
Melody هو مستشعر إنترنت شفاف مبني لاستخبارات التهديدات. يدعم قواعد الوسم المخصصة ومحاكاة التطبيقات الضعيفة.
راقب الضوضاء الخلفية للإنترنت
Melody هو مستشعر إنترنت شفاف مصمم لاستخبارات التهديدات ومدعوم بإطار عمل لقواعد الكشف، مما يتيح لك وضع علامات على الحزم محل الاهتمام لمزيد من التحليل ومراقبة التهديدات.
إليك بعض الميزات الرئيسية لـ Melody:
نظراً لأنني يجب أن أركز على مشاريع أخرى الآن، لا يمكنني تخصيص الكثير من الوقت لتطوير Melody.
ومع ذلك، هناك مجال كبير للتحسين، لذا إليك بعض الميزات التي أرغب في تنفيذها يوماً ما:
cmd/meloctl
احصل على أحدث إصدار من https://github.com/ma111e/melody/releases.
make install # Set default outfacing interface
make cap # Set network capabilities to start Melody without elevated privileges
make certs # Make self signed certs for the HTTPS fileserver
make enable_all_rules # Enable the default rules
make service # Create a systemd service to restart the program automatically and launch it at startup
sudo systemctl stop melody # Stop the service while we're configuring it
قم بتحديث ملف filter.bpf لتصفية الحزم غير المرغوب فيها.
sudo systemctl start melody # Start Melody
sudo systemctl status melody # Check that Melody is running
يجب أن تبدأ السجلات في التراكم في /opt/melody/logs/melody.ndjson.
tail -f /opt/melody/logs/melody.ndjson # | jq
git clone https://github.com/ma111e/melody /opt/melody
cd /opt/melody
make build
ثم تابع مع الخطوات من TL;DR الإصدار.
make certs # Make self signed certs for the HTTPS fileserver
make enable_all_rules # Enable the default rules
mkdir -p /opt/melody/logs
cd /opt/melody/
docker pull ma111e/melody:latest
MELODY_CLI="" # Put your CLI options here. Example : export MELODY_CLI="-s -i 'lo' -F 'dst port 5555' -o 'server.http.port: 5555'"
docker run \
--net=host \
-e "MELODY_CLI=$MELODY_CLI" \
--mount type=bind,source="$(pwd)/filter.bpf",target=/app/filter.bpf,readonly \
--mount type=bind,source="$(pwd)/config.yml",target=/app/config.yml,readonly \
--mount type=bind,source="$(pwd)/var",target=/app/var,readonly \
--mount type=bind,source="$(pwd)/rules",target=/app/rules,readonly \
--mount type=bind,source="$(pwd)/logs",target=/app/logs/ \
ma111e/melody
يجب أن تبدأ السجلات في التراكم في /opt/melody/logs/melody.ndjson.
CVE-2020-14882 Oracle Weblogic Server RCE:
layer: http
meta:
id: 3e1d86d8-fba6-4e15-8c74-941c3375fd3e
version: 1.0
author: BonjourMalware
status: stable
created: 2020/11/07
modified: 2020/20/07
description: "Checking or trying to exploit CVE-2020-14882"
references:
- "https://nvd.nist.gov/vuln/detail/CVE-2020-14882"
match:
http.uri:
startswith|any|nocase:
- "/console/css/"
- "/console/images"
contains|any|nocase:
- "console.portal"
- "consolejndi.portal?test_handle="
tags:
cve: "cve-2020-14882"
vendor: "oracle"
product: "weblogic"
impact: "rce"
حزمة TCP عبر Netcat عبر IPv4:
{
"tcp": {
"window": 512,
"seq": 1906765553,
"ack": 2514263732,
"data_offset": 8,
"flags": "PA",
"urgent": 0,
"payload": {
"content": "I made a discovery today. I found a computer.\n",
"base64": "SSBtYWRlIGEgZGlzY292ZXJ5IHRvZGF5LiAgSSBmb3VuZCBhIGNvbXB1dGVyLgo=",
"truncated": false
}
},
"ip": {
"version": 4,
"ihl": 5,
"tos": 0,
"length": 99,
"id": 39114,
"fragbits": "DF",
"frag_offset": 0,
"ttl": 64,
"protocol": 6
},
"timestamp": "2020-11-16T15:50:01.277828+01:00",
"session": "bup9368o4skolf20rt8g",
"type": "tcp",
"src_ip": "127.0.0.1",
"dst_port": 1234,
"matches": {},
"inline_matches": [],
"embedded": {}
}