איסוף יומנים של Abnormal Security
גרסת כלי הניתוח: 6.0
במאמר הזה מוסבר איך להטמיע יומנים של Abnormal Security ב-Google Security Operations. המנתח מטפל ביומני אימייל בפורמטים JSON ו-Syslog. הוא קודם מנסה לעבד את הקלט כ-JSON, ואם זה לא מצליח, הוא משתמש בתבניות Grok כדי לחלץ נתונים מפורמט Syslog. השדות שחולצו ממופים למודל הנתונים המאוחד (UDM), והנתונים מועשרים בהקשר אבטחה רלוונטי והפורמט עובר סטנדרטיזציה לצורך ניתוח נוסף.
לפני שמתחילים
חשוב לוודא שמתקיימות הדרישות המוקדמות הבאות:
- מופע של Google SecOps.
- גישת אדמין ל-Abnormal Security.
איך מוצאים את מספר הלקוח ב-Google SecOps
- נכנסים למסוף Google SecOps.
- עוברים אל SIEM Settings > Profile (הגדרות SIEM > פרופיל).
- מעתיקים את מזהה הלקוח מהקטע פרטי הארגון ושומרים אותו.
קבלת קובץ אימות להטמעת נתונים ב-Google SecOps
- נכנסים למסוף Google SecOps.
- עוברים אל SIEM Settings > Collection Agents.
- מורידים את קובץ האימות להטמעת נתונים.
הגדרה של Abnormal Security לשליחת יומנים אל Google SecOps
- נכנסים לממשק המשתמש האינטרנטי של Abnormal Security.
- לוחצים על הגדרות > שילובים.
- מחפשים את הסמל של Google Chronicle ולוחצים על Connect (קישור).
- מזינים את מספר הלקוח ב-Google SecOps.
- מזינים את כתובת נקודת הקצה של מכונת Google SecOps.
- קנדה: https://northamerica-northeast2-malachiteingestion-pa.googleapis.com
- Dammam: https://me-central2-malachiteingestion-pa.googleapis.com
- אירופה (מספר אזורים): https://europe-malachiteingestion-pa.googleapis.com
- פרנקפורט: https://europe-west3-malachiteingestion-pa.googleapis.com
- לונדון: https://europe-west2-malachiteingestion-pa.googleapis.com
- מומבאי: https://asia-south1-malachiteingestion-pa.googleapis.com
- סינגפור: https://asia-southeast1-malachiteingestion-pa.googleapis.com
- סידני: https://australia-southeast1-malachiteingestion-pa.googleapis.com
- תל אביב: https://me-west1-malachiteingestion-pa.googleapis.com
- טוקיו: https://asia-northeast1-malachiteingestion-pa.googleapis.com
- ארה"ב (מספר אזורים): https://malachiteingestion-pa.googleapis.com
- ציריך: https://europe-west6-malachiteingestion-pa.googleapis.com
- מעלים את קובץ אימות להטמעת נתונים שהורד קודם כחשבון שירות של Google.
- לוחצים על שמירה > אישור.
פורמטים נתמכים של יומני Abnormal Security
הכלי Abnormal Security parser תומך ביומנים בפורמטים SYSLOG ו-JSON.
יומנים לדוגמה של Abnormal Security שנתמכים
- JSON
{
"threatId": "3fd4ed1a-9237-7e6f-d434-eacdcc41f47b",
"messages": [
{
"abxMessageId": 3405268390454580698,
"abxPortalUrl": "https://portal.abnormalsecurity.com/home/threat-center/remediation-history/3405268390454580698",
"attachmentCount": 0,
"attachmentNames": [],
"attackStrategy": "Unknown Sender",
"attackType": "Spam",
"attackVector": "Link",
"attackedParty": "VIP",
"autoRemediated": true,
"fromAddress": "masked.from@example.com",
"fromName": "Masked User Name",
"impersonatedParty": "None / Others",
"internetMessageId": "<20eb9e7c1c3046fda97f6564c81ced64@530566577>",
"isRead": false,
"postRemediated": false,
"receivedTime": "2023-08-28T14:09:31Z",
"recipientAddress": "masked.recipient@example.com",
"remediationStatus": "Auto-Remediated",
"remediationTimestamp": "2023-08-28T14:09:35.618Z",
"sentTime": "2023-08-28T14:08:44Z",
"subject": "Banking Insights | A deep dive into the global M&A landscape",
"threatId": "3fd4ed1a-9237-7e6f-d434-eacdcc41f47b",
"toAddresses": [
"masked.to@example.com"
],
"ccEmails": [],
"replyToEmails": [
"masked.reply@example.com"
],
"returnPath": "masked.returnPath@example.com",
"senderDomain": "masked.sender.domain",
"senderIpAddress": null,
"summaryInsights": [
"Suspicious Link",
"Unusual Sender",
"Abnormal Email Body HTML",
"Invisible characters found in Email",
"Unusual Sender Domain",
"Suspicious Financial Request",
"Unusual Reply To"
],
"urlCount": 19,
"urls": [
"https://masked.comm.link/e/es?s=530566577&e=2595782&elqTrackId=MASKEDID&elq=MASKEDID&elqaid=119820&elqat=1",
"https://www.masked.group/en/simplifying-the-brand?utm_source=Eloqua&utm_medium=email&utm_campaign=MASKED_CAMPAIGN&elqCampaignId=20995&elq=MASKEDID",
"https://masked.group.link/e/er?utm_source=Eloqua&utm_medium=email&utm_campaign=MASKED_CAMPAIGN&elqCampaignId=20995&s=530566577&lid=192730&elqTrackId=MASKEDID&elq=MASKEDID&elqaid=119820&elqat=1"
// ... (16 additional masked URLs omitted for brevity)
]
}
]
}
- SYSLOG + JSON
<14> {
"threatId": "83da593b-3778-9d2f-da8c-e305dc1425e1",
"messages": [
{
"abxMessageId": 8274341447487143770,
"abxPortalUrl": "https://portal.abnormalsecurity.com/home/threat-center/remediation-history/8274341447487143770",
"attackType": "Spam",
"fromAddress": "masked.from.1@example.com",
"fromName": "Masked User Name",
"internetMessageId": "<PUZPR06MB45764FCED76739D0BC8A1B69E3DFA@masked.server.prod.outlook.com>",
"recipientAddress": "masked.recipient.1@example.com",
"remediationStatus": "Auto-Remediated",
"subject": "Freightview, FreightPOP Users List",
"toAddresses": [
"masked.to.1@example.com"
],
"returnPath": "masked.returnPath.1@example.com",
"senderDomain": "outlook.com",
"senderIpAddress": null,
"urlCount": 0,
"urls": []
},
{
"abxMessageId": -4495524442058864563,
"abxPortalUrl": "https://portal.abnormalsecurity.com/home/threat-center/remediation-history/-4495524442058864563",
"attackType": "Spam",
"fromAddress": "masked.user.2@outlook.com",
"fromName": "Masked User Name",
"internetMessageId": "<PUZPR06MB4576BF221988D780C8412731E3DFA@masked.server.prod.outlook.com>",
"recipientAddress": "masked.recipient.2@example.com",
"remediationStatus": "Auto-Remediated",
"subject": "Freightview, FreightPOP Users List",
"toAddresses": [
"masked.to.2@example.com"
],
"returnPath": "masked.user.2@outlook.com",
"senderDomain": "outlook.com",
"senderIpAddress": null,
"urlCount": 0,
"urls": []
}
]
}
- סכימת JSON (threat_log)
{
"event": {
"abx_message_id": -3325933065721657641,
"abx_portal_url": "https://portal.abnormalsecurity.com/home/threat-center/remediation-history/-3325933065721657641",
"threat_id": "1c3736ab-9e3a-883f-62b5-6fe36ac9672c",
"subject": "[EXTERNAL] RE: Masked Name PUP094439581",
"from_address": "masked.sender@maskeddomain.xyz",
"from_name": "masked.sender@maskeddomain.xyz",
"to_addresses": "masked.recipient@maskedcorp.com",
"recipient_address": "masked.recipient@maskedcorp.com",
"internet_message_id": "<MASKEDID@masked-insurance-group.com>",
"attack_type": "Phishing: Credential",
"return_path": "masked.sender@maskeddomain.xyz",
"sender_ip_address": "",
"urls": [
"www.masked-insurance-group.com",
"http://www.masked-insurance-group.com/"
],
"sender_domain": "masked-insurance-group.com",
"tenant": "Auto Club Group"
},
"sourcetype": "threat_log"
}
- סכימת JSON (abuse_mailbox)
{
"event": {
"abx_metadata": {
"event_type": "ABUSE_MAILBOX",
"timestamp": "2024-04-27T15:25:53.374227319Z",
"trace_id": "00bc67b5-eb26-41c2-9f95-021eb435fc49"
},
"abx_body": {
"campaign_id": "28b9c99f-f4a4-3032-bd99-3b7bac532471",
"subject": "[EXTERNAL] News you might have missed",
"recipient_name": "Masked PII Name",
"recipient_address": "masked.abuse.recipient@secops.com",
"internet_message_id": "<AutoNewsDigest-MASKED@odspnotify>",
"email_label_or_location": "inbox"
}
},
"sourcetype": "abuse_mailbox"
}
- סכימת JSON (audit_log)
{
"event": {
"abx_metadata": {
"event_type": "AUDIT_LOG",
"timestamp": "2024-04-01T17:50:55.194231924Z",
"trace_id": "6f95188c-cba2-4e86-a3ae-3eaf22c869e4"
},
"abx_body": {
"category": "login",
"details": {
"request_url": "/api-token-auth/"
},
"source_ip": "0.0.0.0",
"status": "SUCCESS",
"tenant_name": "masked_secops_tenant",
"timestamp": "2024-04-01T17:50:54.632Z",
"user": {
"email": "masked.audit.user@secops.net"
}
}
},
"sourcetype": "audit_log"
}
- סכימת JSON (case)
{
"event": {
"abx_metadata": {
"event_type": "CASE",
"timestamp": "2024-08-08T12:42:45.104485389Z",
"trace_id": "e4ad638f-439a-4c5f-839d-b650ecab9156"
},
"abx_body": {
"schema_version": "1.0.0",
"case_id": 11188520,
"tenant": "masked name",
"entity": {
"entity_type": "USER_ACCOUNT",
"identifier": "masked.case.user@secops.com"
},
"description": "Account Compromised",
"event_timeline": [
{
"timestamp": "2024-09-07T20:17:25+00:00",
"event_type": "SIGN_IN",
"platform": "AZURE_AD",
"insights": [
{
"signal": "Risky Browser",
"description": "The browser associated with this sign-in, None, is considered risky and has been blocklisted by Abnormal or your organization."
}
],
"ip_address": "0.0.0.0 ",
"operating_system": "ios 17.6",
"isp": "verizon wireless",
"location": {
"city": "Huntley",
"state": "Illinois",
"country": "United States"
}
},
{
"timestamp": "2024-09-07T20:17:25+00:00",
"event_type": "SIGN_IN",
"platform": "AZURE_AD",
"ip_address": "0.0.0.0 ",
"operating_system": "ios 15.6"
}
],
"event_type": "CASE"
}
},
"sourcetype": "case"
}
טבלת מיפוי UDM
| שדה ביומן | מיפוי UDM | היגיון |
|---|---|---|
| attachmentCount | additional.fields.attachmentCount.value.number_value | ממופים ישירות |
| attachmentNames | additional.fields.attachmentNames.value | מחוברים למחרוזת מופרדת בפסיקים |
| attackStrategy | security_result.detection_fields.attackStrategy.value | ממופים ישירות |
| attackType | security_result.threat_name | ממופים ישירות |
| attackVector | security_result.detection_fields.attackVector.value | ממופים ישירות |
| attackedParty | security_result.detection_fields.attackedParty.value | ממופים ישירות |
| autoRemediated | לא ממופה לאובייקט IDM | |
| ccEmails | network.email.cc | כל כתובת אימייל מחולצת ומוסיפים אותה למערך |
| fromAddress | network.email.from | כתובת האימייל מחולצת וממופה ישירות |
| fromName | principal.user.user_display_name | ממופים ישירות |
| impersonatedParty | security_result.detection_fields.impersonatedParty.value | ממופים ישירות |
| internetMessageId | additional.fields.internetMessageId.value.string_value | ממופים ישירות |
| isRead | additional.fields.isRead.value.bool_value | ממופים ישירות |
| postRemediated | additional.fields.postRemediated.value.bool_value | ממופים ישירות |
| receivedTime | additional.fields.mailReceivedTime.value.string_value | ממופים ישירות |
| remediationStatus | additional.fields.remediationStatus.value.string_value | ממופים ישירות |
| remediationTimestamp | additional.fields.mailRemediationTimestamp.value.string_value | ממופים ישירות |
| replyToEmails | network.email.reply_to | כתובת האימייל הראשונה מחולצת וממופה ישירות |
| returnPath | additional.fields.returnPath.value.string_value | ממופים ישירות |
| senderDomain | principal.administrative_domain | ממופים ישירות |
| senderIpAddress | principal.ip, principal.asset.ip | כתובת ה-IP מחולצת וממופה לשני השדות |
| sentTime | additional.fields.mailSentTime.value.string_value | ממופים ישירות |
| נושא | network.email.subject | ממופים ישירות |
| summaryInsights | security_result.summary | מחובר למחרוזת מופרדת בפסיקים |
| threatId | security_result.threat_id | ממופים ישירות |
| toAddresses | network.email.to | כל כתובת אימייל מחולצת ומוסיפים אותה למערך |
| urlCount | additional.fields.urlCount.value.number_value | ממופים ישירות |
| כתובות URL | additional.fields.detectedUrls.value | מחוברים למחרוזת מופרדת בפסיקים |
| additional.fields.campaign_id.value.string_value | ממופה מ-event_data.abx_body.campaign_id אם קיים | |
| additional.fields.trace_id.value.string_value | אם יש ערך, הוא ממופה מ-event_data.abx_metadata.trace_id | |
| additional.fields.messageReportedTime.value.string_value | ממופה מ-event_data.abx_body.message_reported_time אם קיים | |
| metadata.event_type | הערך הוא EMAIL_TRANSACTION אם קיים מערך של הודעות, אחרת הערך נקבע על סמך שדות אחרים ויכול להיות USER_LOGIN, STATUS_UPDATE או GENERIC_EVENT |
|
| metadata.product_name | תמיד מוגדר כ-ABNORMAL_SECURITY |
|
| metadata.vendor_name | תמיד מוגדר כ-ABNORMAL_SECURITY |
|
| metadata.product_event_type | ממופה מ-event_data.abx_metadata.event_type אם קיים | |
| extensions.auth.type | הערך שמוגדר הוא AUTHTYPE_UNSPECIFIED אם event_type הוא USER_LOGIN |
|
| security_result.category | הערך הוא MAIL_SPAM ו-MAIL_PHISHING אם יש מערך של הודעות, אחרת הערך הוא MAIL_PHISHING או MAIL_SPAM בהתאם לשדות אחרים |
|
| security_result.category_details | הערך הוא ABUSE_MAILBOX אם abx_metadata.event_type הוא ABUSE_MAILBOX, אחרת הערך הוא login אם abx_body.category הוא login |
|
| security_result.detection_fields.reported.value | ממופה מ-event_data.abx_body.reported אם קיים | |
| security_result.detection_fields.judgement.value | ממופה מ-event_data.abx_body.judgement אם קיים | |
| target.url | ממופה מ-event_data.abx_body.details.request_url אם הוא קיים | |
| target.user.userid | ממופה מ-event_data.abx_body.user.email אם קיים | |
| target.user.email_addresses | ממופה מ-event_data.abx_body.user.email אם קיים | |
event.abx_body.abnormal_message_id |
event.idm.read_only_udm.metadata.product_log_id |
מופה מיומן השינויים |
event.abx_body.email_label_or_location |
event.idm.read_only_udm.additional.fields |
מופה מיומן השינויים |
event.abx_body.not_analyzed |
event.idm.read_only_udm.security_result.detection_fields |
מופה מיומן השינויים |
event_data.message_sources", "event_data.sender_auth_results.spf", "event_data.sender_auth_results.dkim", "event_data.sender_auth_results.dmarc", "event_data.tenant", and "event_data.attack_score |
additional.fields |
מופה מיומן השינויים |
event_data.abx_body.severity |
security_result.severity |
מופה מיומן השינויים |
event_data.abx_body.trigger_event" and "event_data.abx_body.entity.entity_type |
additional.fields |
מופה מיומן השינויים |
event_data.abx_body.entity.identifier |
principal.user.email_addresses |
מופה מיומן השינויים |
event_data.abx_body.case_id |
metadata.product_log_id |
מופה מיומן השינויים |
sourcetype", "event.folder_locations |
additional.fields |
מופה מיומן השינויים |
event.abx_message_id |
metadata.product_log_id |
מופה מיומן השינויים |
יומן שינויים
צפייה ביומן השינויים של מנתח התוכן הזה
הבעיה עדיין לא נפתרה? קבלת תשובות מחברי הקהילה וממומחי Google SecOps.