Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
SOC335---CVE-2024-49138-Exploitation-Detected — SOC335 دليل الاستجابة للحوادث لـ CVE-2024-49138 تصعيد صلاحيات CLFS، يغطي فرز التنبيهات، وإثراء استخبارات التهديدات، وتحليل شجرة العمليات، والاحتواء. | Kitploit
أدوات/GitHubGitHub/fabianch20/soc335---cve-2024-49138-exploitation-detected
إدارة مؤشرات الاختراق (IOC)تصعيد الامتيازاتتحليل الثغرات الأمنيةتحليل البرمجيات الخبيثةالتحاليل الرقمية الجنائيةاستخبارات التهديداتالتعلم والتعليمالاستجابة للحوادثتحليل السجلات

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مختبرات وتدريب عملي
GitHubfabianch20/soc335---cve-2024-49138-exploitation-detected

SOC335---CVE-2024-49138-Exploitation-Detected

SOC335 دليل الاستجابة للحوادث لـ CVE-2024-49138 تصعيد صلاحيات CLFS، يغطي فرز التنبيهات، وإثراء استخبارات التهديدات، وتحليل شجرة العمليات، والاحتواء.

عرض المستودع
منذ 16 أياملم تتم المراجعة بعد
مشاركة

Rule CVE CVSS Status Verdict Host


> whoami

root@soc:~# cat case_file.txt

  Platform      : LetsDefend
  Case          : SOC335 - CVE-2024-49138 Exploitation Detected
  EventID       : 313
  Alert Time    : 2025-01-22T02:37:00+03:00
  Alert Type    : Privilege Escalation
  Difficulty    : Medium
  Role          : Security Analyst

  Hostname      : Victor
  IP Address    : 172.16.17.207
  Process User  : EC2AMAZ-ILGVOIN\LetsDefend
  Process Name  : svohost.exe   (masquerading svchost.exe)
  Process Path  : C:\temp\service_installer\svohost.exe
  Parent Proc   : C:\Windows\System32\WINDOWSPOWERSHELL\V1.0\powershell.exe
  File Hash     : b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9
  Device Action : Allowed

  MITRE ATT&CK  : T1059.001  PowerShell
                  T1055      Process Injection
                  T1068      Exploitation for Privilege Escalation
                  T1548      Abuse Elevation Control Mechanism
                  T1110      Brute Force

> ./playbook.sh --pivot-methodology

منهجية من 5 مراحل، كل مرحلة تُحل وفق WHO / WHAT / WHEN / WHY قبل الانتقال إلى المرحلة التالية.

┌─[ STEP 1: ALERT TRIAGE ]─────────────────────────────────────────────────────┐
│                                                                              │
│  WHO   : SIEM queue / SOC335 rule (EventID 313)                              │
│  WHAT  : svohost.exe spawned by powershell.exe outside System32              │
│  WHEN  : 2025-01-22 02:37:00 +03:00                                          │
│  WHY   : separates real EoP attempt from benign svc install                  │
│                                                                              │
│  $ filter process_name="svohost.exe" AND path!="*\System32\*"                │
│                                                                              │
│  PIVOT : hash + host isolated -> enrich with threat intel                    │
└──────────────────────────────────────────────────────────────────────────────┘

┌─[ STEP 2: THREAT INTEL ENRICHMENT ]──────────────────────────────────────────┐
│                                                                              │
│  WHO   : VirusTotal, CISA KEV, SentinelOne CVE DB                            │
│  WHAT  : hash flagged malicious; behavior maps to CVE-2024-49138 (CLFS EoP)  │
│  WHEN  : patched Dec-2024 Patch Tuesday; exploited pre-patch as 0-day, KEV-  │
│          listed                                                              │
│  WHY   : turns an unknown binary into a named, weaponized CVE with known TTPs│
│                                                                              │
│  $ vt hash b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9  │
│                                                                              │
│  PIVOT : malware + CVE confirmed -> validate on endpoint process tree        │
└──────────────────────────────────────────────────────────────────────────────┘

┌─[ STEP 3: ENDPOINT PROCESS TREE ]────────────────────────────────────────────┐
│                                                                              │
│  WHO   : Endpoint Security / EDR telemetry on host Victor                    │
│  WHAT  : child proc whoami.exe executes as NT AUTHORITY\SYSTEM               │
│  WHEN  : immediately after svohost.exe execution, same alert window          │
│  WHY   : proves exploitation SUCCEEDED, not merely attempted                 │
│                                                                              │
│  $ proctree --host Victor --pid 7640                                         │
│                                                                              │
│  PIVOT : escalation confirmed -> pivot to network logs for entry vector      │
└──────────────────────────────────────────────────────────────────────────────┘

┌─[ STEP 4: NETWORK & LOG PIVOT ]──────────────────────────────────────────────┐
│                                                                              │
│  WHO   : Log Management: RDP auth logs + firewall/netflow                    │
│  WHAT  : RDP brute force from 185.107.56.141; outbound traffic to C2         │
│  WHEN  : brute force precedes 02:37 alert; C2 traffic follows escalation     │
│  WHY   : completes the chain from initial access to impact; feeds IOC list   │
│                                                                              │
│  $ filter dst_ip=172.16.17.207 AND event_type=logon_failed,logon_success     │
│                                                                              │
│  PIVOT : full attack chain reconstructed -> containment & closure            │
└──────────────────────────────────────────────────────────────────────────────┘

┌─[ STEP 5: CONTAINMENT & CLOSURE ]────────────────────────────────────────────┐
│                                                                              │
│  WHO   : Incident responder / case owner                                     │
│  WHAT  : Device Action=Allowed -> malware NOT quarantined; host isolated     │
│  WHEN  : at alert time, within response SLA                                  │
│  WHY   : halts lateral movement/C2; documents evidence for TP closure        │
│                                                                              │
│  $ isolate-host Victor --reason "CVE-2024-49138 confirmed exploitation"      │
│                                                                              │
│  PIVOT : case closed as True Positive -> remediation (patch CLFS, harden RDP)│
└──────────────────────────────────────────────────────────────────────────────┘

> ./run_investigation.sh

[ Step 1 ] Alert Triage — SIEM / SOC335
$ cat alert_313.log

[i] EventID 313 | Rule: SOC335 - CVE-2024-49138 Exploitation Detected
[i] Parent -> powershell.exe (v1.0)
[i] Child  -> svohost.exe  "C:\temp\service_installer\svohost.exe"
[!] Legit svchost.exe NEVER runs outside C:\Windows\System32\
[+] ANSWER: filename masquerading detected (svohost vs svchost) -> escalate to full case

🔗 [بيانات حالة LetsDefend SOC335]

[ Step 2 ] إثراء استخبارات التهديدات — VirusTotal + بحث CVE
$ vt hash b432dcf4a0f0b601b1d79848467137a5e25cab5a0b7b1224be9d3b6540122db9
تنزيل الأداة