
gundog - Microsoft Defender에서의 안내된 헌팅
gundog - Microsoft 365 Defender에서 PowerShell 기반의 가이드 헌팅 도구
Gundog는 Microsoft 365 Defender에서 가이드 헌팅을 제공합니다. 현재는 특히 (아니면 유일하게) 이메일 및 엔드포인트 경고를 대상으로 합니다.
AlertID(이메일 알림으로 받을 수 있음)를 제공하면 gundog가 가능한 한 많은 관련 데이터를 헌팅합니다. 포털에서 사용하는 고급 헌팅과 같은 유연성을 제공하지는 않지만, 경고, 관련된 모든 엔티티 및 일부 보강 정보에 대한 빠른 첫 개요를 제공합니다.
모든 헌팅은 경고 타임스탬프를 기준으로 수행되며, 따라서 경고 직전 또는 직후의 이벤트만을 고려합니다.
또한 헌팅한 각 엔티티에 대해 PowerShell 개체를 제공합니다. 예를 들어 Microsoft 365 Defender DeviceNetworkEvents 테이블에서 이 경고와 관련하여 찾은 모든 항목에 대한 $Network와 같습니다.
gundog에는 여러분의 작업을 더 쉽게 만들어 주는 몇 가지 다른 기능도 있습니다:
gundog로 첫 평가를 마친 후, 포털에서 더 깊이 들어가 조사할 수 있습니다.
gundog를 자유롭게 확장하고 풀 리퀘스트를 보내주세요! 최고의 사이키델릭 경험을 위해 Windows Terminal Dracula 테마를 gundog와 함께 사용하세요.
mandatory parameters:
- TenantID
- ClientID
- ClientSecret
Optional parameters:
- forgetIncidents
(Background: the first thing gundog is doing is to query all incidents and alerts from the incident API from the last 30 days. These are
saved to a global variable. If you restart gundog, it will not query all incidents again, unless you set forgetIncidents to true.)
AAD에 새 앱을 등록하고 다음 권한을 부여하세요: (앱 등록 방법)
Microsoft Graph
- Directory.Read.All
- IdentityRiskEvent.Read.All
- IdentityRiskyUser.Read.All
- SecurityEvents.Read.All
- User.Read
Microsoft Threat Protection
- AdvancedHunting.ReadAll
- Incident.Read.All
Windows Defender ATP
- AdvancedQuery.Read.All
- Alert.Read.All
- File.Read.All
- Ip.Read.All
- Url.Read.All
- User.Read.All
- Vulnerability.Read.All
자세한 정보는 다음을 방문하세요: https://emptydc.com/2021/02/25/gundog/