
Melody é um sensor de internet transparente criado para inteligência de ameaças. Suporta regras de marcação personalizadas e simulação de aplicações vulneráveis.
Monitore o ruído de fundo da Internet
Melody é um sensor de Internet transparente construído para inteligência de ameaças e apoiado por um framework de regras de detecção que permite marcar pacotes de interesse para análise adicional e monitoramento de ameaças.
Aqui estão algumas funcionalidades chave do Melody:
Como tenho que focar em outros projetos no momento, não posso dedicar muito tempo ao desenvolvimento do Melody.
No entanto, há muito espaço para melhorias, então aqui estão algumas funcionalidades que gostaria de implementar um dia:
cmd/meloctl
Obtenha o último lançamento em https://github.com/ma111e/melody/releases.
make install # Set default outfacing interface
make cap # Set network capabilities to start Melody without elevated privileges
make certs # Make self signed certs for the HTTPS fileserver
make enable_all_rules # Enable the default rules
make service # Create a systemd service to restart the program automatically and launch it at startup
sudo systemctl stop melody # Stop the service while we're configuring it
Atualize o arquivo filter.bpf para filtrar pacotes indesejados.
sudo systemctl start melody # Start Melody
sudo systemctl status melody # Check that Melody is running
Os logs devem começar a se acumular em /opt/melody/logs/melody.ndjson.
tail -f /opt/melody/logs/melody.ndjson # | jq
git clone https://github.com/ma111e/melody /opt/melody
cd /opt/melody
make build
Em seguida, continue com os passos do TL;DR de Lançamento.
make certs # Make self signed certs for the HTTPS fileserver
make enable_all_rules # Enable the default rules
mkdir -p /opt/melody/logs
cd /opt/melody/
docker pull ma111e/melody:latest
MELODY_CLI="" # Put your CLI options here. Example : export MELODY_CLI="-s -i 'lo' -F 'dst port 5555' -o 'server.http.port: 5555'"
docker run \
--net=host \
-e "MELODY_CLI=$MELODY_CLI" \
--mount type=bind,source="$(pwd)/filter.bpf",target=/app/filter.bpf,readonly \
--mount type=bind,source="$(pwd)/config.yml",target=/app/config.yml,readonly \
--mount type=bind,source="$(pwd)/var",target=/app/var,readonly \
--mount type=bind,source="$(pwd)/rules",target=/app/rules,readonly \
--mount type=bind,source="$(pwd)/logs",target=/app/logs/ \
ma111e/melody
Os logs devem começar a se acumular em /opt/melody/logs/melody.ndjson.
Detalhes da sintaxe de regras.
CVE-2020-14882 Oracle Weblogic Server RCE:
layer: http
meta:
id: 3e1d86d8-fba6-4e15-8c74-941c3375fd3e
version: 1.0
author: BonjourMalware
status: stable
created: 2020/11/07
modified: 2020/20/07
description: "Checking or trying to exploit CVE-2020-14882"
references:
- "https://nvd.nist.gov/vuln/detail/CVE-2020-14882"
match:
http.uri:
startswith|any|nocase:
- "/console/css/"
- "/console/images"
contains|any|nocase:
- "console.portal"
- "consolejndi.portal?test_handle="
tags:
cve: "cve-2020-14882"
vendor: "oracle"
product: "weblogic"
impact: "rce"
Detalhes do conteúdo dos logs.
Pacote TCP Netcat sobre IPv4 :
{
"tcp": {
"window": 512,
"seq": 1906765553,
"ack": 2514263732,
"data_offset": 8,
"flags": "PA",
"urgent": 0,
"payload": {
"content": "I made a discovery today. I found a computer.\n",
"base64": "SSBtYWRlIGEgZGlzY292ZXJ5IHRvZGF5LiAgSSBmb3VuZCBhIGNvbXB1dGVyLgo=",
"truncated": false
}
},
"ip": {
"version": 4,
"ihl": 5,
"tos": 0,
"length": 99,
"id": 39114,
"fragbits": "DF",
"frag_offset": 0,
"ttl": 64,
"protocol": 6
},
"timestamp": "2020-11-16T15:50:01.277828+01:00",
"session": "bup9368o4skolf20rt8g",
"type": "tcp",
"src_ip": "127.0.0.1",
"dst_port": 1234,
"matches": {},
"inline_matches": [],
"embedded": {}
}