Network egress

નવો host. જોવાનું કારણ.

captured એજન્ટ commands માં અજાણ્યા destinations નોંધો.

સમસ્યા જુઓ. Finding સમજો.

કૅપ્શન સાથે અંગ્રેજી વર્ણન.

તે કઈ રીતે અવગણાઈ જાય છે

તમારા એજન્ટને documentation જોઈએ. થોડી ક્ષણ પછી, તેની command એવા host તરફ નિર્દેશ કરે છે જે તમે આ workflow માં ક્યારેય જોયો નથી. Destination legitimate હોઈ શકે. પણ context વિના, નવો host terminal માં ફક્ત એક બીજી લાઇન છે.

એક એજન્ટ સામાન્ય રીતે familiar package index વાપરે છે. ટાસ્ક દરમ્યાન, recorded ટૂલ arguments માં અજાણ્યું destination દેખાય. મહત્ત્વનો પ્રશ્ન: આ destination આ સેશનમાં શા માટે છે?

ClawMetry શું detect કરે છે

ClawMetry observed host references ને learned cohort baseline સાથે સરખાવે છે. Baseline માં ગેરહાજર host network egress ચેતવણી ઉઠાવી શકે. તારણ નવો host અને તેને unusual ગણવાનું કારણ identify કરે છે.

Finding બદલી નાખતો તફાવત

Triggering ઉદાહરણ

collector.invalid

ચેતવણી તારણ

Quiet સરખામણી

pypi.org baseline માં

આ detector માટે કોઈ finding નહીં.

ચકાસાયેલ ઉદાહરણમાં, baseline familiar package host ધરાવે છે. તે host ચૂપ રહે. અલગ host first time destination તારણ ઉઠાવે. આ સરખામણી learned baseline ચાહે; fresh install ને તમારા normal destinations ખ્યાલ નથી.

Detector result તપાસો
{
  "kind": "network_egress",
  "severity": "warning",
  "evidence": {
    "ground": "first_time",
    "distinct_hosts": 1,
    "hosts": [
      "collector.invalid"
    ],
    "new_hosts": [
      "collector.invalid"
    ],
    "settling_hosts": [],
    "raw_addresses": [],
    "known_host_count": 1,
    "threshold": 8,
    "write_hosts": [],
    "read_only_writes": [],
    "observed": "tool_arguments"
  }
}
Inputs અને સંપૂર્ણ results ડાઉનલોડ કરો (JSON)
ઉદાહરણ કઈ રીતે તપાસ્યું

આ ઉદાહરણો authored event data અથવા disposable configuration files સાથે published detector નું મૂલ્યાંકન કરે છે. Videos તે behaviors દર્શાવે છે. તે live agents અથવા product interface ના recordings નથી. ઉદાહરણોમાં કોઈ command execute કરવામાં આવ્યો ન હતો.

Result આ inputs માટે behavior સ્થાપિત કરે છે. તે runtime ingestion, prevention અથવા real compromise સ્થાપિત કરતું નથી. Pinned source contract તપાસો.

આગળ શું તપાસવું

Command અને આસપાસના ટાસ્ક inspect કરો. શું એજન્ટ documentation fetch કરી રહ્યો હતો, dependency install કરી રહ્યો હતો, કે write કરવાનો પ્રયાસ કરી રહ્યો હતો? Destination ownership અને તે પહેલાં sensitive ગતિવિધિ તપાસો. ક્રિયા expected હતી કે નહીં નક્કી કરવા આ તથ્યો વાપરો.

  1. Command inspect કરો
  2. Destination ચકાસો
  3. અગાઉની ગતિવિધિ તપાસો

આ signal શું સ્થાપિત કરે છે

Host references ટૂલ arguments માંથી આવે છે, packet capture નથી. નવો host connection સફળ થઈ અથવા data exfiltrate થઈ તે સાબિત કરતો નથી.

મહત્વના ક્ષણો દૃશ્યમાન રાખો.

Agent પ્રવૃત્તિ follow કરો, findings તપાસો અને નક્કી કરો કે શું તમારું ધ્યાન જોઈએ.