{"id":1442,"date":"2021-06-23T08:43:17","date_gmt":"2021-06-23T08:43:17","guid":{"rendered":"https:\/\/cas.cybercop-training.ch\/?page_id=1442"},"modified":"2021-06-23T09:36:59","modified_gmt":"2021-06-23T09:36:59","slug":"velociraptor-introduction","status":"publish","type":"page","link":"https:\/\/cas.cybercop-training.ch\/index.php\/velociraptor-introduction\/","title":{"rendered":"Velociraptor Introduction"},"content":{"rendered":"<h2>1. Introduction<\/h2>\n<blockquote><p>In this challenge, the goal is to familiarize yourself with Velociraptor. For this purpose, there are several tasks introducing you to the various parts of Velociraptor. You will have to use the Notebook, create an Artifact, Labels, the Virtual Filesystem, and Hunts. Students will also get their first look at YARA rules.<\/p><\/blockquote>\n<h2>2. Task 1 (Sysinternals check)<\/h2>\n<p>After Velociraptor is started, I&#8217;ll put a label on all the clients where the velocirpator agent is running.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/06\/tagging01.png\" alt=\"\" \/><br \/>\n<img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/06\/tagging03.png\" alt=\"\" \/><\/p>\n<h3>2.1 Registry Search<\/h3>\n<p>Now that you have the Velociraptor deployment running, let&#8217;s collect some Artifacts. As you may know, Sysinternals tools create a registry key when they&#8217;re first run. On Forensic.winattacklab.local and using Velociraptor, find out which Sysinternals tools have been run by users on the system.<\/p>\n<p>To demonstrate the abilities of Velociraptor, do this in three different ways:<\/p>\n<ul>\n<li>Manually look through the registry<\/li>\n<li>Design your own VQL query and use the Notebook<\/li>\n<li>Run a hunt on only Forensic to get the information<\/li>\n<\/ul>\n<h3>Manually look through the registry<\/h3>\n<p>Note: Sysinternals tools create a new registry key in the <code>HKCU\\SOFTWARE\\Sysinternals<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/06\/veloc01.png\" alt=\"\" \/><\/p>\n<p>Find the username:<\/p>\n<p>Username is in the ntuser.dat file. We have two different ways to find the username behind a User SID.<\/p>\n<ol>\n<li>Registry via hive list:<\/li>\n<\/ol>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">\"\\HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\hivelist\\\"\\REGISTRY\\USER\\S-1-5-21-1934685094-3055893784-3435983073-1004\"<\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/06\/reg01.png\" alt=\"\" \/><br \/>\n<img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/06\/reg02.png\" alt=\"\" \/><\/p>\n<ol start=\"2\">\n<li>Volatile environment:<\/li>\n<\/ol>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">\"\\HKEY_USERS\\S-1-5-21-1934685094-3055893784-3435983073-1004\\Volatile Environment\\USERNAME\"<\/pre>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/06\/reg03.png\" alt=\"\" \/><br \/>\n<img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/06\/reg04.png\" alt=\"\" \/><\/p>\n<h3>Using the notebook to create a manual VQL Query<\/h3>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/06\/notebook01.png\" alt=\"\" \/><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">LET users &lt;= SELECT Name, UUID\r\nFROM Artifact.Windows.Sys.Users()\r\nSELECT\r\nName,\r\nFullPath,\r\n{\r\nSELECT Name FROM users WHERE UUID=regex_replace(\r\nsource=FullPath, re=\".+\\\\\\\\(S-[^\\\\\\\\]+)\\\\\\\\.+\", replace=\"$1\")\r\n} as User\r\nFROM\r\nglob(globs=\"HKEY_USERS\/*\/Software\/Sysinternals\/*\", accessor=\"reg\")\r\nLIMIT 10<\/pre>\n<p>Result:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/06\/notebook02.png\" alt=\"\" \/><\/p>\n<h3>Run a hunt<\/h3>\n<p>It&#8217;s much easier to use an existing artifacte like <code>Sysinternals.eulacheck<\/code> !<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/06\/veloc02.png\" alt=\"\" \/><\/p>\n<p>Note: User is <code>annanass<\/code><\/p>\n<h2>3. Task 2 (Yara Hunt)<\/h2>\n<blockquote><p>You know that a malicious binary is running on Forensic. All that is known about the process is that it contains the string IAmUndetectable. From that, the following YARA rule can be created:<\/p><\/blockquote>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">rule DetectMalware {\r\n    strings: $search_string = \"IAmUndetectable\"\r\n    condition: $search_string\r\n}<\/pre>\n<p>I&#8217;ll check the library of existing artifacts first:<\/p>\n<p><code>Windows Detection.ProcessMemory<\/code> catched my attention. Let&#8217;s have a closer look on this:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/06\/yara01.png\" alt=\"\" \/><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/06\/yara02.png\" alt=\"\" \/><\/p>\n<p>Try the hunt:<\/p>\n<p>Select Forensic Client:<br \/>\n<img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/06\/yara03.png\" alt=\"\" \/><\/p>\n<p>Select Rule:<br \/>\n<img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/06\/yara04.png\" alt=\"\" \/><\/p>\n<p>Set Options:<br \/>\n<img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/06\/yara05.png\" alt=\"\" \/><\/p>\n<p>Run it:<\/p>\n<p>After starting the hunt I can see several errors in the LOG:<br \/>\n(could not attach to process)<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/06\/yara06.png\" alt=\"\" \/><\/p>\n<p>I did not stop the hunt and later I could see some results from several process dump files:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/06\/yara07.png\" alt=\"\" \/><\/p>\n<p>sprlgtprc.exe executed from <code>C:\\Windows\\Temp<\/code> looks suspiscious to me!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. Introduction In this challenge, the goal is to familiarize yourself with Velociraptor. For this purpose, there are several tasks introducing you to the various parts of Velociraptor. You will have to use the Notebook, create an Artifact, Labels, the Virtual Filesystem, and Hunts. Students will also get their first look at YARA rules. 2. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-1442","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/1442","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/comments?post=1442"}],"version-history":[{"count":4,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/1442\/revisions"}],"predecessor-version":[{"id":1485,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/1442\/revisions\/1485"}],"wp:attachment":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/media?parent=1442"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}