_synth_pcap
# auto: uses sslproxy synthetic pcap when available, falls back to keylog decryption
pcapsrc = auto

[pcapng]
enabled = no

[url_analysis]
enabled = yes
# Enable a WHOIS lookup for the target domain of a URL analyses
whois = yes

[strings]
enabled = yes
on_demand = no
nullterminated_only = no
minchars = 5

# Community
[trid]
# Specify the path to the trid binary to use for static analysis.
enabled = no
identifier = data/trid/trid
definitions = data/trid/triddefs.trd

[die]
# Detect it Easy
enabled = no
binary = /usr/bin/diec

[magika]
# Google Magika - deep-learning content type identification.
# https://github.com/google/magika
# Install: poetry run pip install -U magika
# Main benfit is classification of text file types i.e. PowerShell, ini files etc.
enabled = no
# Optional path to a custom/pinned model directory. Empty = use the model
# shipped with the installed magika package.
model_dir =
# high_confidence (default, most conservative) | medium_confidence | best_guess
prediction_mode = high_confidence
# Display-only: results scoring below this are still recorded and shown, just
# flagged low_confidence so a weak prediction isn't read as a confident one.
min_score = 0.5
# Skip files larger than this (MB). 0 = no limit. Magika only reads the head,
# middle and tail of a file, so this is cheap to raise.
max_file_size = 100

[virustotal]
enabled = yes
on_demand = no
timeout = 60
# remove empty detections
remove_empty = yes
# Add your VirusTotal API key here. The default API key, kindly provided
# by the VirusTotal team, should enable you with a sufficient throughput
# and while being shared with all our users, it shouldn't affect your use.
key = a0283a2c3d55728300d064874239b5346fb991317e8449fe43c902879d758088
do_file_lookup = yes
do_url_lookup = yes
# Use cached results from MongoDB if available
cache_default = no
cache_static = no
cache_file = no
cache_dropped = no
cache_cape = no
cache_procdump = no
urlscrub = (^http:\/\/serw\.clicksor\.com\/redir\.php\?url=|&InjectedParam=.+$)

# Since Suricata 8, socket mode is deprecated.
[suricata]
enabled = no
runmode = cli
# Which capture to analyze when decryptpcap produced additional outputs:
# auto | original | mixed | decrypted
pcapsrc = auto
# Outputfiles
# if evelog is specified, it will be used instead of the per-protocol log files
evelog = eve.json

# per-protocol log files
#
#alertlog = alert.json
#httplog = http.json
#tlslog = tls.json
#sshlog = ssh.json
#dnslog = dns.json

fileslog = files-json.log
filesdir = files
# Amount of text to carve from plaintext files (bytes)
buffer = 8192
 #Used for creating an archive of extracted files
7zbin = data/7zz
zippass = infected
# Runmode "cli" options
bin = /usr/bin/suricata
conf = /etc/suricata/suricata.yaml

# Runmode "socket" Options. Deprecated since Suricata 8.
socket_file = /tmp/suricata-command.socket

# Community
[cif]
enabled = no
# url of CIF server
url = https://your-cif-server.com/api
# CIF API key
key = your-api-key-here
# time to wait for server to respond, in seconds
timeout = 60
# minimum confidence level of returned results:
# 25=not confident, 50=automated, 75=somewhat confident, 85=very confident, 95=certain
# defaults to 85
confidence = 85
# don't log queries by default, set to 'no' to log queries
nolog = yes
# max number of results per query
per_lookup_limit = 20
# max number of queries per analysis
per_analysis_limit = 200

[CAPE]
enabled = yes
# Ex targetinfo standalone module
targetinfo = yes
# Ex dropped standalone module
dropped = yes
# Ex procdump standalone module
procdump = yes
# Amount of text to carve from plaintext files (bytes)
buffer = 8192
# Process files not bigger than value below in Mb. We saw that after 90Mb it has biggest delay
max_file_size = 90
# Scan for UserDB.TXT signature matches
userdb_signature = no
# https://capev2.readthedocs.io/en/latest/usage/patterns_replacement.html
replace_patterns = no
# Use file cache to speed up processing by looking up already processed files in MongoDB
file_cache = no
# Store pefile objects for later usage? useful if you doing something in signatures/reporting
pefile_store = no

[network_etw]
enabled = no

# Deduplicate screenshots - You need to install dependency ImageHash>=4.3.1
[deduplication]
#
# Available hashs functions:
#  ahash:      Average hash
#  phash:      Perceptual hash
#  dhash:      Difference hash
#  whash-haar: Haar wavelet hash
#  whash-db4:  Daubechies wavelet hash
enabled = no
hashmethod = ahash

# Community
[vba2graph]
# Mac - brew install graphviz
# Ubuntu - sudo apt-get install graphviz
# Arch - sudo pacman -S graphviz+
# sudo poetry run pip install networkx>=2.1 graphviz>=0.8.4 pydot>=1.2.4
enabled = yes
on_demand = yes

# ja3 finger print db with descriptions
# https://github.com/trisulnsm/trisul-scripts/blob/master/lua/frontend_scripts/reassembly/ja3/prints/ja3fingerprint.json
[ja3]
ja3_path = data/ja3/ja3fingerprint.json

[maliciousmacrobot]
# https://maliciousmacrobot.readthedocs.io
# Install mmbot
#   sudo poetry run pip install mmbot
# Create/Set required paths
# Populate benign_path and malicious_path with appropriate macro maldocs (try the tests/samples in the github)
#   https://github.com/egaus/MaliciousMacroBot/tree/master/tests/samples
# Create modeldata.pickle with your maldocs (this does not append to the model, it overwrites it)
#
#   mmb = MaliciousMacroBot(benign_path, malicious_path, model_path, retain_sample_contents=False)
#   result = mmb.mmb_init_model(modelRebuild=True)
#
# Copy your model file and vocab.txt to your model_path
enabled = no
benign_path = /opt/cuckoo/data/mmbot/benign
malicious_path = /opt/cuckoo/data/mmbot/malicious
model_path = /opt/cuckoo/data/mmbot/model

# Community
[xlsdeobf]
# poetry run pip install git+https://github.com/DissectMalware/XLMMacroDeobfuscator.git
enabled = no
on_demand = no

# Community
[boxjs]
enabled = no
timeout = 60
url = http://your_super_box_js:9000

# Community
# Extractors
[mwcp]
enabled = yes
modules_path = modules/processing/parsers/mwcp/

# Community
[ratdecoders]
enabled = yes
modules_path = modules/processing/parsers/RATDecoders/

# Community
[malduck]
enabled = yes
modules_path = modules/processing/parsers/malduck/

# installed from PYPI
[CAPE_extractors]
enabled = yes
# Must ends with /
modules_path = custom/parsers/
# Config parsers all/core/community
parsers = all
# list of comma separated parsers. Ex: stealc,lumma
exclude=

# Community
[reversinglabs]
enabled = no
url =
key =

# Community
[script_log_processing]
enabled = yes

[html_scraper]
enabled = no

# Community
[polarproxy]
# Enable when using the PolarProxy option during analysis. This will merge the tls.pcap containing
# plain-text TLS streams into the task PCAP.
enabled = no

# Code-similarity engine(s). See conf/integrations.conf [similarity].
[similarity]
enabled = no

# Threat-intelligence enrichment. Engine and API settings live in
# conf/threat_intel.conf.
[threatintelligence]
enabled = no

上一篇
[Day 16] conf 設定補充 [auxiliary] part2
下一篇
[Day 17] conf 設定補充 [processing.conf] part2
系列文
從情資收集到資安鑑識:30 天建構自動化威脅情資與鑑識平台 共 23 篇
圖片
  熱門推薦
圖片
{{ item.channelVendor }} | {{ item.webinarstarted }} |
{{ formatDate(item.duration) }}
直播中

尚未有邦友留言

立即登入留言