ABOUT ME

-

Today
-
Yesterday
-
Total
-
  • Volatility ์„ค์น˜ ๋ฐ ์‚ฌ์šฉ๋ฒ• (Windows)
    SECURITY/FORENSICS 2020. 11. 3. 16:10

    1. Volatility ์„ค์น˜

    Volatility ์„ค์น˜ํ•˜๋Š” ๋ฐฉ๋ฒ•์—๋Š” ํฌ๊ฒŒ ๋‘ ๊ฐ€์ง€๊ฐ€ ์žˆ๋‹ค.

     

    1.1 vol.py 1.2 standalone ์œผ๋กœ ์„ค์น˜

    ์ฝ”๋“œ๋ฅผ ๋‹ค์šด๋ฐ›์•„์„œ ์„ค์ •ํ•˜๊ฑฐ๋‚˜, ์‹คํ–‰ํŒŒ์ผ์„ ๋‹ค์šดํ•ด์„œ ์‚ฌ์šฉํ•˜๋Š” ๋ฐฉ๋ฒ•์ด๋‹ค.

    1.2 ๊ฐ€ ์„ค์ •ํ•˜๋Š” ๊ฒŒ ์ ์–ด์„œ ๋” ํŽธ๋ฆฌํ•  ์ˆ˜ ์žˆ์ง€๋งŒ,, 

    ๋‹ค์–‘ํ•œ ๊ธฐ๋Šฅ๊ณผ ์ˆ˜์ •์„ ์œ„ํ•ด์„  1.1 ๋กœ ํ•˜๋Š” ๊ฒƒ์ด ํŽธ๋ฆฌํ•˜๋‹ค.

    (๋‚˜๋„ 1.2 ๋กœ ํ–ˆ๋‹ค๊ฐ€ ๋ถˆํŽธํ•ด์„œ ๊ฒฐ๊ตญ 1.1 ๋กœ ์„ค์น˜ํ•˜์˜€๋‹ค)

     

     

    1.1 vol.py

    ์ฝ”๋“œ๋กœ ๋‹ค์šด๋ฐ›์•„์„œ ์„ค์ •.

     

    1) Python 2.7.x ์„ค์น˜

    Python ํ™ˆํŽ˜์ด์ง€์—์„œ 2.7.x ๋ฅผ ๋‹ค์šด๋ฐ›์•„์ฃผ๋ฉด ๋œ๋‹ค. (www.python.org/downloads/release/python-2718/)

    ์ด๋•Œ Add pyton.exe to Path ๋ฅผ ์„ค์ •ํ•ด์ค˜์„œ cmd ์—์„œ ๋ฐ”๋กœ python ์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ™˜๊ฒฝ ๋ณ€์ˆ˜๋ฅผ ์„ค์ •ํ•ด์ค€๋‹ค.

     

    2) Pycrypto 2.6 ์„ค์น˜ (www.voidspace.org.uk/python/modules.shtml#pycrypto)

    PyCrypto 2.6 for Pyton 2.7 64 bit ๋ฅผ ์„ค์น˜ํ•ด์ฃผ๋ฉด ๋œ๋‹ค.

     

     

     

     

    3) distorm3-3.3.3 ์„ค์น˜ (github.com/gdabah/distorm/releases)

    4

    4) PIL (Python Imaging Library) 1.1.7 ์„ค์น˜ (www.pythonware.com/products/pil/)

    Python Imaging Library 1.1.7 for Python 2.7 ์„ ํƒ

     

    ํ˜น์€ cmd ์— pip install Pillow ๋ฅผ ์ž…๋ ฅํ•˜์—ฌ๋„ ๋œ๋‹ค.

     

    5) Volatility ์„ค์น˜ (www.volatilityfoundation.org/)

    source code ๋ฅผ ์„ ํƒํ•œ๋‹ค.

    *์—ฌ๊ธฐ์„œ standalone ์œผ๋กœ ๋‹ค์šด๋ฐ›์•„์„œ ์„ค์น˜ํ•˜๋Š” ๊ฒŒ 1.2 ์ด๋‹ค. ๋‚˜๋Š” ๊ทธ๋ ‡๊ฒŒ ํ–ˆ๋‹ค๊ฐ€ ํ”„๋กœํŒŒ์ผ ์„ค์ • ๋“ฑ์ด ๋ถˆํŽธํ•ด์„œ 1.1 ์„ ์„ ํ˜ธํ•œ๋‹ค. ๋˜ํ•œ ์‹คํ–‰ํ•ด๋ณด๋‹ˆ 1.2 ๋กœ ์„ค์น˜ํ–ˆ์„ ๋•Œ๋ณด๋‹ค ์†๋„๋„ ๋น ๋ฅธ ๊ฒƒ ๊ฐ™๋‹ค.

     

     

     

    6) ์ตœ์ข…

     

    5)์—์„œ ๋‹ค์šด๋ฐ›์€ ํŒŒ์ผ์„ python27 ํด๋”์˜ Lib\site-packages ๋กœ ์˜ฎ๊ฒจ์ฃผ๊ณ , ํ•ด๋‹น ๊ฒฝ๋กœ(C:\Python27\Lib\site-packages\volatility-2.6\volatility-master) ์—์„œ ๋‹ค์Œ ๋ช…๋ น์–ด๋“ค์„ ์‹คํ–‰ํ•œ๋‹ค.

     

    C:\Python27\Lib\site-packages\volatility-2.6\volatility-master> python setup.py build

     

    C:\Python27\Lib\site-packages\volatility-2.6\volatility-master> python setup.py install

     

    ์ž˜ ์„ค์น˜๋˜์—ˆ๋Š”์ง€ python vol.py -h ๋กœ ํ™•์ธํ•œ๋‹ค.

     

     

     

     

    1.2 standalone ์œผ๋กœ ์„ค์น˜

    : Volatility 2.6 Standalone Windows Program ์‚ฌ์šฉ

     

    1) ํ™ˆํŽ˜์ด์ง€ ์ ‘์† (www.volatilityfoundation.org/)

     

    2) Releases -> 2.6 ์„ ํƒ (๋ฒ„์ „์˜ ์ฐจ์ด. ํ•„์š”์— ๋”ฐ๋ผ ์„ ํƒํ•˜๋ฉด ๋œ๋‹ค) (www.volatilityfoundation.org/26)

     

    3) Volatility 2.6 Windows Standalone Executable (x64) ์„ ํƒ

     

    4) ์••์ถ• ํ’€์–ด์ฃผ๊ณ , path ์„ค์ •ํ•ด์ฃผ๊ธฐ

    (์‹œ์Šคํ…œ ๊ณ ๊ธ‰ ์„ค์ • -> ํ™˜๊ฒฝ ๋ณ€์ˆ˜ -> path ์ถ”๊ฐ€ -> volatility ์„ค์น˜ํ•œ ํด๋” ์ถ”๊ฐ€)

     

    5) cmd ๋ฅผ ํ†ตํ•ด ์‚ฌ์šฉ

     

     

     

     

    2. ์‚ฌ์šฉ๋ฒ•

     

    volatility ๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ CLI ๊ธฐ๋ฐ˜ ํ”„๋กœ๊ทธ๋žจ์ด๋ผ Windows ์—์„œ cmd ๋ฅผ ํ†ตํ•ด ์‹คํ–‰ํ•ด์•ผ ํ•œ๋‹ค.

    ์„ค์น˜ํ•  ๋•Œ ํ™˜๊ฒฝ๋ณ€์ˆ˜ ์„ค์ •์„ ํ•ด์คฌ๊ธฐ ๋•Œ๋ฌธ์—, ํ•ด๋‹น ํŒŒ์ผ์˜ ์ด๋ฆ„์„ ๋ช…๋ น์–ด๋กœ ์‹คํ–‰ํ•˜๋ฉด ๋œ๋‹ค.

     

    (์—ฌ๊ธฐ์„œ ํ•ด๋‹น ํŒŒ์ผ ์ด๋ฆ„์€ volatility ๋กœ ์„ค์ •๋˜์–ด ์žˆ๋‹ค๊ณ  ๊ฐ€์ •ํ•˜๊ณ  ์ž‘์„ฑํ•ฉ๋‹ˆ๋‹ค. ๋ณธ์ธ์˜ ์„ค์ •์— ๋”ฐ๋ผ ์‚ฌ์šฉํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค.)

     

     

    2.0 ์ฃผ์š” ์˜ต์…˜

    -h, --help ๋„์›€๋ง ๋ณด๊ธฐ
    --profile= ๋คํ”„๋œ ํŒŒ์ผ์˜ ํ”„๋กœํŒŒ์ผ ์ง€์ • (์šด์˜์ฒด์ œ, ๋ฒ„์ „ ๋“ฑ)
    --info ๋“ฑ๋ก๋˜์–ด์žˆ๋Š” ๋ชจ๋“  ์˜ค๋ธŒ์ ํŠธ์˜ ์ •๋ณด ํ™•์ธ
    --output=text ์ถœ๋ ฅ ํฌ๋ฉง txt ๋กœ ์„ค์ •
    -v, --verbose ์ƒ์„ธ ์ •๋ณด ํ™•์ธ
    -d, --debug volatility ๋””๋ฒ„๊ทธ
    -f, --filename ๋ฉ”๋ชจ๋ฆฌ ์ด๋ฏธ์ง€์˜ ๊ฒฝ๋กœ ์„ค์ •

     

    2.1 ๊ธฐ๋ณธ ๋ช…๋ น์–ด ํ˜•์‹

    volatility -f [๋คํ”„ ํŒŒ์ผ] [ํ”Œ๋Ÿฌ๊ทธ์ธ]

    volatility -f [๋คํ”„ ํŒŒ์ผ] --profile=[์šด์˜์ฒด์ œ] [ํ”Œ๋Ÿฌ๊ทธ์ธ]

     

    ๋Œ€๋ถ€๋ถ„์˜ ํ”Œ๋Ÿฌ๊ทธ์ธ๋“ค์€ ์ด 2.1 ์˜ ๊ธฐ๋ณธ ๋ช…๋ น์–ด ํ˜•์‹์„ ๋”ฐ๋ผ ์‚ฌ์šฉํ•˜๋ฉด ๋œ๋‹ค.

     

    ์•„๋ž˜์—์„œ ์†Œ๊ฐœํ•˜๋Š” ํ”Œ๋Ÿฌ๊ทธ์ธ ์™ธ์—๋„ ์ˆ˜๋งŽ์€ ํ”Œ๋Ÿฌ๊ทธ์ธ์ด ์กด์žฌํ•˜๊ณ , ์ง์ ‘ ๋งŒ๋“ค์ˆ˜๋„ ์žˆ๋‹ค.

     

     

    2.2 ์šด์˜์ฒด์ œ ๋ถ„์„

    volatility -f [๋คํ”„ ํŒŒ์ผ] imageinfo

    (๋คํ”„ ํŒŒ์ผ์˜ ์ด๋ฏธ์ง€ ์ •๋ณด ๋ถ„์„)

    --> ์˜ˆ์ƒ ์šด์˜์ฒด์ œ, ๋ฉ”๋ชจ๋ฆฌ ์ฃผ์†Œ ๊ณต๊ฐ„, DTB ์™€ KDBG, KCPR ์˜ ์ฃผ์†Œ ์ถœ๋ ฅ

     

     

    2.3 ํ”„๋กœ์„ธ์Šค ๋ถ„์„

    - psscan : ์‹คํ–‰ ์ค‘์ธ/์ข…๋ฃŒ๋œ ํ”„๋กœ์„ธ์Šค ์ •๋ณด ๋ถ„์„

    volatility -f [๋คํ”„ ํŒŒ์ผ] --profile=[์šด์˜์ฒด์ œ] psscan

    - psxview : pslist, psscan ๋“ฑ ์—ฌ๋Ÿฌ ๋ฐฉ๋ฒ•์œผ๋กœ ํ™•์ธํ•œ ํ”„๋กœ์„ธ์Šค ์ •๋ณด ๋น„๊ต

    volatility -f [๋คํ”„ ํŒŒ์ผ] --profile=[์šด์˜์ฒด์ œ] psxview

    - pstree : ํ”„๋กœ์„ธ์Šค์˜ ๋ถ€๋ชจ/์ž์‹๊ด€๊ณ„ ๋ถ„์„

    volatility -f [๋คํ”„ ํŒŒ์ผ] --profile=[์šด์˜์ฒด์ œ] pstree

     

     

    2.4 ๋„คํŠธ์›Œํฌ ๋ถ„์„

    - connections : ํ™œ์„ฑํ™” ์ƒํƒœ์˜ ๋„คํŠธ์›Œํฌ ์—ฐ๊ฒฐ ์ •๋ณด(์œˆ๋„์šฐ xp/Vista)

    volatility -f [๋คํ”„ ํŒŒ์ผ] --profile=[์šด์˜์ฒด์ œ] connections 

    - connscan : ํ™œ์„ฑํ™” ์ƒํƒœ์˜ ๋„คํŠธ์›Œํฌ ์—ฐ๊ฒฐ ์ •๋ณด/ ์ด๋ฏธ ์ข…๋ฃŒ๋œ ๋„คํŠธ์›Œํฌ ์—ฐ๊ฒฐ ์ •๋ณด

    volatility -f [๋คํ”„ ํŒŒ์ผ] --profile=[์šด์˜์ฒด์ œ] connscan 

    - netscan : ํ™œ์„ฑํ™” ์ƒํƒœ์˜ ๋„คํŠธ์›Œํฌ ์—ฐ๊ฒฐ ์ •๋ณด(์œˆ๋„์šฐ7 ์ด์ƒ)

    volatility -f [๋คํ”„ ํŒŒ์ผ] --profile=[์šด์˜์ฒด์ œ] netscan

     

     

    2.5 ์‹œ๊ฐ„์ •๋ณด ํš๋“

    volatility -f [๋คํ”„ ํŒŒ์ผ] timeliner --output-file result.csv

    --> ์•„ํ‹ฐํŒฉํŠธ๋ฅผ ์‹œ๊ฐ„๊ณผ ํ•จ๊ป˜ csv ํŒŒ์ผ๋กœ ์ถœ๋ ฅ

     

     

    2.6 ํŒŒ์ผ ๋ถ„์„

    - filescan : ๋ฉ”๋ชจ๋ฆฌ์— ๋กœ๋“œ ๋œ ํŒŒ์ผ์ •๋ณด ์Šค์บ”, ํŠน์ • ํ™•์žฅ์ž ๋ฐ ํŒŒ์ผ ์ •๋ณด ์ฐพ๊ธฐ

    (Windows) volatility -f [๋คํ”„ ํŒŒ์ผ] --profile=[์šด์˜์ฒด์ œ] filescan | findstr [ํ™•์ธํ•˜๊ณ ์ž ํ•˜๋Š” ํŒŒ์ผ์˜ ๋ฌธ์ž์—ด] 

    (Linux) volatility -f [๋คํ”„ ํŒŒ์ผ] --profile=[์šด์˜์ฒด์ œ] filescan | grep [ํ™•์ธํ•˜๊ณ ์ž ํ•˜๋Š” ํŒŒ์ผ์˜ ๋ฌธ์ž์—ด] 

    (ex. findstr ".jpg)

     

     

    2.7 ์‹คํ–‰ํŒŒ์ผ ์ถ”์ถœ ๋ฐฉ๋ฒ•

    volatility -f [๋คํ”„ ํŒŒ์ผ] procexedump -D [์ €์žฅ๊ฒฝ๋กœ] -p [PID]

     

     

     

     

     

    Ref.

    [1] www.slideshare.net/youngjunchang14/memory-forensics-with-volatility 

    [2] moaimoai.tistory.com/198

    [3] velog.io/@jjewqm/%EB%A9%94%EB%AA%A8%EB%A6%AC-%ED%8F%AC%EB%A0%8C%EC%8B%9D

    [4] ghdwn0217.tistory.com/62

    [5] blog.naver.com/i1004yu/221973880923

     

    .

    ๋Œ“๊ธ€

Designed by Tistory.