linux安装使用SysmonForLinux
下载deb包:
https://github.com/Sysinternals/SysinternalsEBPF/releases
https://github.com/Sysinternals/SysmonForLinux/releases/tag/1.2.0.0
安装:
1 2 3 | 10 sudo dpkg -i sysinternalsebpf_1.2.0-0_amd64.deb 11 sudo dpkg -i sysmonforlinux_1.2.0-0_amd64.deb 12 sudo sysmon -i |
查看日志:
1 2 3 4 5 6 7 8 9 | sudo journalctl -f Jul 24 04:55:58 kali sysmon[6504]: <Event><System><Provider Name= "Linux-Sysmon" Guid= "{ff032593-a8d3-4f13-b0d6-01fc615a0f97}" /><EventID>1</EventID><Version>5</Version><Level>4</Level><Task>1</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime= "2023-07-24T08:55:58.234550000Z" /><EventRecordID>5127</EventRecordID><Correlation/><Execution ProcessID= "6504" ThreadID= "6504" /><Channel>Linux-Sysmon/Operational</Channel><Computer>kali</Computer><Security UserId= "0" /></System><EventData><Data Name= "RuleName" >-</Data><Data Name= "UtcTime" >2023-07-24 08:55:58.240</Data><Data Name= "ProcessGuid" >{adae0cb1-3c9e-64be-1d46-26cbb2550000}</Data><Data Name= "ProcessId" >9563</Data><Data Name= "Image" >/usr/bin/ip</Data><Data Name= "FileVersion" >-</Data><Data Name= "Description" >-</Data><Data Name= "Product" >-</Data><Data Name= "Company" >-</Data><Data Name= "OriginalFileName" >-</Data><Data Name= "CommandLine" >ip a s </Data><Data Name= "CurrentDirectory" >/home/kali</Data><Data Name= "User" >kali</Data><Data Name= "LogonGuid" >{adae0cb1-0000-0000-e803-000000000000}</Data><Data Name= "LogonId" >1000</Data><Data Name= "TerminalSessionId" >2</Data><Data Name= "IntegrityLevel" >no level</Data><Data Name= "Hashes" >-</Data><Data Name= "ParentProcessGuid" >{00000000-0000-0000-0000-000000000000}</Data><Data Name= "ParentProcessId" >9562</Data><Data Name= "ParentImage" >-</Data><Data Name= "ParentCommandLine" >-</Data><Data Name= "ParentUser" >-</Data></EventData></Event> Jul 24 04:55:58 kali sysmon[6504]: <Event><System><Provider Name= "Linux-Sysmon" Guid= "{ff032593-a8d3-4f13-b0d6-01fc615a0f97}" /><EventID>1</EventID><Version>5</Version><Level>4</Level><Task>1</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime= "2023-07-24T08:55:58.234758000Z" /><EventRecordID>5128</EventRecordID><Correlation/><Execution ProcessID= "6504" ThreadID= "6504" /><Channel>Linux-Sysmon/Operational</Channel><Computer>kali</Computer><Security UserId= "0" /></System><EventData><Data Name= "RuleName" >-</Data><Data Name= "UtcTime" >2023-07-24 08:55:58.240</Data><Data Name= "ProcessGuid" >{adae0cb1-3c9e-64be-59c3-c52c33560000}</Data><Data Name= "ProcessId" >9564</Data><Data Name= "Image" >/usr/bin/grep</Data><Data Name= "FileVersion" >-</Data><Data Name= "Description" >-</Data><Data Name= "Product" >-</Data><Data Name= "Company" >-</Data><Data Name= "OriginalFileName" >-</Data><Data Name= "CommandLine" >grep -o -P (?<=inet )[0-9]{1,3}(\.[0-9]{1,3}){3}</Data><Data Name= "CurrentDirectory" >/home/kali</Data><Data Name= "User" >kali</Data><Data Name= "LogonGuid" >{adae0cb1-0000-0000-e803-000000000000}</Data><Data Name= "LogonId" >1000</Data><Data Name= "TerminalSessionId" >2</Data><Data Name= "IntegrityLevel" >no level</Data><Data Name= "Hashes" >-</Data><Data Name= "ParentProcessGuid" >{00000000-0000-0000-0000-000000000000}</Data><Data Name= "ParentProcessId" >9562</Data><Data Name= "ParentImage" >-</Data><Data Name= "ParentCommandLine" >-</Data><Data Name= "ParentUser" >-</Data></EventData></Event> Jul 24 04:55:58 kali sysmon[6504]: <Event><System><Provider Name= "Linux-Sysmon" Guid= "{ff032593-a8d3-4f13-b0d6-01fc615a0f97}" /><EventID>5</EventID><Version>3</Version><Level>4</Level><Task>5</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime= "2023-07-24T08:55:58.235759000Z" /><EventRecordID>5129</EventRecordID><Correlation/><Execution ProcessID= "6504" ThreadID= "6504" /><Channel>Linux-Sysmon/Operational</Channel><Computer>kali</Computer><Security UserId= "0" /></System><EventData><Data Name= "RuleName" >-</Data><Data Name= "UtcTime" >2023-07-24 08:55:58.241</Data><Data Name= "ProcessGuid" >{adae0cb1-3c9e-64be-1d46-26cbb2550000}</Data><Data Name= "ProcessId" >9563</Data><Data Name= "Image" >/usr/bin/ip</Data><Data Name= "User" >kali</Data></EventData></Event> Jul 24 04:55:58 kali sysmon[6504]: <Event><System><Provider Name= "Linux-Sysmon" Guid= "{ff032593-a8d3-4f13-b0d6-01fc615a0f97}" /><EventID>5</EventID><Version>3</Version><Level>4</Level><Task>5</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime= "2023-07-24T08:55:58.236145000Z" /><EventRecordID>5130</EventRecordID><Correlation/><Execution ProcessID= "6504" ThreadID= "6504" /><Channel>Linux-Sysmon/Operational</Channel><Computer>kali</Computer><Security UserId= "0" /></System><EventData><Data Name= "RuleName" >-</Data><Data Name= "UtcTime" >2023-07-24 08:55:58.242</Data><Data Name= "ProcessGuid" >{adae0cb1-3c9e-64be-59c3-c52c33560000}</Data><Data Name= "ProcessId" >9564</Data><Data Name= "Image" >/usr/bin/grep</Data><Data Name= "User" >kali</Data></EventData></Event> Jul 24 04:55:58 kali sysmon[6504]: <Event><System><Provider Name= "Linux-Sysmon" Guid= "{ff032593-a8d3-4f13-b0d6-01fc615a0f97}" /><EventID>5</EventID><Version>3</Version><Level>4</Level><Task>5</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime= "2023-07-24T08:55:58.236236000Z" /><EventRecordID>5131</EventRecordID><Correlation/><Execution ProcessID= "6504" ThreadID= "6504" /><Channel>Linux-Sysmon/Operational</Channel><Computer>kali</Computer><Security UserId= "0" /></System><EventData><Data Name= "RuleName" >-</Data><Data Name= "UtcTime" >2023-07-24 08:55:58.242</Data><Data Name= "ProcessGuid" >{00000000-0000-0000-0000-000000000000}</Data><Data Name= "ProcessId" >9562</Data><Data Name= "Image" ><unknown process></Data><Data Name= "User" >kali</Data></EventData></Event> Jul 24 04:55:58 kali sysmon[6504]: <Event><System><Provider Name= "Linux-Sysmon" Guid= "{ff032593-a8d3-4f13-b0d6-01fc615a0f97}" /><EventID>5</EventID><Version>3</Version><Level>4</Level><Task>5</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime= "2023-07-24T08:55:58.236456000Z" /><EventRecordID>5132</EventRecordID><Correlation/><Execution ProcessID= "6504" ThreadID= "6504" /><Channel>Linux-Sysmon/Operational</Channel><Computer>kali</Computer><Security UserId= "0" /></System><EventData><Data Name= "RuleName" >-</Data><Data Name= "UtcTime" >2023-07-24 08:55:58.242</Data><Data Name= "ProcessGuid" >{adae0cb1-3c9e-64be-b91b-bf8270550000}</Data><Data Name= "ProcessId" >9557</Data><Data Name= "Image" >/usr/bin/dash</Data><Data Name= "User" >kali</Data></EventData></Event> Jul 24 04:55:59 kali sysmon[6504]: <Event><System><Provider Name= "Linux-Sysmon" Guid= "{ff032593-a8d3-4f13-b0d6-01fc615a0f97}" /><EventID>1</EventID><Version>5</Version><Level>4</Level><Task>1</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated SystemTime= "2023-07-24T08:55:59.163318000Z" /><EventRecordID>5133</EventRecordID><Correlation/><Execution ProcessID= "6504" ThreadID= "6504" /><Channel>Linux-Sysmon/Operational</Channel><Computer>kali</Computer><Security UserId= "0" /></System><EventData><Data Name= "RuleName" >-</Data><Data Name= "UtcTime" >2023-07-24 08:55:59.168</Data><Data Name= "ProcessGuid" >{adae0cb1-3c9f-64be-9132-26787b550000}</Data><Data Name= "ProcessId" >9565</Data><Data Name= "Image" >/usr/bin/sudo</Data><Data Name= "FileVersion" >-</Data><Data Name= "Description" >-</Data><Data Name= "Product" >-</Data><Data Name= "Company" >-</Data><Data Name= "OriginalFileName" >-</Data><Data Name= "CommandLine" >sudo journalctl -f</Data><Data Name= "CurrentDirectory" >/home/kali/Desktop</Data><Data Name= "User" >kali</Data><Data Name= "LogonGuid" >{adae0cb1-0000-0000-e803-000000000000}</Data><Data Name= "LogonId" >1000</Data><Data Name= "TerminalSessionId" >2</Data><Data Name= "IntegrityLevel" >no level</Data><Data Name= "Hashes" >-</Data><Data Name= "ParentProcessGuid" >{00000000-0000-0000-0000-000000000000}</Data><Data Name= "ParentProcessId" >1586</Data><Data Name= "ParentImage" >-</Data><Data Name= "ParentCommandLine" >-</Data><Data Name= "ParentUser" >-</Data></EventData></Event> Jul 24 04:55:59 kali sudo[9565]: kali : TTY=pts/0 ; PWD=/home/kali/Desktop ; USER=root ; COMMAND=/usr/bin/journalctl -f |
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 | └─$ sudo journalctl -f | sudo /opt/sysmon/sysmonLogView Event SYSMONEVENT_PROCESS_TERMINATE RuleName: - UtcTime: 2023-07-24 08:56:38.438 ProcessGuid: {adae0cb1-3cc6-64be-0000-000000000000} ProcessId: 9892 Image: - User: kali Event SYSMONEVENT_PROCESS_TERMINATE RuleName: - UtcTime: 2023-07-24 08:56:38.438 ProcessGuid: {adae0cb1-3cc6-64be-b9eb-bfc606560000} ProcessId: 9887 Image: /usr/bin/dash User: kali Event SYSMONEVENT_CREATE_PROCESS RuleName: - UtcTime: 2023-07-24 08:56:38.981 ProcessGuid: {adae0cb1-3cc6-64be-91c2-e74030560000} ProcessId: 9895 Image: /usr/bin/sudo FileVersion: - Description: - Product: - Company: - OriginalFileName: - CommandLine: sudo journalctl -f CurrentDirectory: /home/kali/Desktop User: kali LogonGuid: {adae0cb1-0000-0000-e803-000000000000} LogonId: 1000 TerminalSessionId: 2 IntegrityLevel: no level Hashes: - ParentProcessGuid: {00000000-0000-0000-0000-000000000000} ParentProcessId: 1586 ParentImage: - ParentCommandLine: - ParentUser: - Event SYSMONEVENT_CREATE_PROCESS RuleName: - UtcTime: 2023-07-24 08:56:38.982 ProcessGuid: {adae0cb1-3cc6-64be-91c2-f2c5c1550000} ProcessId: 9896 Image: /usr/bin/sudo FileVersion: - Description: - Product: - Company: - OriginalFileName: - CommandLine: sudo /opt/sysmon/sysmonLogView CurrentDirectory: /home/kali/Desktop User: kali LogonGuid: {adae0cb1-0000-0000-e803-000000000000} LogonId: 1000 TerminalSessionId: 2 IntegrityLevel: no level Hashes: - ParentProcessGuid: {00000000-0000-0000-0000-000000000000} ParentProcessId: 1586 ParentImage: - ParentCommandLine: - ParentUser: - |
数据采集和windows sysmon类似。
标签:
安全分析
【推荐】国内首个AI IDE,深度理解中文开发场景,立即下载体验Trae
【推荐】编程新体验,更懂你的AI,立即体验豆包MarsCode编程助手
【推荐】抖音旗下AI助手豆包,你的智能百科全书,全免费不限次数
【推荐】轻量又高性能的 SSH 工具 IShell:AI 加持,快人一步
· 全程不用写代码,我用AI程序员写了一个飞机大战
· MongoDB 8.0这个新功能碉堡了,比商业数据库还牛
· 记一次.NET内存居高不下排查解决与启示
· 白话解读 Dapr 1.15:你的「微服务管家」又秀新绝活了
· DeepSeek 开源周回顾「GitHub 热点速览」
2020-07-24 FI的developuser就是人机用户
2019-07-24 函数式编程之pipeline——很酷有没有
2019-07-24 函数式编程——做到并发,不可变数据修改就只能复制后修改返回
2018-07-24 DNS污染——domain name的解析被劫持了返回无效的ip
2017-07-24 Fuzzy C Means 算法及其 Python 实现——写得很清楚,见原文
2017-07-24 spark Bisecting k-means(二分K均值算法)
2017-07-24 python spark kmeans demo