elastic-edr.md (4026B)
1 --- 2 title: "Elastic EDR" 3 section: "Red Team" 4 sectionSlug: "redteam" 5 sourcePath: "docs/redteam/evasion/elastic-edr.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/evasion/elastic-edr.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Elastic EDR 12 13 > Elastic EDR (Endpoint Detection and Response) is a component of Elastic Security designed to address cybersecurity threats at the endpoint level. It plays a crucial role in preventing, detecting, and responding to cyber threats like ransomware and malware. 14 15 * [peasead/elastic-container](https://github.com/peasead/elastic-container) - Stand up a simple Elastic container with Kibana, Fleet, and the Detection Engine 16 17 ## Setup 18 19 * First, you need `docker` and the `docker-compose` plugin 20 21 ```ps1 22 # Add Docker's official GPG key: 23 sudo apt-get update 24 sudo apt-get install ca-certificates curl 25 sudo install -m 0755 -d /etc/apt/keyrings 26 sudo curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc 27 sudo chmod a+r /etc/apt/keyrings/docker.asc 28 29 # Add the repository to Apt sources: 30 echo \ 31 "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/ubuntu \ 32 $(. /etc/os-release && echo "$VERSION_CODENAME") stable" | \ 33 sudo tee /etc/apt/sources.list.d/docker.list > /dev/null 34 sudo apt-get update 35 36 # Install docker from apt 37 sudo apt-get install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin 38 ``` 39 40 * You might want to grant the `docker` right to the default user 41 42 ```ps1 43 sudo groupadd docker 44 sudo usermod -aG docker $USER 45 ``` 46 47 * Install the requirements for the elastic scripts 48 49 ```ps1 50 apt-get update 51 apt-get install jq git curl 52 ``` 53 54 * Clone the project 55 56 ```ps1 57 git clone https://github.com/peasead/elastic-container 58 cd elastic-container 59 ``` 60 61 * Edit `.env` to set the credentials and activate rules 62 63 ```ps1 64 ELASTIC_PASSWORD="changeme" 65 KIBANA_PASSWORD="changeme" 66 STACK_VERSION="8.11.2" 67 WindowsDR=1 68 LICENSE=trial # enable the platinum features 69 ``` 70 71 * Download the images and run the containers 72 73 ```ps1 74 chmod +x ./elastic-container.sh 75 ./elastic-container.sh start 76 ``` 77 78 * Access the Elastic EDR interface at `https://localhost:5601` 79 * Fleet > `Add agent` 80 * Enroll in Fleet (recommended) 81 * Copy Windows PowerShell one-liner and append the `--insecure` flag if you are using untrusted certificates 82 83 ```ps1 84 powershell Invoke-WebRequest -Uri https://artifacts.elastic.co/downloads/beats/elastic-agent/elastic-agent-7.15.1-windows-x86_64.zip -outfile elastic-agent-7.15.1-windows-x86_64.zip 85 Expand-Archive -Path elastic-agent-7.15.1-windows-x86_64.zip -DestinationPath C:\ElasticAgent 86 C:\ElasticAgent\elastic-agent-7.15.1-windows-x86_64\elastic-agent.exe install -f --fleet-server-es={{ fleet_server_es }} --fleet-server-service-token={{ fleet_token }} --fleet-server-policy={{ fleet_policy }} 87 ``` 88 89 * Fleet > Integrations > Elastic Defend 90 * Switch `Prevent` to `Detect`, to keep the execution running 91 * Enable these features to collect more data 92 93 ```ps1 94 windows.advanced.memory_protection.shellcode_collect_sample 95 windows.advanced.memory_protection.memory_scan_collect_sample 96 windows.advanced.memory_protection.shellcode_enhanced_pe_parsing 97 ``` 98 99 * Destroy the containers 100 101 ```ps1 102 ./elastic-container.sh destroy 103 ``` 104 105 ## References 106 107 * [The Elastic Container Project for Security Research - Andrew Pease, Colson Wilhoit, Derek Ditch - 1 March 2023](https://www.elastic.co/security-labs/the-elastic-container-project) 108 * [Cyber Security Lab Basics - Installing EDR in Malware Development Lab - AhmedS Kasmani](https://www.youtube.com/watch?v=1luhjL7TN9U) 109 * [Setting Up Elastic 8 with Kibana, Fleet, Endpoint Security, and Windows Log Collection - IppSec - 10 oct. 2022](https://youtu.be/Ts-ofIVRMo4)