(In)direct 시스템 콜: 높은 수준에서 낮은 수준으로의 여정
RedOps | Red Team Village | DEF CON 31
시작하기
모든 이론과 실습을 위한 플레이북은 wiki에서 찾을 수 있으며, 준비된 POC와 함께 이 프로젝트의 핵심입니다. 실습을 위한 POC는 메인 페이지에서 찾을 수 있습니다.
즐거운 학습 되세요!
Daniel Feichter
고지 사항
우선, 지난 10년 넘게 제가 하는 모든 일을 지지해 준 여자친구에게 큰 감사를 전합니다! 그녀의 지지와 후원이 없었다면 지난 10년 동안의 어떤 프로젝트도 가능하지 않았을 것입니다.
또한 처음 만난 이후로 저를 지지해 준 AV-Comparatives의 좋은 친구 Andreas Clementi에게도 감사드립니다. 그리고 훌륭한 Red Teamer인 친구 Jonas Kemmner가 저를 지지하고 제 모든 블로그 게시물을 미리 읽어 준 것에 감사드립니다. 이 모든 훌륭한 사람들과 인연을 맺게 되어 매우 감사하게 생각합니다.
이 저장소의 콘텐츠와 모든 코드 예제는 교육 및 연구 목적으로만 제공되며 윤리적인 맥락에서만 사용해야 합니다! 코드 예제는 새로운 것이 아니며, 그렇다고 주장하지도 않습니다. 대부분의 코드 또는 그 기반은 자주 그렇듯이 ired.team에서 비롯되었습니다. 훌륭한 작업과 공유에 대해 @spotheplanet에게 감사드립니다. 또한 훌륭한 도구 x64dbg를 만들어 주신 @mrexodia에게도 많은 감사를 드립니다.
더욱이, 아주 중요하게, 이 워크숍은 EDR 우회의 맥락에서 만능 해결책은 아닙니다. 그러나 Win32 APIs, Native APIs, direct syscalls, indirect syscalls의 기초와 셸코드 실행 및 EDR 우회 맥락에서의 call stacks에 대해 조금 이해하는 데 도움이 되어야 합니다. 그 이상도 이하도 아닙니다. 이 워크숍의 목표는 가장 은밀한 옵션이나 가장 복잡한 direct/indirect syscalls POC를 보여 주는 것이 아니라, 기초를 가르치는 데 집중하는 것입니다. 즉, 가능한 한 적은 도구를 사용하고 가능한 한 많은 작업을 수동으로 수행한다는 뜻입니다.
syscalls, direct system calls, indirect syscalls 등의 주제를 연구하고 형성해 왔으며 계속 연구하고 있는 정보보안 커뮤니티의 모든 구성원들에게 감사를 전하고 싶습니다.
크레딧 및 참고 자료
| 트위터 핸들 | 기여 및 연구 |
|---|
| @Cneelis | https://outflank.nl/blog/2019/06/19/red-team-tactics-combining-direct-system-calls-and-srdi-to-bypass-av-edr/ https://github.com/outflanknl/Dumpert |
| @spotheplanet | 그의 놀라운 블로그와 연구 전체 https://www.ired.team/ |
| @NinjaParanoid | 그의 블로그, 연구, 강의, 그리고 항상 제 질문에 답변해 준 것에 대해. https://0xdarkvortex.dev/hiding-in-plainsight/ https://0xdarkvortex.dev/proxying-dll-loads-for-hiding-etwti-stack-tracing/ |
| @ShitSecure | 그의 연구, 그의 블로그 https://s3cur3th1ssh1t.github.io/, 그리고 EDR, syscalls 등에 대한 훌륭한 논의에 대해. |
| @AliceCliment | 그녀의 블로그, 연구, 그리고 EDR, syscalls 등에 대한 논의에 대해. https://alice.climent-pommeret.red/posts/how-and-why-to-unhook-the-import-address-table/ https://alice.climent-pommeret.red/posts/a-syscall-journey-in-the-windows-kernel/ https://alice.climent-pommeret.red/posts/direct-syscalls-hells-halos-syswhispers2/ |
| @0xBoku | 그의 전반적인 연구, 정보보안에 대한 기여, 새로운 커뮤니티 구성원을 돕는 일, 그리고 정보보안의 지속적인 발전에 대해. https://0xboku.com/ https://github.com/boku7/AsmHalosGate https://github.com/boku7/HellsGatePPID https://github.com/boku7/halosgate-ps |
| @Jackson_T | 그의 연구와 도구 SysWhispers 및 SysWhispers2에 대해. https://github.com/jthuraisamy/SysWhispers) https://github.com/jthuraisamy/SysWhispers2 |
| @KlezVirus | 그의 블로그, 연구, EDR, syscalls 등에 대한 훌륭한 논의와 SysWhispers3에 대해. https://github.com/klezVirus/SysWhispers3 https://klezvirus.github.io/RedTeaming/AV_Evasion/NoSysWhisper/ https://github.com/klezVirus/SilentMoonwalk |
| @j00ru | https://j00ru.vexillium.org/syscalls/nt/64/ |
| @modexpblog | https://www.mdsec.co.uk/2020/12/bypassing-user-mode-hooks-and-direct-invocation-of-system-calls-for-red-teams/ |
| @netero_1010 | https://www.netero1010-securitylab.com/evasion/indirect-syscall-in-csharp) |
| @CaptMeelo | https://captmeelo.com/redteam/maldev/2021/11/18/av-evasion-syswhisper.html |
| Paul Laîné @am0nsec and smelly__vx @RtlMateusz | https://github.com/am0nsec/HellsGate/tree/master |
| @mrd0x | https://github.com/Maldev-Academy/HellHall |
| @SEKTOR7net | https://blog.sektor7.net/#!res/2021/halosgate.md |
| @D1rkMtr | https://github.com/TheD1rkMtr/D1rkLdr |
| @trickster012 | https://github.com/trickster0/TartarusGate |
| @thefLinkk | https://github.com/thefLink/RecycledGate |
| @ElephantSe4l and MarioBartolome | https://github.com/crummie5/FreshyCalls |
추가 자료