daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

elastic-edr.md (4026B)


      1 ---
      2 title: "Elastic EDR"
      3 section: "Red Team"
      4 sectionSlug: "redteam"
      5 sourcePath: "docs/redteam/evasion/elastic-edr.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/evasion/elastic-edr.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Elastic EDR
     12 
     13 > Elastic EDR (Endpoint Detection and Response) is a component of Elastic Security designed to address cybersecurity threats at the endpoint level. It plays a crucial role in preventing, detecting, and responding to cyber threats like ransomware and malware.
     14 
     15 * [peasead/elastic-container](https://github.com/peasead/elastic-container) - Stand up a simple Elastic container with Kibana, Fleet, and the Detection Engine
     16 
     17 ## Setup
     18 
     19 * First, you need `docker` and the `docker-compose` plugin
     20 
     21     ```ps1
     22     # Add Docker's official GPG key:
     23     sudo apt-get update
     24     sudo apt-get install ca-certificates curl
     25     sudo install -m 0755 -d /etc/apt/keyrings
     26     sudo curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc
     27     sudo chmod a+r /etc/apt/keyrings/docker.asc
     28 
     29     # Add the repository to Apt sources:
     30     echo \
     31     "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/ubuntu \
     32     $(. /etc/os-release && echo "$VERSION_CODENAME") stable" | \
     33     sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
     34     sudo apt-get update
     35 
     36     # Install docker from apt
     37     sudo apt-get install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
     38     ```
     39 
     40 * You might want to grant the `docker` right to the default user
     41 
     42     ```ps1
     43     sudo groupadd docker
     44     sudo usermod -aG docker $USER
     45     ```
     46 
     47 * Install the requirements for the elastic scripts
     48 
     49     ```ps1
     50     apt-get update
     51     apt-get install jq git curl
     52     ```
     53 
     54 * Clone the project
     55 
     56     ```ps1
     57     git clone https://github.com/peasead/elastic-container
     58     cd elastic-container
     59     ```
     60 
     61 * Edit `.env` to set the credentials and activate rules
     62 
     63     ```ps1
     64     ELASTIC_PASSWORD="changeme"
     65     KIBANA_PASSWORD="changeme"
     66     STACK_VERSION="8.11.2"
     67     WindowsDR=1
     68     LICENSE=trial # enable the platinum features
     69     ```
     70 
     71 * Download the images and run the containers
     72 
     73     ```ps1
     74     chmod +x ./elastic-container.sh
     75     ./elastic-container.sh start
     76     ```
     77 
     78 * Access the Elastic EDR interface at `https://localhost:5601`
     79 * Fleet > `Add agent`
     80 * Enroll in Fleet (recommended)
     81 * Copy Windows PowerShell one-liner and append the `--insecure` flag if you are using untrusted certificates
     82 
     83     ```ps1
     84     powershell Invoke-WebRequest -Uri https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-7.15.1-windows-x86_64.zip -outfile elastic-agent-7.15.1-windows-x86_64.zip
     85     Expand-Archive -Path elastic-agent-7.15.1-windows-x86_64.zip -DestinationPath C:\ElasticAgent
     86     C:\ElasticAgent\elastic-agent-7.15.1-windows-x86_64\elastic-agent.exe install -f --fleet-server-es={{ fleet_server_es }} --fleet-server-service-token={{ fleet_token }} --fleet-server-policy={{ fleet_policy }}
     87     ```
     88 
     89 * Fleet > Integrations > Elastic Defend
     90     * Switch `Prevent` to `Detect`, to keep the execution running
     91     * Enable these features to collect more data
     92 
     93         ```ps1
     94         windows.advanced.memory_protection.shellcode_collect_sample
     95         windows.advanced.memory_protection.memory_scan_collect_sample
     96         windows.advanced.memory_protection.shellcode_enhanced_pe_parsing
     97         ```
     98 
     99 * Destroy the containers
    100 
    101     ```ps1
    102     ./elastic-container.sh destroy
    103     ```
    104 
    105 ## References
    106 
    107 * [The Elastic Container Project for Security Research - Andrew Pease, Colson Wilhoit, Derek Ditch - 1 March 2023](https://www.elastic.co/security-labs/the-elastic-container-project)
    108 * [Cyber Security Lab Basics - Installing EDR in Malware Development Lab - AhmedS Kasmani](https://www.youtube.com/watch?v=1luhjL7TN9U)
    109 * [Setting Up Elastic 8 with Kibana, Fleet, Endpoint Security, and Windows Log Collection - IppSec - 10 oct. 2022](https://youtu.be/Ts-ofIVRMo4)