개요
Windows 메모리 이미지를 트리아지 유형(triage type)에 따라 처리하도록 개발된 Python 스크립트입니다.
요구 사항
- Python3
- Bulk Extractor
- Volatility2 with Community Plugins
- Volatility3
- Plaso
- Yara
사용 방법
빠른 트리아지
python3 winSuperMem.py -f memdump.mem -o output/ -tt 1
전체 트리아지
python3 winSuperMem.py -f memdump.mem -o output/ -tt 2
종합 트리아지
python3 winSuperMem.py -f memdump.mem -o output/ -tt 3
설치
- Python 3 설치
- Python 2 설치
- pip3 install -r requirements.txt
- Volatility 3 Framework 설치
- Volatility 2 Framework 설치
- Volatility 2 Community Plugins 다운로드
- Bulk Extractor 설치
- Plaso 설치
- Yara 설치
- Strings 설치
- EVTxtract 설치
출력 결과 읽는 방법
- 종합 트리아지의 출력 디렉터리 구조:
- BEoutputdir - Bulk Extractor 출력
- DumpedDllsOutput - 프로세스에 로드된 덤프된 DLL
- DumpedFilesOutput - 메모리에서 덤프된 파일
- DumpedModules - 덤프된 로드된 드라이버
- DumpedProcessOutput - 덤프된 실행 중인 프로세스
- DumpedRegistry - 덤프된 로드된 레지스트리 하이브
- EVTxtract - EVTxtract로 추출된 데이터
- IOCs.csv - 출력 데이터 세트에서 식별된 수집된 IP
- Logging.log - 스크립트 로깅
- Plaso - Plaso 마스터 타임라인
- Strings - Unicode, Ascii, Big Endian 문자열 출력
- Volatility2 - Volatility2 플러그인 출력
- Volatility3 - Volatility3 플러그인 출력
- Yara - Yara 매치
문제 해결
이 섹션에는 몇 가지 알려진 버그가 설명되어 있습니다.
- Windows 8 미만의 Windows 이미지에서는 파일 덤프가 작동하지 않을 수 있습니다. volatility3 filescan 플러그인이 제공하는 오프셋은 때때로 가상(virtual)이 아닌 물리(physical) 주소입니다. 어떤 것이 반환되는지 지정하는 설명자(descriptor)도 없습니다. 현재 스크립트는 가상 주소만 기대합니다.
dumpfiles 함수를 --virtaddr에서 --physaddr로 변경하여 이 문제를 해결할 수 있습니다.