Показаны сообщения с ярлыком ex. Показать все сообщения
Показаны сообщения с ярлыком ex. Показать все сообщения

23.12.2015

Fireeye malware rec "clip" [NX, EX, FX] запись действий малвари

Запись действий (видео) вредоносного файла внутри виртуальной машины гипервизора MVX (Fireeye)

NX#_debug show avc config
NX#_debug avc config vnc_rec enable


Attack Validator Controller Daemon
        Name                                          : avc
        NA Heart-Beat timeout (ms)                    : 30000
        VM Ping Retry Delay (ms)                      : 5000
        VM Ping Retry Max                             : 20

07.07.2015

BCC. Postfix / MS Exchange + Fireeye EX

Postfix

always_bccAdd the following entry in /etc/postfix/main.cf to forward all mails in the server to fireeyebcc@fireeye.mycorp.com.

always_bcc = fireeyebcc@fireeye.mycorp.com

sender_bcc_maps and recipient_bcc_maps

..........................................
(Вариант с Postfix. BCC)

DNS server (внутренний/внешний, который используется как основной dns для Postfix):

;$TTL 86400
$ORIGIN mycorp.com.
$TTL 3D
...
fireeye         A       192.168.1.116

После чего, Postfix будет копировать мыла на ip 192.168.1.116(адрес на интерфейсе patch3,Fireeye EX, который стоит в режиме BCC, (action - DROP, в настройках))

MS Exchange

Go To Organization Configuration > Hub Transport and select the Send Connectors tab

· Right-click to create a new send connector

· On the ‘Address Space’ page of the wizard, add your BCC domain (fetest.com in this example)

· On the ‘Network Settings’ page, choose ‘Route mail through the following smart hosts’ and

define a new smart host with the IP address of the FireEye (BCC) MTA

· Follow

On the ‘Network Settings’ page, choose ‘Route mail through the following smart hosts’ and
define a new smart host with the IP address of the FireEye (BCC) MTA


Follow the defaults to complete the rest of the wizard

Go To Organization Configuration > Hub Transport and select the Transport Rules tab
· Right-click to create a new transport rule
· On the ‘Conditions’ page of the rule wizard, do not select any conditions (so that the rule
applies unconditionally). You should get a warning that the rule will be applied to every
message
· On the ‘Actions’ page of the wizard, select ‘Blind Carbon Copy…’ and enter the BCC address
· Follow the defaults to complete the wizard and create the rule


22.06.2015

fenet-install-FE

fenet dti mil service type CMS username S_355950 password xxx
fenet dti mil service type DTI username S_355950 password xxx
fenet dti source type CDN username S_355950 password xxx
fenet dti source type CMS username S_355950 password xxx
fenet dti source type DTI username S_355950 password xxx
fenet dti upload destination type CMS username S_355950 password xxx
fenet dti upload destination type DTI username S_355950 password xxx
fenet user S_355950 password xxx