Linux rapid triage using velociraptor offline collector with catscale
Today we will see how we can collect linux artifacts during malware incidents.
Catscale will use linux live on the land tools to collect artifacts.
Step 1:
Download the velociraptor from the below link on your analyst windows system:
https://docs.velociraptor.app/downloads/
Step 2:
Now we need to launch PowerShell to execute the velociraptor gui by the following command.
.\velociraptor-v0.XX.X-windows-amd64.exe gui
Step 3:
In this step we will import the catscale VR artifacts. Here we have multiple steps.
1. From the VR welcome page, click on "Import Extra Artifacts".
2. On the next dialogue box, follow below image instruction.
Remove all except Artifact Exchange and The Triage Artifacts. Artifact Exchange contains the catscale.
3. Now click Launch to import the artifacts.
4. Once it is done then you will see check mark under state column like the below image.
5. Now we need to build the offline collector. From the above image you can either click on this icon
or from the top left three lines – aka (“hamburger”) icon > Click "Server Artifacts"
Click the same offline collector icon.
6. A box will open where we need to search for artifacts that we need to collect.
Start with catscale. When you select the artifacts then it will become dark green.
Next, for each of the following artifacts, “search” for them, then click to add to our Collector:
• Linux.Network.NetstatEnriched
• Linux.Sys.BashHistory
• Linux.Sys.Crontab
• Linux.Sys.LastUserLogin
• Linux.Sys.Pslist
• Linux.Syslog.SSHLogin
• Linux.Users.RootUsers
• Linux.Users.InteractiveUsers
Now when you are done then click Configure Parameters. From here we need to tweak one thing of netstat collector settings. Click the wrench icon as suggested by the below image.
Instead of LISTEN|ESTAB, just make it as "." period.
Now click the Configure Collection option. Change settings as per the below image.
Now click on Launch.
7. Now need to download the .musl file.
Now we need to take this musl file to the target system and execute. The result will be the .zip file with the format of hostname and timestamp.
Step 4:
In our system wsl is installed and ubuntu is also install via wsl. In production we need to take this musl file to the target system. But for this demo we are switching to wsl ubuntu to show you the process.
From command prompt, open ubuntu shell. Then type below commands.
See the system name. .zip file will follow this name.
cd /mnt/c/Users/Security/Downloads
chmod +x vr-linux-collector-no-upload.musl
sudo ./vr-linux-collector-no-upload.musl
You will get this file.
Step 5:
Now for triage with catscale script, we need to do the following.
Now create this folder "c:\cases\linux-wsl-lab\triage_data” and move your collection data to this folder like the above image suggested.
Now download the catscale script from this link and place it to the triage_data folder -https://github.com/secure-cake/rapid-endpoint-investigations/blob/main/linux-mac/rtw-vr-linux-catscale.sh
Now execute the script.
chmod +x rtw-vr-linux-catscale.sh
./rtw-vr-linux-catscale.sh
Once done, you will see these files on the triage_data folder. Now start analysis.
Avi
Comments
Post a Comment