, 30 2017 . 09:06
+
Positive Hack Days 7, ( , ?) (The Standoff).
SOC, . , .
(Positive Technologies):
, , . , , . .
, ( ). , , . .
, , , , . .
5 :
SOC
SOC . , SOC , ( ).
12 , , .
SOC . S.P.A.N (Servionica Palo Alto Networks).
, .
.
VMware.
( ) MaxPatrol 8 . 1719 pdf-.
. :
- IDS .
- IDS .
- Moloch .
- Network Analyzer .
- Network Analyzer .
- HIDS (host IDS) .
- TIAS , .
. .
, 30 .
, PHDays .
, .
!
.
, ! 8 , 11-30.
, - , 19 IDS:
, ( ). Moloch . .
, , , . , - , , .
HIDS , - , .
, VPN, . !
- , , , , .
- - !
- , .
. SOC . . , , , .
, .
- , 198.18.78.12 - web- (198.18.12.177) . , . . . , - .
- .1. , . NAT . fair-play .
- (198.18.12.169) DMZ mysql (10.25.153.24). , . . , . .
- , DMZ. web-c (198.18.12.179) XSS. . xss, url. !
- web- (198.18.12.179) pureFTP. FTP. .
- web- (198.18.12.180) (/.git) . . !
- 00:30 10.64.94.0/24. DMZ. , . *- , !
- web- (198.18.12.141), /install. . .
- ! SMB. , Secret Net . , false positive .
- 198.18.12.169 /wp_include . .
- 05:00 07:00 . .
- 8:00 , : nmap, sqlmap, nessus, ( nmap). , user-agent: go-http-client , .
- , , , . , , .
- , 198.18.12.143. wordpress ( ) API- admin:admin123. . , .
- FTP. .
S.P.A.N.
, , , .
, !
- 20:26 smb 172.20.3.147 10.25.21.23. . -.
- , smb, snmp, sql. , . .
- , 203.0.113.169 ( ) wordpress white hat, .
- smb 172.20.3.147 10.25.21.24 ( , ).
! , , . , 100% .
, . ? :
- . - , , , . .
- ( ) , , .
- , . , , .
, , . - !
, . PHDays 8.
Positive Technologies ( , , ) .
S.P.A.N. , .
, .
Baymaxx .
.
UAC Bypass
I 2017
SDL. 2017
https://habrahabr.ru/post/329730/