Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to...

63
Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY www.kod.uy CEO CSIETE www.csiete.org

Transcript of Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to...

Page 1: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Open Source Toolsfor Practical Response to Incidents

Mateo Martínez Giovanni Cruz ForeroCEO KOD LATAM SECURITY

www.kod.uy CEO CSIETE

www.csiete.org

Page 2: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Temario1. INTRODUCCIÓN

2. PREPARACIÓN

3. DETECCIÓN Y ANÁLISIS

4. CONTENCIÓN, ERRADICACIÓN Y RECUPERACIÓN

5. ACTIVIDADES POST-INCIDENTE

Page 3: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Respuesta a Incidentes después del Simposio

Page 4: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Oficialmente eres el encargado de IR...

Page 5: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Hay un incidente…

Page 6: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

¿Porqué Respuesta a Incidentes?

Page 7: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Software Libre + Respuesta a Incidentes

Page 8: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE
Page 9: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

¿Cómo sentimos que estamos?

Page 10: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

¿Cómo nos hemos preparado?

Page 11: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Así estamos...

Page 12: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Así nos ven los atacantes...

Page 13: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Así son los atacantes

Page 14: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Y así...

Page 15: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Y así también...

Page 16: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Y aún así...

Page 17: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

O incluso así...

Page 18: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

También se ven ...

Page 19: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Fuente: NIST Computer Security Incident Handling Guide

NIST SP 800-61

Page 20: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Preparación

Page 21: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Preparación● Crear un plan de respuesta ante incidentes

● Priorizar activos

● Sistemas de reporte de incidentes

● Analizadores de tráfico de red

● Herramientas de análisis forense digital

● Conocer configuración de sistemas

● Imágenes de Sistemas Operativos Limpias

● Hashes de archivos críticos

Page 22: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Preparación

https://www.owasp.org/index.php/OWASP_Incident_Response_Project

Page 23: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Preparación

https://www.owasp.org/index.php/OWASP_Open_Cyber_Security_Framework_Project

Page 24: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Preparación

https://www.sans.org/reading-room/whitepapers/incident/incident-response-capabilities-2016-2016-incident-response-survey-37047

Page 25: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Preparación

http://www.haka-security.org/

Page 26: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Preparación

http://molo.ch/

Page 27: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Preparación

https://github.com/volatilityfoundation/volatility

Page 28: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Preparación

https://www.cuckoosandbox.org/

Page 29: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Preparación

https://www.alienvault.com/products/ossim

Page 30: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Preparación

https://github.com/CERTUNLP

Page 31: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Prevención● Gestión de riesgos

● Hardening

● Seguridad y monitoreo de redes

● Prevención de malware

● Capacitación a usuarios

Page 32: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Prevención

http://ossec.github.io/

Page 33: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Prevención

https://oisf.net/suricata/

Page 34: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Prevención

http://www.openvas.org/

Page 35: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Prevención

https://www.owasp.org/index.php/Category:OWASP_ModSecurity_Core_Rule_Set_Project

Page 36: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Detección y Análisis

Vectores de AtaqueSignos de un Incidentes

Fuentes de Precursores e IndicadoresAnálisis de Incidentes

Documentación del IncidentePriorización del IncidenteNotificación del Incidente

Page 37: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Contención, Erradicación y Recuperación

Elección de la Estrategia de ContenciónRecolección y Manejo de Evidencia

Identificación de los Equipos AtacadosErradicación y Recuperación

Page 38: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

F.I.D.O.

Fuentes de Precursores e Indicadore

https://github.com/Netflix/Fido

Signos de un Incidente

Page 39: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

F.I.D.O.

Page 40: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

F.I.D.O.

Page 41: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

ELK

Page 42: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

osquery

Análisis del Incidentehttps://osquery.io/

Page 43: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE
Page 44: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

REDLINE

Page 45: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

MIG: Mozilla InvestiGator

Page 46: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Linux + OS X

Page 47: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

VERIS - Vocabulary for Event Recording and Incident Sharing

Documentación del Incidente

Page 48: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

STIX - Structured Threat Information eXpression Documentación del Incidente

Page 49: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

TAXII

Page 50: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

HAIL A TAXII

Page 51: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

THREATCONNECT

Page 52: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

OTX - Open Threat Exchange

Page 53: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Soluciones Internas

Page 54: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

MISP

Page 55: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

MISP

Page 56: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

MOZDEF

Page 57: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Manera Tradicional de Documentación

Page 58: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

FIR

Page 59: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

RTIR

Page 60: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

THREAT NOTE

Page 61: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Actividades Post-Incidente● Lecciones Aprendidas● Análisis de datos recolectados● Retención de Evidencias

Page 62: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Conclusiones● No hemos cubierto ni el 30% de herramientas open source disponibles para

hacer la respuesta a incidentes de manera práctica, cubrimos solamente algunas de las más relevantes

● El uso de este tipo de herramientas puede permitir una fácil operación de un grupo de respuesta a incidentes sin la necesidad de una inversión alta ni la necesidad de muchos recursos

● Se debe tener un espíritu hacker para poder tener una infraestructura de un grupo de Respuesta a Incidentes con herramientas open source, no será un click and install, pero el resultado podrá permitir tener una infraestructura realmente personalizada.

Page 63: Open Source Tools - Herramientas de Open... · Open Source Tools for Practical Response to Incidents Mateo Martínez Giovanni Cruz Forero CEO KOD LATAM SECURITY  CEO CSIETE

Muchas gracias

CEO KOD LATAM SECURITYwww.kod.uy

CEO CSIETEwww.csiete.org