<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>cs_security.log</title>
        <link>https://velog.io/</link>
        <description>코드에 숨겨진 위협을 읽고 AI로 보안의 미래를 설계합니다. 프론트엔드 개발 경험을 자산 삼아 더 견고하고 지능적인 보안 운영 시스템을 구축해 나가는 과정을 기록합니다</description>
        <lastBuildDate>Thu, 01 Oct 2026 10:41:20 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://github.com/jpmonette/feed</generator>
        <image>
            <title>cs_security.log</title>
            <url>https://velog.velcdn.com/images/cs_security/profile/f1019efd-3412-4145-b872-11f345d32303/image.png</url>
            <link>https://velog.io/</link>
        </image>
        <copyright>Copyright (C) 2019. cs_security.log. All rights reserved.</copyright>
        <atom:link href="https://v2.velog.io/rss/cs_security" rel="self" type="application/rss+xml"/>
        <item>
            <title><![CDATA[150. Linux 정보 수집 — Linux 정보 노출 및 수집 종합 정리]]></title>
            <link>https://velog.io/@cs_security/syssec-c50</link>
            <guid>https://velog.io/@cs_security/syssec-c50</guid>
            <pubDate>Thu, 01 Oct 2026 10:41:20 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>50/50편</strong> (전체 150/450)
학습 단계: 실전 시나리오·종합
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c49">149. Linux 정보 수집 — 실전 시나리오</a></li>
<li><a href="https://velog.io/@cs_security/syssec-c01">101. OS 정보 수집 흔적 식별</a></li>
<li><a href="https://velog.io/@cs_security/linsec-50-final-comprehensive">150. Linux 시스템 침해사고 종합 분석(linsec)</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>C영역 50편은 <strong>&quot;침입 후 정찰(reconnaissance)&quot;</strong> 을 탐지·분석하는 체계입니다. 공격자가 시스템·네트워크·계정·프로세스·파일·로그를 조회하는 흔적을, 정상 관리와 구분해 SOC에서 탐지하는 방법을 다뤘습니다.</p>
<pre><code class="language-text">[Linux 정보 수집 정찰 탐지 체계]
 정찰 유형 식별(C01~45)
   ↓
 정상 기준선 대비(C10·20·30·40·45)
   ↓
 세션 상관분석(C46)
   ↓
 Wazuh/ELK 탐지(C47·48)
   ↓
 정탐/오탐 판단(C48)
   ↓
 Incident Response(C49)</code></pre>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>정찰은 공격의 초기 단계라, 탐지하면 권한 상승(D)·탈취(E)·지속성(F) 이전에 대응할 수 있습니다.</li>
<li>정찰 명령은 정상 관리와 같아, <strong>세션 상관·기준선</strong>이 탐지의 핵심입니다.</li>
<li>C영역은 A(설정)·B(계정) 영역과 함께, 공격 흐름의 &quot;정찰&quot; 축을 담당합니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<p><strong>정보 수집 종합 정리표</strong></p>
<table>
<thead>
<tr>
<th>항목</th>
<th>내용</th>
</tr>
</thead>
<tbody><tr>
<td>정보 수집 유형</td>
<td>시스템·네트워크·계정/권한·프로세스/서비스·파일·로그/설정</td>
</tr>
<tr>
<td>주요 로그</td>
<td>auditd(recon_*), secure/auth.log, /var/log, 원격 사본</td>
</tr>
<tr>
<td>탐지 포인트</td>
<td>세션 내 다영역 연속 조회, 보안솔루션/자격증명/흔적 조회</td>
</tr>
<tr>
<td>정상/비정상</td>
<td>단일영역·관리망·업무시간 vs 다영역·비관리망·새벽(C45·48 비교표)</td>
</tr>
<tr>
<td>Wazuh</td>
<td>102000 대역, recon 키, 세션 상관(102450)</td>
</tr>
<tr>
<td>ELK/SIEM</td>
<td>세션별 영역 수 집계, 출발지·시간 결합</td>
</tr>
<tr>
<td>IOC</td>
<td>출발지 IP·계정·조회 대상(id_rsa·.env·보안솔루션)</td>
</tr>
<tr>
<td>타임라인</td>
<td>로그인→시스템→네트워크→계정→프로세스→파일→로그(C49)</td>
</tr>
<tr>
<td>정탐/오탐</td>
<td>다영역·전후 공격(정탐) vs 단일·업무맥락(오탐)</td>
</tr>
<tr>
<td>초기 대응</td>
<td>세션 종료·계정 조치·출발지 차단(B영역 연계)</td>
</tr>
<tr>
<td>추가 조사</td>
<td>다음 단계(D·E·F) 전개, 다른 서버 동일 IOC</td>
</tr>
<tr>
<td>사고 보고</td>
<td>정찰 범위·IOC·다음 단계 위험·대응</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># 정찰 탐지 체계 점검 (분석 방법)
# 1) recon 감사 규칙 적재 여부
sudo auditctl -l | grep -c recon_
# 2) Wazuh recon 룰 활성 여부
sudo grep -c &#39;102[0-9]\{3\}&#39; /var/ossec/etc/rules/*.xml 2&gt;/dev/null
# 3) 최근 정찰 상관 Alert
# Kibana: rule.id:102450 or rule.id:102470 (최근 7일)</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">[정찰 탐지 체계 — 실습 예시 점검]
auditd recon 규칙   : 적재됨
Wazuh 102000 룰     : 활성, wazuh-logtest 검증 완료
세션 상관(102450)   : 동작 확인
원격 로그 전송      : 구성(A영역 29편) — 로컬 변조 대비
→ 정찰 탐지 운영 가능</code></pre>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">[탐지 공백 — 실습 예시]
auditd recon 규칙   : 미적재 → 정찰 조회가 기록되지 않음
-p r 규칙 폭증      : 튜닝 안 됨 → Alert 피로로 사실상 미탐
원격 전송 없음      : 로컬 로그 삭제 시 정찰 흔적 소실(C41~43)
→ 보완 전까지 정찰 탐지 불가</code></pre>
<p>특히 <strong>auditd recon 규칙 미적재·원격 전송 없음</strong>은 정찰을 탐지도 보존도 못 하게 하므로 우선 보완 대상입니다.</p>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>C영역을 A·B영역과 합친 공격 흐름 전체입니다(가상의 예시).</p>
<pre><code class="language-text">A영역(설정)   하드닝 상태·변경     ┐
B영역(계정)   로그인·인증·탈취      ├─ 침입·기반
C영역(정찰)   정보 수집(이 영역)    ┘
   ↓
D영역(권한)   권한 변경 이상 징후   ← 다음
E~I영역       탈취·프로세스·로그변조·확산·무결성

정찰(C)은 침입(B) 후, 권한 상승(D) 전의 연결 고리</code></pre>
<table>
<thead>
<tr>
<th>영역</th>
<th>역할</th>
</tr>
</thead>
<tbody><tr>
<td>A</td>
<td>서버 설정·하드닝</td>
</tr>
<tr>
<td>B</td>
<td>계정·인증·탈취</td>
</tr>
<tr>
<td>C</td>
<td>정보 수집(정찰)</td>
</tr>
<tr>
<td>D</td>
<td>권한 변경(다음)</td>
</tr>
</tbody></table>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>정찰 탐지는 <strong>세션 상관 + 기준선 + 원격 로그 보존</strong>을 축으로 운영합니다.</li>
<li>auditd recon 규칙·Wazuh 102000 룰·세션 상관이 모두 있어야 정찰을 탐지·보존합니다.</li>
<li>정찰 탐지 시점이 D·E·F영역 이전의 조기 대응 기회입니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<p>C영역 탐지 체계를 한 장으로 정리하면 다음과 같습니다.</p>
<pre><code class="language-text">       [수집]                    [탐지]                      [대응]
 auditd recon_*(C01~45)    세션 상관·Wazuh·ELK(C46~48)    판단(C48)→IR(C49)
        ↓                          ↓                          ↑
   원격 전송(A영역 29) ── 로컬 변조 대비 ──→ 대시보드 ────────┘
        ↑                                                      │
        └────── 재발 방지: 기준선·룰·예외 갱신 ←───────────────┘</code></pre>
<p>다음 <strong>D영역 「권한 변경 이상 징후」(151~200)</strong> 에서는, 정찰(C27·C28)로 파악한 권한 상승 경로를 공격자가 <strong>실제로 실행</strong>하는 단계 — chmod/chown·SUID·setuid·sudoers 변경 등 권한 변경의 이상 징후를 탐지합니다. C영역이 &quot;상승 경로를 찾는 정찰&quot;이라면, D영역은 &quot;그 경로로 권한을 바꾸는 행위&quot;입니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — 정찰 탐지 체계(recon 규칙·Wazuh 룰·세션 상관·원격 전송)의 적재·동작을 점검합니다.</li>
<li><strong>범위 확인</strong> — 정찰 Alert의 다음 단계(D·E·F) 전개와 다른 서버 동일 IOC를 확인합니다.</li>
<li><strong>증거 확보</strong> — 정찰 범위·IOC·타임라인을 사고 보고로 정리합니다.</li>
<li><strong>차단/조치</strong> — 정탐은 침해 대응(세션·계정·IP), 공백은 체계 보완을 진행합니다.</li>
<li><strong>재발 방지</strong> — C영역 탐지 체계를 A·B영역과 통합 운영합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>구분</th>
<th>핵심 내용</th>
</tr>
</thead>
<tbody><tr>
<td>유형</td>
<td>시스템·네트워크·계정·프로세스·파일·로그</td>
</tr>
<tr>
<td>탐지</td>
<td>세션 상관·기준선·Wazuh 102000·ELK</td>
</tr>
<tr>
<td>보존</td>
<td>원격 전송(로컬 변조 대비)</td>
</tr>
<tr>
<td>연결</td>
<td>A(설정)·B(계정)·C(정찰)·D(권한, 다음)</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;정찰은 침입과 권한 상승 사이의 연결 고리 — 조기 탐지 지점&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p><strong>C영역 「Linux 정보 노출 및 수집」 50편을 마칩니다.</strong> 다음은 D영역 <strong><a href="https://velog.io/@cs_security/series/system-security-vuln">151. 권한 변경 이상 징후 — chmod/chown 기반 권한 변경 개요</a></strong> 로, 정찰로 찾은 상승 경로를 실제 실행하는 권한 변경 탐지로 이어집니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c49">149. Linux 정보 수집 — 실전 시나리오 — 로그인부터 정찰·SIEM 탐지까지</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[149. Linux 정보 수집 — 실전 시나리오 — 로그인부터 정찰·SIEM 탐지까지]]></title>
            <link>https://velog.io/@cs_security/syssec-c49</link>
            <guid>https://velog.io/@cs_security/syssec-c49</guid>
            <pubDate>Thu, 01 Oct 2026 10:41:20 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>49/50편</strong> (전체 149/450)
학습 단계: 실전 시나리오·종합
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c46">146. Linux 정보 수집 — 이벤트 상관분석</a></li>
<li><a href="https://velog.io/@cs_security/syssec-a49">049. 하드닝 해제 후 침해 시도 타임라인(A영역)</a></li>
<li><a href="https://velog.io/@cs_security/syssec-b49">049. brute-force부터 계정 탈취·권한 상승까지(B영역)</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>이 편은 <strong>가상의 실습 시나리오</strong>입니다. B영역에서 탈취된 세션(devops, 192.168.56.77, ses=12)이 로그인 직후 수행하는 <strong>정찰 전 과정</strong>을, 공격 명령이 아니라 <strong>관제 화면과 로그에 남는 흔적</strong> 중심으로 재구성합니다.</p>
<pre><code class="language-text">정찰 시나리오 (방어자 관점)
 로그인(B영역 74편 돌파)
   ↓
 시스템 정보 확인 (C01~10)
   ↓
 네트워크 정보 확인 (C11~20)
   ↓
 계정/권한 정보 확인 (C21~30)
   ↓
 프로세스/서비스 확인 (C31~40)
   ↓
 중요 파일 존재 확인 (C38·39)
   ↓
 관련 로그 발생 → SIEM 탐지 → SOC 분석</code></pre>
<p>A영역 49편(설정 변경)·B영역 49편(계정 탈취) 시나리오에 이어, 이 편은 <strong>정찰</strong> 관점으로 같은 사건을 봅니다.</p>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>정찰 단계는 공격의 초기라, 여기서 SIEM이 탐지하면 권한 상승·탈취·지속성(D·E·F영역) 이전에 대응할 수 있습니다.</li>
<li>관제원은 공격 명령을 재현할 필요 없이, <strong>어떤 흔적이 어떤 순서로 남는가</strong>를 알면 정찰을 탐지·분석할 수 있습니다.</li>
<li>이 시나리오는 C영역 전체(C01~48)의 종합 적용입니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<table>
<thead>
<tr>
<th>단계</th>
<th>관제 화면·로그 흔적</th>
<th>영역</th>
</tr>
</thead>
<tbody><tr>
<td>로그인</td>
<td>비관리망 성공(B영역 74)</td>
<td>B</td>
</tr>
<tr>
<td>시스템</td>
<td>recon_sysinfo 다건</td>
<td>C01~10</td>
</tr>
<tr>
<td>네트워크</td>
<td>recon_net 다건 + IDS 전환(C20)</td>
<td>C11~20</td>
</tr>
<tr>
<td>계정/권한</td>
<td>recon_account/priv</td>
<td>C21~30</td>
</tr>
<tr>
<td>프로세스/서비스</td>
<td>recon_proc/svc + 보안솔루션 조준</td>
<td>C31~40</td>
</tr>
<tr>
<td>중요 파일</td>
<td>recon_file(id_rsa·.env)</td>
<td>C38·39</td>
</tr>
<tr>
<td>종합</td>
<td>세션 상관 Alert(102450)</td>
<td>C46~48</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># 정찰 시나리오 재구성 (분석 방법) — 세션 타임라인
SES=12
sudo ausearch --session $SES -i 2&gt;/dev/null | grep -oE &#39;[0-9]{2}:[0-9]{2}:[0-9]{2}.*key=&quot;recon_[^&quot;]+&quot;&#39; | sed -E &#39;s/.*(recon_[a-z]+)&quot;.*/\1/&#39; | sort | uniq -c
# SIEM: 세션 12 정찰 타임라인
# Kibana: data.audit.session:&quot;12&quot; and rule.groups:&quot;recon&quot; → 시간순</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<p>정상 로그인 후에는 이런 정찰 흐름이 나타나지 않습니다.</p>
<pre><code class="language-text">09:12 로그인(admin1, 관리망, publickey)
09:13 systemctl status httpd  (단일 작업)
 → recon 상관 Alert 없음 (정상)</code></pre>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<p><strong>정찰 시나리오 타임라인 (가상, 2026-10-02)</strong></p>
<pre><code class="language-text">시각      흔적                                      영역/탐지
02:10:44  Accepted password devops 192.168.56.77    B영역 74(돌파)
02:11:40  uname·os-release·cpuinfo (recon_sysinfo)  C01~10 / 102000
02:13:00  ip addr/route/neigh·ss (recon_net)        C11~20 / 102190
02:13:05  IDS: 내부 대역 스캔 전환                   C20(네트워크 측)
02:14:00  passwd·group·sudo -l (recon_account/priv) C21~30 / 102290
02:15:10  ps·pgrep wazuh·systemctl (recon_proc/svc) C31~40 / 102300(보안솔루션)
02:16:25  ls id_rsa·cat .env (recon_file)           C38·39 / 102370
02:17:00  grep 자기IP secure (recon_log)            C41·42 / 102400
02:17:30  [SIEM] 세션 12 전방위 정찰 Alert           C46~48 / 102450·102470</code></pre>
<ul>
<li>로그인 직후 6분간 <strong>시스템→네트워크→계정→프로세스→파일→로그</strong> 전 영역 정찰</li>
<li>각 단계가 recon 키로 탐지되고, 세션 상관(102450)으로 하나의 정찰로 묶임</li>
<li>다음 단계(권한 상승 D·중요 정보 E·지속성 F)로 이어지기 전 탐지 가능</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>SOC 분석 관점의 정리입니다(가상의 예시).</p>
<pre><code class="language-text">[관제 화면]
 세션 12 (devops, 192.168.56.77) 전방위 정보 수집 Alert (level 13)
 - 영역: 시스템·네트워크·계정·프로세스·파일·로그 (6영역)
 - 시간: 02:11~02:17 (6분 집중)
 - 전: B영역 돌파 / 후: E영역 접근 징후

[분석 결론]
 정탐: 탈취 계정의 침해 정찰 (단일 영역이면 보류, 다영역이라 정탐)
 다음 예상: 권한 상승(D)·자격증명 악용(E)·지속성(F)</code></pre>
<table>
<thead>
<tr>
<th>분석 항목</th>
<th>내용</th>
</tr>
</thead>
<tbody><tr>
<td>정탐 근거</td>
<td>다영역·비관리망·새벽·돌파 직후</td>
</tr>
<tr>
<td>IOC</td>
<td>192.168.56.77, devops, id_rsa·.env 접근</td>
</tr>
<tr>
<td>다음 단계</td>
<td>D·E·F영역</td>
</tr>
</tbody></table>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>정찰 시나리오는 <strong>로그인→각 영역 정찰→세션 상관 Alert</strong>의 순서로 관제 화면에 나타납니다.</li>
<li>공격 명령 없이도 흔적 순서·recon 키·세션 상관으로 정찰을 탐지·분석할 수 있습니다.</li>
<li>정찰 탐지 시점이 D·E·F영역 이전의 <strong>조기 대응 기회</strong>입니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;!-- 돌파 직후 전방위 정찰: B영역 돌파 + C영역 상관 결합 --&gt;
&lt;rule id=&quot;102490&quot; level=&quot;14&quot;&gt;
  &lt;if_sid&gt;102470&lt;/if_sid&gt;
  &lt;if_matched_sid&gt;101220&lt;/if_matched_sid&gt;  &lt;!-- B영역 돌파 --&gt;
  &lt;same_field field=&quot;audit.session&quot; /&gt;
  &lt;description&gt;인증 돌파 직후 전방위 정찰(침해 정찰 Incident)&lt;/description&gt;
&lt;/rule&gt;</code></pre>
<p>B영역 돌파(101220)와 C영역 정찰 상관(102470)을 결합하면 &quot;침입→정찰&quot; 흐름을 하나로 탐지합니다. SIEM 상관(148편)으로도 구현합니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — 정찰 세션의 로그인→각 영역 정찰 순서와 세션 상관을 확인합니다.</li>
<li><strong>범위 확인</strong> — 정찰 뒤 D·E·F영역(상승·탈취·지속성) 전개를 추적합니다.</li>
<li><strong>증거 확보</strong> — 세션 정찰 타임라인·IOC(IP·계정·대상 파일)를 보존합니다.</li>
<li><strong>차단/조치</strong> — 탈취·정찰 세션이면 B영역 대응과 다음 단계 선제 차단을 진행합니다.</li>
<li><strong>재발 방지</strong> — 돌파+정찰 결합 상관을 운영해 조기 대응합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>단계</th>
<th>흔적</th>
</tr>
</thead>
<tbody><tr>
<td>로그인</td>
<td>비관리망 돌파(B영역)</td>
</tr>
<tr>
<td>시스템~로그</td>
<td>recon_* 영역별 다건</td>
</tr>
<tr>
<td>종합</td>
<td>세션 상관 Alert(102450)</td>
</tr>
<tr>
<td>결합</td>
<td>돌파+정찰(102490)</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;정찰 흔적의 순서와 세션 상관으로 공격 명령 없이도 침해를 조기 탐지&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c50">150. Linux 정보 수집 — Linux 정보 노출 및 수집 종합 정리</a></strong> 에서는 C영역 마지막으로 <strong>Linux 정보 노출 및 수집 종합 정리</strong>와 D영역 연결을 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c48">148. Linux 정보 수집 — ELK/SIEM 기반 정보 수집 탐지와 정탐·오탐 판단</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[148. Linux 정보 수집 — ELK/SIEM 기반 정보 수집 탐지와 정탐·오탐 판단]]></title>
            <link>https://velog.io/@cs_security/syssec-c48</link>
            <guid>https://velog.io/@cs_security/syssec-c48</guid>
            <pubDate>Thu, 01 Oct 2026 10:41:19 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>48/50편</strong> (전체 148/450)
학습 단계: SOC 탐지 연계
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c47">147. Linux 정보 수집 — Wazuh 기반 탐지</a></li>
<li><a href="https://velog.io/@cs_security/syssec-a46">046. 설정 변경 이벤트의 SIEM·ELK 연계(A영역)</a></li>
<li><a href="https://velog.io/@cs_security/syssec-b48">048. 인증 Alert 정탐·오탐 판단(B영역)</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>Wazuh 룰(C47)이 Alert를 만들면, ELK/SIEM에서 <strong>세션별 집계·대시보드</strong>로 전체를 보고, 각 Alert를 <strong>정탐·정상행위·오탐</strong>으로 판단합니다. 정보 수집은 정상 명령 기반이라 판단이 특히 중요합니다.</p>
<pre><code class="language-text">SIEM 탐지·판단 흐름
 Wazuh Alert(recon) → Elasticsearch → Kibana 대시보드
   ↓
 세션별 recon 영역 수·시간 밀도 집계
   ↓
 정탐/오탐 판단: 기준선·주체·맥락·다음 단계
   ↓
 대응(정탐) / 튜닝(오탐)

판단 핵심(문제 지문): 이벤트·user·IP·time·process·trace·관련로그·전후이벤트·기준선·탐지조건·오탐가능성·추가확인·대응</code></pre>
<p>A영역 46편(SIEM 연계)·B영역 48편(정탐오탐)의 틀을 정보 수집에 적용합니다.</p>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>정보 수집 Alert는 정상 관리 명령과 겹쳐 오탐이 많습니다. 기준선·맥락 없이 올리면 피로도가, 닫으면 정찰을 놓칩니다.</li>
<li>세션별 집계(다영역 상관)가 단건보다 정탐률이 높습니다(C46).</li>
<li>판단 결과를 대응·튜닝으로 되돌려야 탐지 품질이 유지됩니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<table>
<thead>
<tr>
<th>판단 요소</th>
<th>확인</th>
</tr>
</thead>
<tbody><tr>
<td>이벤트·user·IP·time</td>
<td>Alert 기본 필드</td>
</tr>
<tr>
<td>process·command trace</td>
<td>data.audit.comm·exe</td>
</tr>
<tr>
<td>관련 로그·전후 이벤트</td>
<td>세션(ses) 타임라인</td>
</tr>
<tr>
<td>정상 기준선</td>
<td>계정 평소 조회(C10·20·30)</td>
</tr>
<tr>
<td>탐지 조건·오탐 가능성</td>
<td>룰·정상 작업 여부</td>
</tr>
<tr>
<td>추가 확인·대응</td>
<td>다음 단계·조치</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-text"># Kibana(KQL) 정보 수집 탐지 질의 (실습 예시)
# 1) 세션별 recon 영역 수 (다영역 = 정찰)
rule.groups: &quot;recon&quot; and agent.name: &quot;rocky9-web01&quot;
  → Terms(data.audit.session) × Unique count(rule.id)

# 2) 특정 세션 정찰 타임라인
data.audit.session: &quot;12&quot;  → 시간순, 컬럼: timestamp, rule.description, data.audit.comm

# 3) 비관리망·새벽 정찰 (B영역 출발지와 결합)
rule.groups: &quot;recon&quot; and not data.srcip: &quot;192.168.56.0/28&quot;</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<p>정상행위(Benign)로 판정되는 사례입니다.</p>
<pre><code class="language-text">Alert   : 102000 시스템 정보 조회 (admin1, ses=8, 09:00)
집계    : 단일 영역(recon_sysinfo) 2건
기준선  : admin1은 아침 점검에 uname/df 사용
전후    : 이후 정상 서비스 관리
판정    : 정상행위 / 튜닝 — admin1 아침 점검 시간 예외(좁게)</code></pre>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<p>정탐으로 판정되는 사례입니다.</p>
<pre><code class="language-text">Alert   : 102450 전방위 정보 수집 (devops, ses=12, 02:11~02:17)
집계    : 7개 영역, 수십 건, 6분 집중
기준선  : devops {관리망·업무시간·소수 조회} — 전면 이탈
IP/time : 192.168.56.77(비관리망), 새벽
전후    : B영역 돌파(74편) 직후, 이후 E영역 접근 징후
판정    : 정탐 → 침해 정찰 Incident (C49 시나리오)</code></pre>
<p>정상 사례와 비교하면 영역 수·시간·출발지·전후 이벤트가 모두 반대입니다.</p>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>흔한 오탐·정상행위 패턴과 처리입니다(분석 방법).</p>
<pre><code class="language-text">패턴                          원인              처리
단일 영역 소수 조회           관리자 점검       기준선·시간 예외(좁게)
모니터링 스크립트의 조회      정기 수집         스크립트 계정·시각 예외
장애 대응 중 다수 조회        인시던트 대응     변경관리·티켓 확인
백업 스크립트의 파일 탐색     정상 백업         백업 계정 예외(C47 102460)</code></pre>
<p>예외는 <strong>계정+시각+대상</strong>을 좁게 지정합니다(B영역 48편). 넓은 예외는 공격 통로가 됩니다.</p>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>정보 수집 Alert는 <strong>세션 다영역 집계 + 기준선·맥락</strong>으로 정탐/오탐을 판단합니다.</li>
<li>단일 영역·관리망·업무 시간은 오탐 가능, 다영역·비관리망·새벽·전후 공격은 정탐입니다.</li>
<li>판단에 근거(기준선·전후 이벤트)를 남기고, 오탐은 좁은 예외로 튜닝합니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;!-- 비관리망·업무외 정찰은 상향 --&gt;
&lt;rule id=&quot;102470&quot; level=&quot;13&quot;&gt;
  &lt;if_sid&gt;102450&lt;/if_sid&gt;
  &lt;srcip&gt;!192.168.56.0/28&lt;/srcip&gt;
  &lt;time&gt;18:00-08:00&lt;/time&gt;
  &lt;description&gt;업무 외 비관리망 전방위 정보 수집(정찰 Incident)&lt;/description&gt;
&lt;/rule&gt;</code></pre>
<p>SIEM에서는 세션별 distinct recon_id count와 출발지·시간을 결합한 알림으로 운영합니다(A영역 46편 방식).</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — Alert의 집계(영역 수·밀도)·기준선·출발지·시간·전후 이벤트를 판단 요소대로 확인합니다.</li>
<li><strong>범위 확인</strong> — 정탐이면 세션으로 다음 단계(E·F·G) 전개를 확인합니다.</li>
<li><strong>증거 확보</strong> — 판단 근거(집계·기준선·타임라인)를 보존합니다.</li>
<li><strong>차단/조치</strong> — 정탐은 침해 대응(C49), 오탐은 좁은 예외 튜닝을 진행합니다.</li>
<li><strong>재발 방지</strong> — 정보 수집 대시보드·판단 기준을 운영합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>판단 요소</th>
<th>내용</th>
</tr>
</thead>
<tbody><tr>
<td>집계</td>
<td>세션 다영역 수·시간 밀도</td>
</tr>
<tr>
<td>기준선</td>
<td>계정 평소 조회(C10·20·30)</td>
</tr>
<tr>
<td>맥락</td>
<td>출발지·시간·전후 이벤트</td>
</tr>
<tr>
<td>정탐</td>
<td>다영역·비관리망·새벽·전후 공격</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;정보 수집은 정상 명령 기반 — 세션 집계+기준선으로 정탐을 가린다&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c49">149. Linux 정보 수집 — 실전 시나리오 — 로그인부터 정찰·SIEM 탐지까지</a></strong> 에서는 실전 시나리오로 <strong>로그인부터 정찰·SIEM 탐지까지</strong>를 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c47">147. Linux 정보 수집 — Wazuh 기반 Linux 정보 수집 탐지</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[147. Linux 정보 수집 — Wazuh 기반 Linux 정보 수집 탐지]]></title>
            <link>https://velog.io/@cs_security/syssec-c47</link>
            <guid>https://velog.io/@cs_security/syssec-c47</guid>
            <pubDate>Thu, 01 Oct 2026 10:41:19 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>47/50편</strong> (전체 147/450)
학습 단계: SOC 탐지 연계
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c46">146. Linux 정보 수집 — 이벤트 상관분석</a></li>
<li><a href="https://velog.io/@cs_security/llp-47-wazuh">47. Wazuh(llp)</a></li>
<li><a href="https://velog.io/@cs_security/syssec-a47">047. 서버 설정 탐지 규칙 모음(A영역)</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>C영역 상관분석(C46)을 Wazuh로 자동화합니다. 핵심은 <strong>auditd의 recon 키를 Wazuh가 받아, 세션 기준으로 상관</strong>하는 것입니다. C영역 룰은 <strong>102000번대</strong>를 씁니다.</p>
<pre><code class="language-text">탐지 파이프라인
 auditd 규칙(recon_*)        → audit.log
    ↓ Wazuh audit 디코더
 Wazuh manager (룰 매칭)      → recon 단건 룰 + 세션 상관 룰
    ↓
 Alert (102000대) → 대시보드(148편)

룰 계층
 단건  : recon_* 키별 조회 (낮은 레벨)
 세션 상관: 다영역 결합 (높은 레벨, 102450)
 유스케이스: 정찰→다음단계 (E·F·G 연계)</code></pre>
<p>A영역 47편(룰셋 관리)의 방식을 C영역에 적용합니다.</p>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>수동 상관분석(C46)은 사고 후 분석엔 좋지만, 상시 탐지는 자동화가 필요합니다.</li>
<li>auditd <code>-p r</code>(읽기) 규칙은 이벤트가 많아, <strong>사람 세션(auid)·키·빈도</strong>로 좁히지 않으면 로그가 폭증합니다.</li>
<li>룰은 반드시 <code>wazuh-logtest</code>로 검증하고 테스트 환경에서 오탐을 튜닝한 뒤 배포합니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<table>
<thead>
<tr>
<th>요소</th>
<th>내용</th>
</tr>
</thead>
<tbody><tr>
<td>auditd 연동</td>
<td>recon_* 키 규칙(C01~45)</td>
</tr>
<tr>
<td>Wazuh 디코더</td>
<td>audit → data.audit.key·session·auid</td>
</tr>
<tr>
<td>단건 룰</td>
<td>102000~102440(키별)</td>
</tr>
<tr>
<td>상관 룰</td>
<td>102450(세션 다영역)</td>
</tr>
<tr>
<td>검증</td>
<td>wazuh-logtest</td>
</tr>
<tr>
<td>튜닝</td>
<td>사람 세션·빈도·예외</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># 1) auditd recon 규칙이 Wazuh로 수집되는지 확인 (실습 예시)
sudo tail -f /var/ossec/logs/alerts/alerts.log | grep -E &#39;recon_|102[0-9]{3}&#39;

# 2) 샘플 정찰 로그로 룰 매칭 검증
sudo /var/ossec/bin/wazuh-logtest
# 입력: type=SYSCALL ... auid=1002 ses=12 comm=&quot;uname&quot; key=&quot;recon_sysinfo&quot;
# 출력: id &#39;102000&#39;(또는 상관 102450) 확인

# 3) 오탐 튜닝: 관리자 계정·백업 스크립트 세션 예외 (좁게)
# local_rules.xml 에 특정 auid/프로그램 예외 룰 추가</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">**Phase 3: Completed filtering (rules).
    id: &#39;102450&#39;
    level: &#39;12&#39;
    description: &#39;단일 세션의 전방위 정보 수집(다영역 정찰 상관)&#39;
    groups: &#39;[..., syssec_c, recon]&#39;</code></pre>
<p>샘플 정찰 로그가 상관 룰(102450)에 매칭되고, 관리자 정상 세션은 단건 낮은 레벨에 그치는 상태가 정상입니다.</p>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">$ sudo tail /var/ossec/logs/ossec.log
wazuh-analysisd: ERROR: Invalid regex at rule &#39;102440&#39;
 또는
(recon_log 단건 Alert 폭증 — tail/cat 정상 작업까지 탐지)</code></pre>
<ul>
<li>정규식 오류로 룰 로딩 실패 → 해당 파일 미적용(A영역 47편과 동일 위험)</li>
<li><code>-p r</code> 읽기 규칙이 너무 넓어 <strong>정상 로그 열람까지 Alert 폭증</strong> → 사람 세션·빈도로 좁혀야 함</li>
<li>배포 전 wazuh-logtest·테스트 환경 검증 필수</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>Wazuh 탐지 결과의 구조입니다(가상의 예시).</p>
<pre><code class="language-text">rule.id: 102450  level: 12
rule.description: 단일 세션의 전방위 정보 수집
data.audit.auid: 1002   data.audit.session: 12
agent.name: rocky9-web01   timestamp: 2026-10-02T02:17:00
rule.mitre.id: [&quot;T1082&quot;,&quot;T1016&quot;,&quot;T1087&quot;]</code></pre>
<table>
<thead>
<tr>
<th>필드</th>
<th>활용</th>
</tr>
</thead>
<tbody><tr>
<td>audit.session</td>
<td>세션 상관</td>
</tr>
<tr>
<td>audit.auid</td>
<td>행위자</td>
</tr>
<tr>
<td>rule.mitre.id</td>
<td>ATT&amp;CK 매핑</td>
</tr>
<tr>
<td>agent.name</td>
<td>호스트</td>
</tr>
</tbody></table>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>C영역 룰은 <strong>102000 대역 + recon 그룹</strong>으로 통일하고 세션 상관을 핵심으로 둡니다.</li>
<li><code>-p r</code> 읽기 규칙은 사람 세션·빈도·예외로 좁혀 폭증을 막습니다.</li>
<li>모든 룰은 wazuh-logtest·테스트 환경 검증 후 배포합니다(실습 예시 명시).</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;group name=&quot;local,syssec_c,recon,&quot;&gt;
  &lt;!-- 정상 백업 스크립트 세션 예외(좁게) --&gt;
  &lt;rule id=&quot;102460&quot; level=&quot;2&quot;&gt;
    &lt;if_sid&gt;102000,102440&lt;/if_sid&gt;
    &lt;field name=&quot;audit.auid&quot;&gt;^991$&lt;/field&gt;  &lt;!-- backup 계정 UID 예시 --&gt;
    &lt;description&gt;백업 계정의 정보 조회(정상) - 집계용&lt;/description&gt;
  &lt;/rule&gt;
&lt;/group&gt;</code></pre>
<p>예외는 계정·프로그램을 <strong>좁게</strong> 지정합니다(A영역 48편 원칙). 넓은 예외는 공격자가 그 계정을 악용하는 통로가 됩니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — recon 룰의 매칭·오탐·폭증을 wazuh-logtest·대시보드로 점검합니다.</li>
<li><strong>범위 확인</strong> — 상관 룰(102450)이 세션을 올바로 묶는지 검증합니다.</li>
<li><strong>증거 확보</strong> — 룰 파일(git)·검증 결과를 보존합니다.</li>
<li><strong>차단/조치</strong> — 오류 룰 수정·예외 튜닝 후 재배포합니다.</li>
<li><strong>재발 방지</strong> — 102000 대역 룰셋과 세션 상관을 운영 기준으로 둡니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>구분</th>
<th>핵심 내용</th>
</tr>
</thead>
<tbody><tr>
<td>ID 대역</td>
<td>C영역 102000~102999</td>
</tr>
<tr>
<td>파이프라인</td>
<td>auditd(recon_*) → Wazuh → 상관 Alert</td>
</tr>
<tr>
<td>핵심 룰</td>
<td>102450 세션 다영역 상관</td>
</tr>
<tr>
<td>주의</td>
<td>-p r 규칙 폭증 → 사람 세션·빈도로 제한</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;읽기 감사는 폭증하기 쉬워 세션·빈도로 좁히고 검증 후 배포&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c48">148. Linux 정보 수집 — ELK/SIEM 기반 정보 수집 탐지와 정탐·오탐 판단</a></strong> 에서는 ELK/SIEM 기반 탐지와 <strong>정탐·오탐 판단</strong>을 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c46">146. Linux 정보 수집 — Linux 정보 수집 행위의 이벤트 상관분석</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[146. Linux 정보 수집 — Linux 정보 수집 행위의 이벤트 상관분석]]></title>
            <link>https://velog.io/@cs_security/syssec-c46</link>
            <guid>https://velog.io/@cs_security/syssec-c46</guid>
            <pubDate>Thu, 01 Oct 2026 10:41:18 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>46/50편</strong> (전체 146/450)
학습 단계: SOC 탐지 연계
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c10">110. 시스템 정보 수집 종합 분석</a></li>
<li><a href="https://velog.io/@cs_security/syssec-c20">120. 네트워크 정보 수집 종합 분석</a></li>
<li><a href="https://velog.io/@cs_security/syssec-c30">130. 사용자·권한 정보 수집 종합 분석</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>정보 수집 탐지의 핵심은 <strong>개별 이벤트가 아니라 상관분석</strong>입니다. 조회 하나하나는 정상이지만, 같은 사용자·세션·출발지에서 여러 종류가 짧은 시간에 모이면 정찰입니다. 상관분석은 이 &quot;모임&quot;을 찾는 작업입니다.</p>
<pre><code class="language-text">상관 기준(correlation keys)
 user(auid)      → 누가
 source IP       → 어디서(로그인 출발지)
 timestamp       → 언제(시간 밀도)
 process/command → 무엇을(조회 종류)
 session(ses)    → 하나의 세션으로 묶기

상관 흐름
 개별 이벤트 → 세션(ses)으로 그룹 → 조회 종류·밀도 집계
   → 정상 기준선과 비교 → 정찰 판정</code></pre>
<p>C10·C20·C30·C40·C45의 영역별 세트를, 이 편에서 <strong>전 영역 통합 상관</strong>으로 묶습니다.</p>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>단일 이벤트 룰은 오탐이 많고(정상 명령), 미탐도 많습니다(느린 정찰). 상관분석이 정확도를 좌우합니다.</li>
<li>상관 기준(user·IP·time·process·session)을 표준화하면, 흩어진 조회를 재현성 있게 묶을 수 있습니다.</li>
<li>정상 기준선(관리자의 평소 조회 패턴)과 비교해야 &quot;많다/빠르다/이상하다&quot;를 판정할 수 있습니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<table>
<thead>
<tr>
<th>상관 기준</th>
<th>데이터</th>
<th>용도</th>
</tr>
</thead>
<tbody><tr>
<td>user</td>
<td>auid</td>
<td>행위자</td>
</tr>
<tr>
<td>source IP</td>
<td>USER_LOGIN addr</td>
<td>출발지(B영역)</td>
</tr>
<tr>
<td>timestamp</td>
<td>이벤트 시각</td>
<td>밀도</td>
</tr>
<tr>
<td>process</td>
<td>comm·exe</td>
<td>조회 종류</td>
</tr>
<tr>
<td>session</td>
<td>ses</td>
<td>그룹 키</td>
</tr>
<tr>
<td>기준선</td>
<td>평소 조회 패턴(C10·20·30)</td>
<td>비교</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># 세션 기준 전 영역 정찰 상관 (분석 방법)
SES=12
echo &quot;== 세션 $SES 정찰 상관 ==&quot;
# 1) 세션의 출발지·사용자
sudo ausearch -m USER_LOGIN --session $SES -i 2&gt;/dev/null | grep -oE &#39;acct=[^ ]+|addr=[^ ]+&#39; | sort -u
# 2) 조회 종류(key)별 건수
sudo ausearch --session $SES -k recon_sysinfo,recon_net,recon_account,recon_priv,recon_proc,recon_file,recon_log -i 2&gt;/dev/null | grep -oE &#39;key=&quot;[^&quot;]+&quot;&#39; | sort | uniq -c | sort -rn
# 3) 시간 밀도(첫~마지막 조회)
sudo ausearch --session $SES -i 2&gt;/dev/null | grep -oE &#39;[0-9]{2}:[0-9]{2}:[0-9]{2}&#39; | sort | sed -n &#39;1p;$p&#39;</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">== 세션 8 정찰 상관 ==
acct=admin1 addr=192.168.56.5
recon_sysinfo 2
(단일 영역, 소수, 업무 시간)</code></pre>
<p>관리자 세션은 단일 영역·소수 조회·관리망·업무 시간으로, 기준선 안에 있습니다(정상).</p>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">== 세션 12 정찰 상관 ==
acct=devops addr=192.168.56.77
  recon_sysinfo 7   recon_net 18   recon_account 8
  recon_priv 5      recon_proc 5   recon_file 9    recon_log 24
시간 밀도: 02:11:40 ~ 02:17:33 (약 6분)</code></pre>
<ul>
<li>한 세션에서 <strong>7개 영역 전부</strong>, 수십 건, 6분 집중 → 전방위 정찰 확정</li>
<li>비관리망·새벽·탈취 계정 → 모든 상관 기준이 기준선 이탈</li>
<li>시스템→네트워크→계정→프로세스→로그 순서 → 교과서적 정찰 흐름(C49 시나리오)</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>상관분석 결과를 한 화면으로 정리한 예시입니다(가상의 예시).</p>
<pre><code class="language-text">세션 12 (devops, 192.168.56.77, 02:11~02:17)
 영역      건수   대표 조회
 시스템    7     uname, os-release, cpuinfo
 네트워크  18    ip addr/route/neigh, ss
 계정      8     passwd, group, sudo -l
 프로세스  5     ps, pgrep wazuh
 파일      9     find id_rsa, cat .env
 로그      24    grep 자기IP secure
 → 전 영역 상관 = 전방위 정찰 (단일 영역이면 오탐 가능, 다영역이면 정탐)</code></pre>
<table>
<thead>
<tr>
<th>상관 지표</th>
<th>정상(ses 8)</th>
<th>정찰(ses 12)</th>
</tr>
</thead>
<tbody><tr>
<td>영역 수</td>
<td>1</td>
<td>7</td>
</tr>
<tr>
<td>출발지</td>
<td>관리망</td>
<td>비관리망</td>
</tr>
<tr>
<td>시간</td>
<td>업무</td>
<td>새벽</td>
</tr>
</tbody></table>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>정보 수집 탐지는 <strong>세션(ses) 기준 다영역 상관</strong>으로 판정합니다(단일 영역·단건은 오탐 가능).</li>
<li>상관 기준(user·IP·time·process·session)을 표준화해 재현성 있게 묶습니다.</li>
<li>정상 기준선(C10·20·30 평소 패턴)과 비교해 이탈을 판정합니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;group name=&quot;local,syssec_c,recon,&quot;&gt;
  &lt;!-- 한 세션에서 서로 다른 정찰 영역 키가 결합 --&gt;
  &lt;rule id=&quot;102450&quot; level=&quot;12&quot; frequency=&quot;10&quot; timeframe=&quot;300&quot;&gt;
    &lt;if_group&gt;audit&lt;/if_group&gt;
    &lt;field name=&quot;audit.key&quot; type=&quot;pcre2&quot;&gt;recon_(sysinfo|net|account|priv|proc|file|log)&lt;/field&gt;
    &lt;same_field field=&quot;audit.session&quot; /&gt;
    &lt;description&gt;단일 세션의 전방위 정보 수집(다영역 정찰 상관)&lt;/description&gt;
    &lt;mitre&gt;&lt;id&gt;T1082&lt;/id&gt;&lt;/mitre&gt;
  &lt;/rule&gt;
&lt;/group&gt;</code></pre>
<p><code>same_field</code>·다영역 조건은 버전 제약이 있으므로, 핵심 상관은 SIEM(148편)에서 <strong>세션별 distinct recon_key count</strong>로 구현합니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — 세션 기준으로 user·IP·time·조회 영역을 상관해 정찰을 판정합니다.</li>
<li><strong>범위 확인</strong> — 정찰 세션의 다음 단계(E·F·G영역) 전개를 추적합니다.</li>
<li><strong>증거 확보</strong> — 상관 결과(세션·영역·밀도)와 근거 로그를 보존합니다.</li>
<li><strong>차단/조치</strong> — 탈취·정찰 세션이면 B영역 대응과 다음 단계 차단을 진행합니다.</li>
<li><strong>재발 방지</strong> — 세션 기준 다영역 상관을 탐지 표준으로 운영합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>상관 기준</th>
<th>용도</th>
</tr>
</thead>
<tbody><tr>
<td>user(auid)</td>
<td>행위자</td>
</tr>
<tr>
<td>source IP</td>
<td>출발지(B영역)</td>
</tr>
<tr>
<td>timestamp</td>
<td>시간 밀도</td>
</tr>
<tr>
<td>process</td>
<td>조회 종류</td>
</tr>
<tr>
<td>session(ses)</td>
<td>그룹 키</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;단일 영역·단건은 오탐 — 세션 기준 다영역 상관이 정찰 판정의 핵심&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c47">147. Linux 정보 수집 — Wazuh 기반 Linux 정보 수집 탐지</a></strong> 에서는 상관분석을 자동화하는 <strong>Wazuh 기반 Linux 정보 수집 탐지</strong>를 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c45">145. Linux 정보 수집 — 설정 파일 접근 종합 분석</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[145. Linux 정보 수집 — 설정 파일 접근 종합 분석]]></title>
            <link>https://velog.io/@cs_security/syssec-c45</link>
            <guid>https://velog.io/@cs_security/syssec-c45</guid>
            <pubDate>Thu, 01 Oct 2026 10:41:18 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>45/50편</strong> (전체 145/450)
학습 단계: 로그·설정·환경 정보 수집
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c41">141. Linux 정보 수집 — 로그 파일 접근 흔적</a></li>
<li><a href="https://velog.io/@cs_security/syssec-c44">144. Linux 정보 수집 — 애플리케이션 로그 접근</a></li>
<li><a href="https://velog.io/@cs_security/llp-46-log-to-siem">46. 로그를 SIEM으로(llp)</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>로그·설정·환경 접근(C41~44, C09·C39)은 <strong>자격증명 수집</strong>과 <strong>흔적 확인(변조 선행)</strong> 두 목적으로 수렴합니다. 이 세트는 정찰의 마지막 단계이자, E영역(중요 정보 접근)·G영역(로그 변조)의 직접 선행입니다.</p>
<pre><code class="language-text">로그·설정·환경 접근 세트
 환경변수(C09) + 설정 파일(C39) → 자격증명 수집
 로그 접근(C41~44)             → 흔적 확인(변조 선행) + 추가 정보

정상 관리자 vs 침해 의심 계정
 관리자: 작업 맥락, 특정 로그, 쓰기(변경) 포함, 업무 시간
 침해:   자기 흔적 검색, 자격증명 파일 집중, 읽기 전용, 연속·새벽</code></pre>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>이 영역은 정찰의 종착점입니다: 자격증명을 모아 E영역(DB·중요 정보) 접근으로, 흔적을 파악해 G영역(로그 변조)으로 이어집니다.</li>
<li>관리자의 정상 로그/설정 접근과 침해 계정의 비정상 접근은 <strong>주체·패턴·목적</strong>으로 구분해야 오탐을 줄입니다.</li>
<li>llp 시리즈(로그 경로·SIEM)와 연결해, 로그 접근 정찰이 SIEM에서 어떻게 보이는지 정리합니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<p>정상 관리자 vs 침해 의심 계정 접근 비교:</p>
<table>
<thead>
<tr>
<th>항목</th>
<th>정상 관리자</th>
<th>침해 의심 계정</th>
</tr>
</thead>
<tbody><tr>
<td>로그 접근</td>
<td>특정 로그·작업 맥락</td>
<td>전수 조회·자기 IP 검색(C41·42)</td>
</tr>
<tr>
<td>설정 접근</td>
<td>변경 작업(쓰기)</td>
<td>자격증명 파일 읽기(C39)</td>
</tr>
<tr>
<td>환경 접근</td>
<td>자기 셸</td>
<td>타 프로세스 environ(C09)</td>
</tr>
<tr>
<td>시점</td>
<td>업무 시간·변경관리</td>
<td>새벽·연속·탈취 세션</td>
</tr>
<tr>
<td>목적</td>
<td>운영·장애 대응</td>
<td>자격증명 수집·흔적 확인</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># 로그·설정·환경 접근 세트의 세션별 집계 (분석 방법)
for ses in $(sudo ausearch -k recon_log,recon_file,recon_env,recon_environ -i --start today 2&gt;/dev/null | grep -oE &#39;ses=[0-9]+&#39; | sort -u | cut -d= -f2); do
  n=$(sudo ausearch --session $ses -k recon_log,recon_file,recon_env,recon_environ -i 2&gt;/dev/null | grep -cE &#39;type=SYSCALL&#39;)
  echo &quot;ses=$ses 로그설정접근=$n&quot;
done | sort -t= -k2 -rn | head</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">ses=8  로그설정접근=3  (admin1, 특정 로그 작업)</code></pre>
<p>관리자 세션은 특정 로그·설정을 작업 맥락에서 접근하고, 자격증명 파일·자기 흔적 검색이 없는 상태가 정상입니다.</p>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">ses=12 로그설정접근=24  (devops, 02:16~02:17)
 .env·my.cnf(자격증명) + secure·messages(자기 흔적) + access_log(토큰)</code></pre>
<ul>
<li>한 세션에서 자격증명 파일 + 로그 흔적 검색 <strong>다수 결합</strong> → 수집+변조 준비 종합</li>
<li>.env·토큰(자격증명) → E영역 접근 / secure·messages 자기 흔적 → G영역 변조</li>
<li>시스템·네트워크·계정·프로세스 정찰(C01~40)의 종착점</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>로그·설정 정찰 수렴 타임라인입니다(가상의 예시).</p>
<pre><code class="language-text">02:16:35 cat .env / my.cnf          (자격증명 수집, C39)
02:17:00 ls /var/log / grep 자기IP  (흔적 확인, C41)
02:17:10 grep admin1 secure         (패턴 학습, C42)
02:17:30 grep token access_log      (토큰 수집, C44)
 → 자격증명 수집(E영역) + 흔적 확인(G영역) 수렴</code></pre>
<table>
<thead>
<tr>
<th>수렴점</th>
<th>조회</th>
<th>다음 영역</th>
</tr>
</thead>
<tbody><tr>
<td>자격증명</td>
<td>설정·환경·토큰</td>
<td>E영역</td>
</tr>
<tr>
<td>흔적 확인</td>
<td>인증·시스템 로그</td>
<td>G영역</td>
</tr>
</tbody></table>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>로그·설정·환경 접근은 <strong>자격증명 수집·흔적 확인</strong> 두 목적으로 수렴합니다.</li>
<li>정상 관리자와 침해 계정을 주체·패턴·목적 비교표로 구분합니다.</li>
<li>이 세트 탐지 뒤 E영역(중요 정보 접근)·G영역(로그 변조)으로의 전개를 추적합니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;group name=&quot;local,syssec_c,recon,&quot;&gt;
  &lt;rule id=&quot;102440&quot; level=&quot;9&quot; frequency=&quot;5&quot; timeframe=&quot;180&quot;&gt;
    &lt;if_group&gt;audit&lt;/if_group&gt;
    &lt;field name=&quot;audit.key&quot; type=&quot;pcre2&quot;&gt;recon_(log|file|env|environ)&lt;/field&gt;
    &lt;same_field field=&quot;audit.session&quot; /&gt;
    &lt;description&gt;단일 세션의 다종 로그·설정·환경 접근(자격증명 수집·흔적 확인 정찰)&lt;/description&gt;
    &lt;mitre&gt;&lt;id&gt;T1552&lt;/id&gt;&lt;/mitre&gt;
  &lt;/rule&gt;
&lt;/group&gt;</code></pre>
<p><code>same_field</code> 미지원 시 SIEM 집계(146·148편)로 구현합니다. E·G영역 룰과 연계합니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — 로그·설정·환경 접근 세션의 목적(자격증명/흔적)·주체·패턴을 비교표로 확인합니다.</li>
<li><strong>범위 확인</strong> — 자격증명 수집 뒤 E영역 접근, 흔적 확인 뒤 G영역 변조가 이어졌는지 확인합니다.</li>
<li><strong>증거 확보</strong> — 세션 접근 흐름(원격 사본)을 보존합니다.</li>
<li><strong>차단/조치</strong> — 탈취 세션이면 B영역 대응과 자격증명 교체·로그 무결성 점검을 진행합니다.</li>
<li><strong>재발 방지</strong> — 로그·설정 접근을 E·G영역 상관에 포함합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>구분</th>
<th>핵심 내용</th>
</tr>
</thead>
<tbody><tr>
<td>세트</td>
<td>환경변수·설정·로그 접근</td>
</tr>
<tr>
<td>수렴점</td>
<td>자격증명 수집(E영역) · 흔적 확인(G영역)</td>
</tr>
<tr>
<td>구분</td>
<td>주체·패턴·목적 비교표</td>
</tr>
<tr>
<td>다음</td>
<td>중요 정보 접근(E) · 로그 변조(G)</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;로그/설정 접근은 자격증명 수집과 흔적 확인으로 수렴 — 정찰의 종착점&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c46">146. Linux 정보 수집 — Linux 정보 수집 행위의 이벤트 상관분석</a></strong> 에서는 6단계 SOC 탐지로 넘어가 <strong>Linux 정보 수집 행위의 이벤트 상관분석</strong>을 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c44">144. Linux 정보 수집 — 애플리케이션 로그 접근</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[144. Linux 정보 수집 — 애플리케이션 로그 접근]]></title>
            <link>https://velog.io/@cs_security/syssec-c44</link>
            <guid>https://velog.io/@cs_security/syssec-c44</guid>
            <pubDate>Thu, 01 Oct 2026 10:41:17 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>44/50편</strong> (전체 144/450)
학습 단계: 로그·설정·환경 정보 수집
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c43">143. Linux 정보 수집 — 시스템 로그 접근 분석</a></li>
<li><a href="https://velog.io/@cs_security/syssec-c39">39. 설정 파일 탐색 흔적</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>애플리케이션 로그(웹 access/error, DB, 앱 로그)는 시스템 로그보다 <strong>민감한 운영 데이터</strong>를 담기도 합니다: URL에 담긴 토큰·세션ID, 사용자 활동, 쿼리, 오류 스택(경로·버전). 공격자는 여기서 추가 자격증명·공격 표면을 수집합니다.</p>
<pre><code class="language-text">앱 로그 접근
 cat /var/log/httpd/access_log  → 요청 URL(토큰·파라미터)
 cat /var/log/httpd/error_log   → 오류(경로·스택·버전)
 cat /var/log/mysql/*.log       → DB 로그(쿼리·연결)
 앱 자체 로그(/var/www/.../logs) → 앱 활동·세션

위험: access_log의 URL 토큰·세션ID, error_log의 경로·버전 노출</code></pre>
<p>C39(설정 파일)가 &quot;설정의 자격증명&quot;이라면, 여기서는 &quot;로그에 흘러든 민감 데이터&quot;입니다. 웹 보안 영역(기존 웹 300편)과도 연결됩니다.</p>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>access_log의 URL에 토큰·세션ID·API 키가 GET 파라미터로 남으면(앱 취약점), 공격자가 그대로 탈취합니다.</li>
<li>error_log의 스택 트레이스는 내부 경로·프레임워크 버전·DB 구조를 드러내 추가 공격 표면이 됩니다.</li>
<li>앱 로그 접근은 서비스 계정(apache)·침입 계정이 하며, 자기 웹 공격 흔적 확인에도 쓰입니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>민감 정보</th>
</tr>
</thead>
<tbody><tr>
<td><code>access_log</code></td>
<td>URL 토큰·세션·파라미터</td>
</tr>
<tr>
<td><code>error_log</code></td>
<td>경로·스택·버전</td>
</tr>
<tr>
<td>DB 로그</td>
<td>쿼리·연결</td>
</tr>
<tr>
<td>앱 로그</td>
<td>세션·활동</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># 앱 로그 접근 감사 (실습 예시)
-w /var/log/httpd -p r -k recon_log
-w /var/log/nginx -p r -k recon_log
-w /var/log/mysql -p r -k recon_log

# 앱 로그 접근 패턴 (분석 방법)
sudo ausearch -k recon_log -i --start recent | grep -E &#39;access_log|error_log|mysql|httpd|nginx&#39; | tail</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">$ sudo ausearch -k recon_log -i --start today | grep access_log | tail -1
10:50:02 auid=admin1 ses=8 comm=&quot;tail&quot; name=&quot;/var/log/httpd/access_log&quot;  (트래픽 점검)</code></pre>
<p>관리자가 웹 트래픽·오류를 점검하는 것은 정상입니다. 공격자는 <strong>토큰·세션 검색, 서비스 계정의 로그 열람</strong>이 특징입니다.</p>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">02:17:30 auid=devops ses=12 comm=&quot;grep&quot; (token /var/log/httpd/access_log)
02:17:33 auid=devops ses=12 comm=&quot;cat&quot; name=&quot;/var/log/httpd/error_log&quot;</code></pre>
<ul>
<li>access_log에서 <code>token</code> 검색 → URL에 노출된 토큰·세션ID 탈취 시도</li>
<li>error_log 열람 → 내부 경로·버전·DB 구조 수집(추가 공격 표면)</li>
<li>설정(C39)·앱 로그(C44)에서 자격증명·토큰 수집 → E영역 접근 준비</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>앱 로그 정찰 흐름입니다(가상의 예시 로그 — 토큰 값은 가림).</p>
<pre><code class="language-text">type=EXECVE ... a0=&quot;grep&quot; a1=&quot;token&quot; a2=&quot;/var/log/httpd/access_log&quot;
type=SYSCALL ... auid=devops ses=12 comm=&quot;grep&quot; key=&quot;recon_log&quot;
[access_log 예시 - 민감값 마스킹]
192.168.56.50 - - [02/Oct/2026:01:00:00] &quot;GET /api?token=&lt;masked&gt; HTTP/1.1&quot; 200</code></pre>
<table>
<thead>
<tr>
<th>관찰</th>
<th>해석</th>
</tr>
</thead>
<tbody><tr>
<td>grep token access_log</td>
<td>토큰·세션 탈취</td>
</tr>
<tr>
<td>cat error_log</td>
<td>경로·버전 수집</td>
</tr>
<tr>
<td>서비스 계정 열람</td>
<td>비정상 접근</td>
</tr>
<tr>
<td>ses=12</td>
<td>앱 로그 정찰</td>
</tr>
</tbody></table>
<p>로그에서 토큰·세션을 다룰 때는 <strong>값을 마스킹</strong>해 분석하고, 보고서에 원문을 남기지 않습니다.</p>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>앱 로그 접근 중 <strong>토큰·세션·자격증명 검색</strong>을 정찰로 봅니다(값은 마스킹 분석).</li>
<li>URL에 토큰이 평문으로 남는 앱 설계 문제는 웹 보안 영역과 함께 시정합니다.</li>
<li>앱 로그에서 얻은 토큰·세션 악용(E영역·세션 재사용)을 연계 감시합니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;group name=&quot;local,syssec_c,recon,credential,&quot;&gt;
  &lt;rule id=&quot;102430&quot; level=&quot;8&quot;&gt;
    &lt;if_group&gt;audit&lt;/if_group&gt;
    &lt;field name=&quot;audit.key&quot;&gt;recon_log&lt;/field&gt;
    &lt;regex type=&quot;pcre2&quot;&gt;(access_log|error_log|/var/log/(httpd|nginx|mysql))&lt;/regex&gt;
    &lt;description&gt;애플리케이션 로그 접근(토큰·세션 수집 정찰)&lt;/description&gt;
    &lt;mitre&gt;&lt;id&gt;T1552.001&lt;/id&gt;&lt;/mitre&gt;
  &lt;/rule&gt;
&lt;/group&gt;</code></pre>
<p>앱 로그에서 토큰 검색은 자격증명 수집으로 분류하고, E영역·웹 보안 영역과 연계합니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — 앱 로그 접근의 대상(토큰·세션 검색)·주체를 확인합니다(값 마스킹).</li>
<li><strong>범위 확인</strong> — 노출 토큰·세션의 악용(E영역·세션 재사용)이 이어졌는지 확인합니다.</li>
<li><strong>증거 확보</strong> — 앱 로그 접근 흔적을 보존합니다(민감값 마스킹).</li>
<li><strong>차단/조치</strong> — 탈취 세션이면 B영역 대응과 노출 토큰·세션 무효화를 진행합니다.</li>
<li><strong>재발 방지</strong> — 앱 로그 토큰 검색을 자격증명 수집 상관에 포함합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>민감 정보</th>
</tr>
</thead>
<tbody><tr>
<td>access_log</td>
<td>URL 토큰·세션</td>
</tr>
<tr>
<td>error_log</td>
<td>경로·버전·스택</td>
</tr>
<tr>
<td>DB 로그</td>
<td>쿼리·연결</td>
</tr>
<tr>
<td>구분</td>
<td>트래픽 점검(정상) vs 토큰·세션 검색(정찰)</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;URL에 남은 토큰은 로그만 봐도 탈취 — 값은 마스킹해 분석&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c45">145. Linux 정보 수집 — 설정 파일 접근 종합 분석</a></strong> 에서는 5단계를 마무리하는 <strong>설정 파일 접근 종합 분석</strong>을 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c43">143. Linux 정보 수집 — 시스템 로그 접근 분석</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[143. Linux 정보 수집 — 시스템 로그 접근 분석]]></title>
            <link>https://velog.io/@cs_security/syssec-c43</link>
            <guid>https://velog.io/@cs_security/syssec-c43</guid>
            <pubDate>Thu, 01 Oct 2026 10:41:17 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>43/50편</strong> (전체 143/450)
학습 단계: 로그·설정·환경 정보 수집
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c42">142. Linux 정보 수집 — 인증 로그 접근 분석</a></li>
<li><a href="https://velog.io/@cs_security/llp-12-messages">12. messages 로그(llp)</a></li>
<li><a href="https://velog.io/@cs_security/llp-31-journald">31. journald(llp)</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>시스템 로그(<code>/var/log/messages</code>·<code>syslog</code>·journald)는 <strong>서비스 시작·오류·커널·cron 실행</strong> 등 시스템 전반의 기록입니다. 공격자는 여기서 시스템 활동을 학습하거나, 자신의 행위(서비스 등록·cron 실행)가 남긴 흔적을 확인합니다.</p>
<pre><code class="language-text">시스템 로그 접근
 cat/tail /var/log/messages  → 시스템 기록(Rocky)
 cat/tail /var/log/syslog    → 시스템 기록(Ubuntu)
 journalctl                  → systemd 저널(llp 31편)
 journalctl -u &lt;서비스&gt;      → 특정 서비스 로그
 grep &lt;자기행위&gt; messages    → 자기 흔적 확인

용도: 시스템 구조·오류 학습 / 자기 서비스·cron 등록 흔적 확인(G영역 선행)</code></pre>
<p>llp 12·31편이 시스템 로그·journald 분석(방어)이라면, 여기서는 공격자가 <strong>시스템 로그에 접근하는</strong> 정찰입니다.</p>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>시스템 로그로 공격자는 자기 지속성(서비스·cron 등록) 흔적이 어디 남았나 확인해, 삭제(G영역)나 회피를 준비합니다.</li>
<li>journald는 바이너리 저장이라 선별 삭제가 어렵지만, 설정 변경(A영역 28편 volatile)으로 무력화할 수 있어 공격자가 구조를 조회합니다.</li>
<li>오류 로그에서 서비스 취약점·경로 정보를 얻을 수도 있습니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>목적</th>
</tr>
</thead>
<tbody><tr>
<td><code>tail /var/log/messages</code>·<code>syslog</code></td>
<td>시스템 기록</td>
</tr>
<tr>
<td><code>journalctl</code></td>
<td>systemd 저널(llp 31편)</td>
</tr>
<tr>
<td><code>journalctl -u 서비스</code></td>
<td>특정 서비스</td>
</tr>
<tr>
<td><code>grep &lt;자기행위&gt;</code></td>
<td>흔적 확인</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># 시스템 로그 접근 감사 (실습 예시)
-w /var/log/messages -p r -k recon_log
-w /var/log/syslog -p r -k recon_log
-a always,exit -F arch=b64 -S execve -F path=/usr/bin/journalctl -F auid&gt;=1000 -F auid!=unset -k recon_log

# 시스템 로그 접근 패턴 (분석 방법)
sudo ausearch -k recon_log -i --start recent | grep -E &#39;messages|syslog|journalctl&#39; | tail</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">$ sudo ausearch -k recon_log -i --start today | grep messages | tail -1
10:40:02 auid=admin1 ses=8 comm=&quot;tail&quot; name=&quot;/var/log/messages&quot;  (장애 점검)</code></pre>
<p>관리자가 장애·서비스 로그를 점검하는 것은 정상입니다(llp 12편 분석). 공격자는 <strong>자기 행위 흔적 검색·전수 조회</strong>가 특징입니다.</p>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">02:17:20 auid=devops ses=12 comm=&quot;journalctl&quot; (-u 특정 서비스)
02:17:23 auid=devops ses=12 comm=&quot;grep&quot; (sysbak /var/log/messages)</code></pre>
<ul>
<li>journald로 자기 서비스 등록 로그 확인 + messages에서 자기 생성 계정(sysbak) 흔적 검색 → 흔적 확인</li>
<li>지속성(서비스·계정) 흔적이 어느 로그에 남았나 파악 → G영역 변조·회피 준비</li>
<li>인증 로그(C42)에 이어 시스템 로그까지 흔적 확인 → 로그 전반 삭제 범위 파악</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>시스템 로그 흔적 확인 흐름입니다(가상의 예시 로그).</p>
<pre><code class="language-text">type=EXECVE ... a0=&quot;journalctl&quot; a1=&quot;-u&quot; a2=&quot;dbus-update&quot;
type=SYSCALL ... auid=devops ses=12 comm=&quot;journalctl&quot; key=&quot;recon_log&quot;
type=EXECVE ... a0=&quot;grep&quot; a1=&quot;sysbak&quot; a2=&quot;/var/log/messages&quot;</code></pre>
<table>
<thead>
<tr>
<th>관찰</th>
<th>해석</th>
</tr>
</thead>
<tbody><tr>
<td>journalctl -u</td>
<td>자기 서비스 흔적</td>
</tr>
<tr>
<td>grep sysbak messages</td>
<td>자기 계정 흔적</td>
</tr>
<tr>
<td>전반 로그 검색</td>
<td>삭제 범위 파악</td>
</tr>
<tr>
<td>ses=12</td>
<td>시스템 로그 정찰</td>
</tr>
</tbody></table>
<p>흔적 확인 뒤 journald 설정 변경(A영역 28편)·로그 삭제(G영역)가 이어지는지 연계합니다.</p>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>시스템 로그 접근 중 <strong>자기 행위(계정·서비스) 흔적 검색</strong>을 변조 선행으로 봅니다.</li>
<li>journald 구조 조회 뒤 설정 변경(A영역 28편 volatile)이 이어지는지 확인합니다.</li>
<li>인증(C42)+시스템(C43) 로그 흔적 확인을 묶어 로그 변조 준비로 봅니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;group name=&quot;local,syssec_c,recon,&quot;&gt;
  &lt;rule id=&quot;102420&quot; level=&quot;7&quot;&gt;
    &lt;if_group&gt;audit&lt;/if_group&gt;
    &lt;field name=&quot;audit.key&quot;&gt;recon_log&lt;/field&gt;
    &lt;regex type=&quot;pcre2&quot;&gt;(messages|syslog)|a0=&quot;journalctl&quot;&lt;/regex&gt;
    &lt;description&gt;시스템 로그 접근(흔적 확인 정찰)&lt;/description&gt;
    &lt;mitre&gt;&lt;id&gt;T1070&lt;/id&gt;&lt;/mitre&gt;
  &lt;/rule&gt;
&lt;/group&gt;</code></pre>
<p>시스템 로그 접근은 G영역(로그 변조)·A영역 28편(journald)과 연계합니다. 원격 전송 로그로 탐지 신뢰도를 확보합니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — 시스템 로그 접근의 패턴(자기 흔적·전수)·주체를 확인합니다.</li>
<li><strong>범위 확인</strong> — 접근 뒤 journald 설정 변경·로그 삭제(A영역 28편·G영역)가 이어졌는지 확인합니다.</li>
<li><strong>증거 확보</strong> — 시스템 로그 접근 흔적(원격 사본)을 보존합니다.</li>
<li><strong>차단/조치</strong> — 탈취 세션이면 B영역 대응과 로그 무결성 점검을 진행합니다.</li>
<li><strong>재발 방지</strong> — 시스템 로그 접근을 변조 선행 상관에 포함합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>목적</th>
</tr>
</thead>
<tbody><tr>
<td>tail messages/syslog</td>
<td>시스템 기록</td>
</tr>
<tr>
<td>journalctl -u</td>
<td>서비스 로그</td>
</tr>
<tr>
<td>grep 자기행위</td>
<td>흔적 확인</td>
</tr>
<tr>
<td>구분</td>
<td>장애 점검(정상) vs 자기 흔적 검색(정찰)</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;시스템 로그 흔적 확인은 지속성 흔적 삭제 범위 파악&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c44">144. Linux 정보 수집 — 애플리케이션 로그 접근</a></strong> 에서는 애플리케이션 로그 접근인 <strong>애플리케이션 로그 접근</strong>을 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c42">142. Linux 정보 수집 — 인증 로그 접근 분석</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[142. Linux 정보 수집 — 인증 로그 접근 분석]]></title>
            <link>https://velog.io/@cs_security/syssec-c42</link>
            <guid>https://velog.io/@cs_security/syssec-c42</guid>
            <pubDate>Thu, 01 Oct 2026 10:41:16 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>42/50편</strong> (전체 142/450)
학습 단계: 로그·설정·환경 정보 수집
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c41">141. Linux 정보 수집 — 로그 파일 접근 흔적</a></li>
<li><a href="https://velog.io/@cs_security/llp-13-secure">13. secure 로그(llp)</a></li>
<li><a href="https://velog.io/@cs_security/llp-22-authlog">22. auth.log(llp)</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>인증 로그(<code>/var/log/secure</code>·<code>auth.log</code>)는 <strong>로그인 성공·실패·sudo·su</strong> 기록이 모인 곳입니다. 공격자에게 두 가치가 있습니다: ①다른 계정의 로그인 패턴 학습(C25 역이용 심화), ②자신의 인증 흔적 확인(삭제 대상, C41 심화).</p>
<pre><code class="language-text">인증 로그 접근
 cat/tail /var/log/secure   → 인증 기록(Rocky)
 cat/tail /var/log/auth.log → 인증 기록(Ubuntu)
 grep &lt;계정&gt; secure         → 특정 계정 로그인 패턴
 grep &lt;자기세션&gt; secure     → 자기 인증 흔적

용도: 정상 사용자 패턴 학습(위장) / 자기 로그인·sudo 흔적 확인(삭제)</code></pre>
<p>llp 13·22편이 인증 로그 분석(방어)이라면, 여기서는 공격자가 <strong>인증 로그에 접근하는</strong> 정찰입니다.</p>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>인증 로그로 공격자는 정상 로그인 패턴(시간·출발지)을 학습해 위장(B영역 27편 회피)하거나, 자기 흔적(돌파·sudo)을 확인해 삭제(G영역) 대상을 정합니다.</li>
<li>인증 로그는 사고 분석의 핵심 증거라, 공격자가 지우려는 1순위입니다. 접근·삭제 모두 주시합니다.</li>
<li>서비스 계정·비관리 계정의 인증 로그 열람은 거의 항상 비정상입니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>목적</th>
</tr>
</thead>
<tbody><tr>
<td><code>tail /var/log/secure</code></td>
<td>인증 기록 확인</td>
</tr>
<tr>
<td><code>grep &lt;계정&gt; secure</code></td>
<td>계정 로그인 패턴</td>
</tr>
<tr>
<td><code>grep &lt;자기IP&gt; secure</code></td>
<td>자기 흔적(C41)</td>
</tr>
<tr>
<td><code>/var/log/btmp</code>(실패)</td>
<td>실패 기록</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># 인증 로그 접근 감사 (실습 예시)
-w /var/log/secure -p r -k recon_log
-w /var/log/auth.log -p r -k recon_log
-w /var/log/btmp -p r -k recon_log

# 인증 로그 접근 패턴 (분석 방법)
sudo ausearch -k recon_log -i --start recent | grep -E &#39;secure|auth.log|btmp&#39; | tail</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">$ sudo ausearch -k recon_log -i --start today | grep secure | tail -1
10:30:02 auid=admin1 ses=8 comm=&quot;tail&quot; name=&quot;/var/log/secure&quot;  (인증 점검)</code></pre>
<p>관리자·보안 담당자가 인증 로그를 분석하는 것은 정상입니다(llp 13편 분석). 공격자는 <strong>자기 흔적 검색·비관리 계정 열람</strong>이 특징입니다.</p>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">02:17:10 auid=devops ses=12 comm=&quot;grep&quot; (admin1 /var/log/secure)
02:17:13 auid=devops ses=12 comm=&quot;grep&quot; (192.168.56.77 /var/log/secure)</code></pre>
<ul>
<li>admin1 로그인 패턴 검색(위장 준비, C25 심화) + 자기 출발지(.77) 검색(흔적 확인, C41 심화)</li>
<li>정상 사용자 패턴 학습 + 자기 흔적 파악 → 위장·삭제 준비 동시</li>
<li>인증 로그는 돌파(B영역 74편)·sudo 흔적을 담아, 공격자의 핵심 삭제 대상</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>인증 로그 접근 흐름입니다(가상의 예시 로그).</p>
<pre><code class="language-text">type=EXECVE ... a0=&quot;grep&quot; a1=&quot;admin1&quot; a2=&quot;/var/log/secure&quot;
type=SYSCALL ... auid=devops ses=12 comm=&quot;grep&quot; key=&quot;recon_log&quot;
type=EXECVE ... a0=&quot;grep&quot; a1=&quot;192.168.56.77&quot; a2=&quot;/var/log/secure&quot;</code></pre>
<table>
<thead>
<tr>
<th>관찰</th>
<th>해석</th>
</tr>
</thead>
<tbody><tr>
<td>grep admin1 secure</td>
<td>정상 패턴 학습(위장)</td>
</tr>
<tr>
<td>grep 자기IP secure</td>
<td>자기 흔적(삭제 대상)</td>
</tr>
<tr>
<td>비관리 계정 열람</td>
<td>비정상 접근</td>
</tr>
<tr>
<td>ses=12</td>
<td>인증 로그 정찰</td>
</tr>
</tbody></table>
<p>인증 로그 접근 뒤 위장 접속(B영역 27편)·로그 삭제(G영역)가 이어지는지 연계합니다.</p>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>인증 로그 접근 중 <strong>자기 흔적 검색·정상 패턴 학습</strong>을 정찰로 봅니다.</li>
<li>서비스·비관리 계정의 인증 로그 열람은 즉시 확인합니다.</li>
<li>인증 로그는 원격 전송(A영역 29편)으로 보존해 로컬 삭제(G영역)에 대비합니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;group name=&quot;local,syssec_c,recon,&quot;&gt;
  &lt;rule id=&quot;102410&quot; level=&quot;8&quot;&gt;
    &lt;if_group&gt;audit&lt;/if_group&gt;
    &lt;field name=&quot;audit.key&quot;&gt;recon_log&lt;/field&gt;
    &lt;regex type=&quot;pcre2&quot;&gt;(secure|auth\.log|btmp)&lt;/regex&gt;
    &lt;description&gt;인증 로그 접근(흔적 확인·패턴 학습 정찰)&lt;/description&gt;
    &lt;mitre&gt;&lt;id&gt;T1070&lt;/id&gt;&lt;/mitre&gt;
  &lt;/rule&gt;
&lt;/group&gt;</code></pre>
<p>인증 로그 접근은 G영역(로그 변조)·B영역 27편(이상 로그인)과 연계합니다. 원격 사본으로 탐지 신뢰도를 확보합니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — 인증 로그 접근의 패턴(자기 흔적·정상 패턴)·주체를 확인합니다.</li>
<li><strong>범위 확인</strong> — 접근 뒤 위장 접속(B영역)·로그 삭제(G영역)가 이어졌는지 원격 사본으로 확인합니다.</li>
<li><strong>증거 확보</strong> — 인증 로그 접근 흔적(원격 사본)을 보존합니다.</li>
<li><strong>차단/조치</strong> — 탈취 세션이면 B영역 대응과 인증 로그 무결성 점검을 진행합니다.</li>
<li><strong>재발 방지</strong> — 인증 로그 접근을 변조·이상로그인 상관에 포함합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>목적</th>
</tr>
</thead>
<tbody><tr>
<td>tail secure/auth.log</td>
<td>인증 기록</td>
</tr>
<tr>
<td>grep 계정</td>
<td>패턴 학습(위장)</td>
</tr>
<tr>
<td>grep 자기IP</td>
<td>흔적 확인(삭제)</td>
</tr>
<tr>
<td>구분</td>
<td>인증 분석(정상) vs 자기 흔적·비관리 계정 열람(정찰)</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;인증 로그는 위장 학습과 흔적 삭제의 양쪽 목적으로 노려진다&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c43">143. Linux 정보 수집 — 시스템 로그 접근 분석</a></strong> 에서는 시스템 로그 접근인 <strong>시스템 로그 접근 분석</strong>을 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c41">141. Linux 정보 수집 — 로그 파일 접근 흔적</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[141. Linux 정보 수집 — 로그 파일 접근 흔적]]></title>
            <link>https://velog.io/@cs_security/syssec-c41</link>
            <guid>https://velog.io/@cs_security/syssec-c41</guid>
            <pubDate>Thu, 01 Oct 2026 10:41:15 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>41/50편</strong> (전체 141/450)
학습 단계: 로그·설정·환경 정보 수집
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c40">140. Linux 정보 수집 — 프로세스·서비스·파일 정보 수집 종합 분석</a></li>
<li><a href="https://velog.io/@cs_security/linsec-41-log-structure">41. Linux 보안 로그 구조(linsec)</a></li>
<li><a href="https://velog.io/@cs_security/llp-03-var-log">03. /var/log(llp)</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>로그 파일 접근은 <strong>양면성</strong>을 가진 정찰입니다. 공격자는 로그에서 ①정보를 수집(다른 사용자 활동·내부 구조)하거나, ②<strong>자신의 흔적을 확인</strong>해 어떤 로그를 지울지 파악합니다(G영역 로그 변조의 선행).</p>
<pre><code class="language-text">로그 접근 (/var/log)
 ls /var/log/            → 어떤 로그가 있는가(G영역 삭제 대상 파악)
 cat/tail /var/log/*     → 로그 내용(정보 수집·흔적 확인)
 grep &lt;자기IP&gt; /var/log/* → 자기 흔적 검색(제거 대상 특정)

두 목적
 ① 정보 수집: 다른 사용자·시스템 활동 학습
 ② 흔적 확인: 자신의 로그인·행위가 어디 남았나 → G영역 삭제 준비</code></pre>
<p>llp 시리즈(로그 경로 정리)가 &quot;로그 구조·분석&quot;(방어)이라면, 여기서는 공격자가 <strong>로그에 접근하는</strong> 정찰입니다.</p>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>공격자가 <code>grep &lt;자기IP&gt; /var/log</code>로 자기 흔적을 찾으면, 이후 그 로그를 선별 삭제(G영역)하려 합니다. 흔적 확인은 로그 변조의 직접 선행입니다.</li>
<li>로그 디렉터리 전수 조회(<code>ls /var/log</code>)는 &quot;어떤 로그가 수집되는가&quot;를 파악해 삭제·회피 범위를 정합니다.</li>
<li>로그 접근 자체는 관리자도 하므로, <strong>자기 IP/계정 검색·전수 조회·삭제 선행</strong> 패턴으로 구분합니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>목적</th>
</tr>
</thead>
<tbody><tr>
<td><code>ls /var/log/</code></td>
<td>로그 종류 파악(삭제 범위)</td>
</tr>
<tr>
<td><code>tail/cat 로그</code></td>
<td>내용 수집·흔적 확인</td>
</tr>
<tr>
<td><code>grep &lt;자기IP&gt; 로그</code></td>
<td>자기 흔적 검색(G영역 선행)</td>
</tr>
<tr>
<td><code>/var/log/secure</code>·<code>auth.log</code></td>
<td>인증 흔적(C42)</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># 로그 접근 감사 (실습 예시)
-w /var/log -p r -k recon_log

# 자기 흔적 검색 패턴인지 (분석 방법)
sudo ausearch -k recon_log -i --start recent | grep &#39;/var/log&#39; | tail
sudo ausearch --session 12 -i 2&gt;/dev/null | grep -E &#39;comm=&quot;grep&quot;.*log|comm=&quot;ls&quot;.*log|/var/log&#39; | tail</code></pre>
<p><code>/var/log</code> 읽기는 관리자가 자주 하므로, 사람 세션의 <strong>전수 조회·grep 자기IP·삭제 선행</strong>으로 좁혀 봅니다(147편).</p>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">$ sudo ausearch -k recon_log -i --start today | grep &#39;/var/log&#39; | tail -1
10:00:02 auid=admin1 ses=8 comm=&quot;tail&quot; name=&quot;/var/log/messages&quot;  (로그 점검)</code></pre>
<p>관리자가 특정 로그를 점검·분석하는 것은 정상입니다(llp 시리즈 분석 작업). 차이는 <strong>자기 흔적 검색·전수 조회</strong>입니다.</p>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">02:17:00 auid=devops ses=12 comm=&quot;ls&quot; name=&quot;/var/log/&quot;
02:17:03 auid=devops ses=12 comm=&quot;grep&quot; (192.168.56.77 /var/log/secure)
02:17:05 auid=devops ses=12 comm=&quot;grep&quot; (devops /var/log/*)</code></pre>
<ul>
<li>로그 디렉터리 전수 조회 + <strong>자기 IP·계정으로 로그 검색</strong> → 흔적 확인(삭제 대상 특정)</li>
<li>자기 흔적이 어느 로그에 남았나 파악 → G영역 로그 변조 준비</li>
<li>정찰 마무리 단계에서 &quot;내 흔적 지우기&quot; 준비로 이어짐</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>로그 흔적 확인 → 변조 준비 흐름입니다(가상의 예시 로그).</p>
<pre><code class="language-text">type=EXECVE ... a0=&quot;grep&quot; a1=&quot;192.168.56.77&quot; a2=&quot;/var/log/secure&quot;
type=SYSCALL ... auid=devops ses=12 comm=&quot;grep&quot; key=&quot;recon_log&quot;
[이후 가능] /var/log/secure 선별 삭제·변조 (G영역)</code></pre>
<table>
<thead>
<tr>
<th>관찰</th>
<th>해석</th>
</tr>
</thead>
<tbody><tr>
<td>ls /var/log</td>
<td>로그 종류(삭제 범위)</td>
</tr>
<tr>
<td>grep 자기IP</td>
<td>흔적 위치 확인</td>
</tr>
<tr>
<td>grep 자기계정</td>
<td>흔적 범위 파악</td>
</tr>
<tr>
<td>이후 변조</td>
<td>G영역 로그 변조</td>
</tr>
</tbody></table>
<p>로그 흔적 확인 직후 로그 삭제·크기 변화(G영역)가 나타나는지 연계합니다.</p>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>로그 접근 중 <strong>자기 IP/계정 검색·전수 조회</strong>를 흔적 확인(변조 선행)으로 봅니다.</li>
<li>흔적 확인 직후 로그 삭제·변조(G영역)가 이어지는지 연계 감시합니다.</li>
<li>로그 접근은 원격 전송 로그(A영역 29편)로 교차 확인해, 로컬 변조에 대비합니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;group name=&quot;local,syssec_c,recon,&quot;&gt;
  &lt;rule id=&quot;102400&quot; level=&quot;8&quot;&gt;
    &lt;if_group&gt;audit&lt;/if_group&gt;
    &lt;field name=&quot;audit.key&quot;&gt;recon_log&lt;/field&gt;
    &lt;regex type=&quot;pcre2&quot;&gt;a0=&quot;grep&quot;.*(/var/log|secure|auth\.log)&lt;/regex&gt;
    &lt;description&gt;로그 파일에서 특정 IP/계정 검색(흔적 확인·변조 선행)&lt;/description&gt;
    &lt;mitre&gt;&lt;id&gt;T1070&lt;/id&gt;&lt;/mitre&gt;
  &lt;/rule&gt;
&lt;/group&gt;</code></pre>
<p><code>T1070</code>(Indicator Removal) 계열. 로그 흔적 확인은 G영역(로그 변조) 룰과 연계합니다. 로컬 로그는 지워질 수 있으므로 <strong>원격 사본</strong>(A영역 29편)으로 탐지합니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — 로그 접근의 패턴(자기IP·전수 조회)·주체와 대상 로그를 확인합니다.</li>
<li><strong>범위 확인</strong> — 흔적 확인 직후 로그 삭제·변조(G영역)가 이어졌는지 원격 사본으로 확인합니다.</li>
<li><strong>증거 확보</strong> — 로그 접근 흔적(원격 사본 포함)을 보존합니다.</li>
<li><strong>차단/조치</strong> — 탈취 세션이면 B영역 대응과 로그 무결성 점검을 진행합니다.</li>
<li><strong>재발 방지</strong> — 로그 흔적 확인을 변조 선행 상관(G영역)에 포함합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>목적</th>
</tr>
</thead>
<tbody><tr>
<td>ls /var/log</td>
<td>로그 종류(삭제 범위)</td>
</tr>
<tr>
<td>grep 자기IP/계정</td>
<td>흔적 확인(G영역 선행)</td>
</tr>
<tr>
<td>tail/cat</td>
<td>정보 수집</td>
</tr>
<tr>
<td>구분</td>
<td>로그 점검(정상) vs 자기 흔적 검색·전수 조회(정찰)</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;로그에서 자기 IP 검색은 지울 흔적을 특정하는 변조 선행&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c42">142. Linux 정보 수집 — 인증 로그 접근 분석</a></strong> 에서는 인증 흔적 확인인 <strong>인증 로그 접근 분석</strong>을 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c40">140. Linux 정보 수집 — 프로세스·서비스·파일 정보 수집 종합 분석</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[140. Linux 정보 수집 — 프로세스·서비스·파일 정보 수집 종합 분석]]></title>
            <link>https://velog.io/@cs_security/syssec-c40</link>
            <guid>https://velog.io/@cs_security/syssec-c40</guid>
            <pubDate>Thu, 01 Oct 2026 10:33:58 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>40/50편</strong> (전체 140/450)
학습 단계: 프로세스·서비스·파일 정보 수집
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c31">131. Linux 정보 수집 — 프로세스 목록 조회 흔적</a></li>
<li><a href="https://velog.io/@cs_security/syssec-c39">139. Linux 정보 수집 — 설정 파일 탐색 흔적</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>프로세스·서비스·파일 정찰(C31~39)은 &quot;무엇이 돌고, 무엇이 등록됐고, 어떤 파일이 있는가&quot;를 파악해 <strong>지속성 등록·탈취 대상·탐지 회피</strong>를 준비하는 단계입니다. 이 영역의 핵심은 <strong>정상 운영 명령과 의심 연속 조회의 구분</strong>입니다.</p>
<pre><code class="language-text">프로세스·서비스·파일 정찰 세트 (한 세션)
 프로세스(C31·32) → 도구(C33) → 서비스(C34·35) → cron(C36)
   → 파일 탐색(C37) → 중요 파일(C38) → 설정(C39)

수렴점
 - 지속성 준비: systemd(C35)·cron(C36) 등록 위치
 - 탈취 준비: 중요 파일(C38)·설정 자격증명(C39)
 - 회피 준비: 보안 솔루션(C31·34)</code></pre>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>이 영역의 명령(ps·systemctl·find·cat)은 <strong>관리자가 매일 쓰는 것</strong>이라, 단건 탐지는 오탐투성이입니다. 연속·대상·맥락으로 구분해야 합니다.</li>
<li>세트로 보면 지속성·탈취·회피 준비가 한 세션에 수렴하는 것이 드러납니다.</li>
<li>정상 운영과 정찰의 경계를 표로 정리해 두면 판단이 일관됩니다(문제 지문의 비교표).</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<p>정상 운영 vs 의심 연속 조회 비교(문제 지문 기반 확장):</p>
<table>
<thead>
<tr>
<th>구분</th>
<th>정상적인 관리</th>
<th>의심 가능한 패턴</th>
</tr>
</thead>
<tbody><tr>
<td>프로세스 조회</td>
<td>정기 점검·부하 확인</td>
<td>짧은 시간 반복, 보안 솔루션 조준(C31)</td>
</tr>
<tr>
<td>서비스 조회</td>
<td>장애 대응</td>
<td>전수+보안 서비스 연속(C34), systemd 구조 학습(C35)</td>
</tr>
<tr>
<td>파일 조회</td>
<td>특정 작업 디렉터리</td>
<td>전체 파일시스템·민감 패턴 탐색(C37·38)</td>
</tr>
<tr>
<td>설정 조회</td>
<td>변경 작업(쓰기)</td>
<td>자격증명 파일 읽기, 인증·네트워크와 연속(C39)</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># 프로세스·서비스·파일 정찰 세트의 세션별 조회 종류 집계 (분석 방법)
for ses in $(sudo ausearch -k recon_proc,recon_svc,recon_file,recon_tool,recon_persist -i --start today 2&gt;/dev/null | grep -oE &#39;ses=[0-9]+&#39; | sort -u | cut -d= -f2); do
  n=$(sudo ausearch --session $ses -k recon_proc,recon_svc,recon_file,recon_tool,recon_persist -i 2&gt;/dev/null | grep -oE &#39;key=&quot;[^&quot;]+&quot;&#39; | sort -u | wc -l)
  echo &quot;ses=$ses 정찰키종류=$n&quot;
done | sort -t= -k2 -rn | head</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">ses=8  정찰키종류=1  (admin1, 특정 작업)</code></pre>
<p>관리자 세션은 특정 작업 맥락의 단일 종류 조회에 그치고, 보안 솔루션 조준·전체 탐색이 없는 상태가 정상입니다.</p>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">ses=12 정찰키종류=5  (devops, 02:15~02:16)
 recon_proc(보안솔루션) + recon_svc(systemd) + recon_persist(cron) + recon_file(민감파일) + recon_tool(LOLBins)</code></pre>
<ul>
<li>한 세션에서 프로세스·서비스·cron·파일·도구 <strong>5종 정찰 결합</strong> → 지속성+탈취+회피 준비 종합</li>
<li>보안 솔루션 조준(C31) + systemd/cron 조회(C35·36) + 민감 파일(C38) → 다음 단계(F영역 지속성·E영역 탈취) 임박</li>
<li>시스템(C10)·네트워크(C20)·계정(C30) 정찰에 이어 4단계 정찰 완료</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>프로세스·파일 정찰 세트 타임라인입니다(가상의 예시).</p>
<pre><code class="language-text">02:15:10 ps aux / pgrep wazuh   (프로세스·보안솔루션, C31)
02:15:40 systemctl list/status  (서비스, C34·35)
02:16:00 crontab -l / cron.d    (cron, C36)
02:16:10 find / -name id_rsa    (민감 파일, C37·38)
02:16:35 cat .env / my.cnf      (설정 자격증명, C39)
 → 1분 반 내 5종, 한 세션 = 지속성+탈취+회피 준비 정찰</code></pre>
<table>
<thead>
<tr>
<th>수렴점</th>
<th>조회</th>
</tr>
</thead>
<tbody><tr>
<td>회피</td>
<td>보안 솔루션(C31·34)</td>
</tr>
<tr>
<td>지속성</td>
<td>systemd·cron(C35·36)</td>
</tr>
<tr>
<td>탈취</td>
<td>중요 파일·설정(C38·39)</td>
</tr>
</tbody></table>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>프로세스·서비스·파일 정찰은 <strong>세션 내 조회 키 종류·대상</strong>으로 판정합니다(개별 명령 아님).</li>
<li>보안 솔루션 조준·systemd/cron 조회·자격증명 파일 열람이 결합되면 다음 단계(E·F영역) 임박입니다.</li>
<li>정상/의심 비교표를 판단 기준으로 운영합니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;group name=&quot;local,syssec_c,recon,&quot;&gt;
  &lt;rule id=&quot;102390&quot; level=&quot;10&quot; frequency=&quot;5&quot; timeframe=&quot;180&quot;&gt;
    &lt;if_group&gt;audit&lt;/if_group&gt;
    &lt;field name=&quot;audit.key&quot; type=&quot;pcre2&quot;&gt;recon_(proc|svc|file|tool|persist)&lt;/field&gt;
    &lt;same_field field=&quot;audit.session&quot; /&gt;
    &lt;description&gt;단일 세션의 다종 프로세스·서비스·파일 정보 수집(정찰 세트)&lt;/description&gt;
    &lt;mitre&gt;&lt;id&gt;T1057&lt;/id&gt;&lt;/mitre&gt;
  &lt;/rule&gt;
&lt;/group&gt;</code></pre>
<p><code>same_field</code> 미지원 시 SIEM 집계로 구현합니다(146·148편). E·F영역 룰과 연계합니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — 프로세스·파일 정찰 세션의 조회 키 종류·대상·주체를 확인합니다.</li>
<li><strong>범위 확인</strong> — 지속성(F영역)·탈취(E영역)·회피(A영역 39편)로 이어졌는지 확인합니다.</li>
<li><strong>증거 확보</strong> — 세션 조회 흐름과 비교표 기반 판정을 보존합니다.</li>
<li><strong>차단/조치</strong> — 탈취·지속성 세션이면 E·F영역 대응과 연계합니다.</li>
<li><strong>재발 방지</strong> — 프로세스·파일 정찰 세트 탐지를 운영 기준으로 둡니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>구분</th>
<th>핵심 내용</th>
</tr>
</thead>
<tbody><tr>
<td>세트</td>
<td>프로세스·도구·서비스·cron·파일·설정</td>
</tr>
<tr>
<td>수렴점</td>
<td>회피(보안솔루션)·지속성(systemd/cron)·탈취(파일/설정)</td>
</tr>
<tr>
<td>판정</td>
<td>세션 내 조회 키 종류·대상 + 비교표</td>
</tr>
<tr>
<td>다음</td>
<td>탈취(E영역)·지속성(F영역)·회피(A영역 39편)</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;매일 쓰는 명령이라 단건은 오탐 — 연속·대상·맥락으로 구분&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c41">141. Linux 정보 수집 — 로그 파일 접근 흔적</a></strong> 에서는 5단계로 넘어가 <strong>로그 파일 접근 흔적</strong>을 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c39">139. Linux 정보 수집 — 설정 파일 탐색 흔적</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[139. Linux 정보 수집 — 설정 파일 탐색 흔적]]></title>
            <link>https://velog.io/@cs_security/syssec-c39</link>
            <guid>https://velog.io/@cs_security/syssec-c39</guid>
            <pubDate>Thu, 01 Oct 2026 10:33:57 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>39/50편</strong> (전체 139/450)
학습 단계: 프로세스·서비스·파일 정보 수집
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c38">138. Linux 정보 수집 — 중요 파일 존재 여부 확인</a></li>
<li><a href="https://velog.io/@cs_security/syssec-a21">21. /etc 디렉터리 변경 관리(A영역)</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>설정 파일은 <strong>자격증명·연결 정보·경로</strong>가 모여 있는 고가치 대상입니다. 웹 서버 설정, DB 설정, 앱 config(.env·yml)에는 DB 비밀번호·API 키·백엔드 주소가 담겨 있어, 공격자가 집중 조회합니다.</p>
<pre><code class="language-text">설정 파일 탐색·열람
 cat /etc/httpd/conf/*    → 웹 서버 설정(경로·가상호스트)
 cat /etc/my.cnf          → DB 설정
 cat /var/www/html/.env   → 앱 자격증명(DB_PASSWORD 등)
 cat application.yml      → 앱 설정

위험: 설정 내 평문 자격증명 → 추가 인증 없이 DB·API 접근(E영역)</code></pre>
<p>문제 지문의 비교: 설정 조회가 <strong>인증·네트워크 정보와 연속</strong>되면(계정→네트워크→설정) 정찰의 종합 단계입니다. A영역 21편(/etc 변경 관리)이 변경 탐지라면, 여기서는 설정 <strong>열람</strong> 정찰입니다.</p>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>설정 파일의 평문 자격증명은 <strong>추가 인증 없이</strong> DB·API·백엔드 접근을 가능하게 합니다(C09 환경변수와 함께 자격증명 수집의 핵심).</li>
<li>웹 설정의 가상호스트·경로는 추가 공격 표면(숨은 앱·관리 페이지)을 드러냅니다.</li>
<li>설정 조회가 계정(C21<del>)·네트워크(C11</del>) 정찰과 연속되면, 정찰이 자격증명 수집으로 수렴하는 신호입니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td>웹 설정(<code>httpd.conf</code>·<code>nginx.conf</code>)</td>
<td>경로·가상호스트</td>
</tr>
<tr>
<td>DB 설정(<code>my.cnf</code>·<code>postgresql.conf</code>)</td>
<td>연결·경로</td>
</tr>
<tr>
<td>앱 config(<code>.env</code>·<code>*.yml</code>)</td>
<td>자격증명</td>
</tr>
<tr>
<td>인증 설정(<code>sshd_config</code>)</td>
<td>인증 방식(A영역 09편)</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># 설정 파일 열람 감사 (실습 예시)
-w /var/www -p r -k recon_file
-w /etc/my.cnf -p r -k recon_file
-w /etc/httpd -p r -k recon_file

# 설정 조회가 계정·네트워크 정보와 연속됐는지 (분석 방법)
sudo ausearch -k recon_file -i --start recent | grep -E &#39;conf|\.env|\.yml|my.cnf&#39; | tail
sudo ausearch --session 12 -i 2&gt;/dev/null | grep -E &#39;passwd|resolv|httpd|\.env|my.cnf&#39; | tail</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">$ sudo ausearch -k recon_file -i --start today | grep httpd | tail -1
11:20:02 auid=admin1 ses=8 comm=&quot;vi&quot; name=&quot;/etc/httpd/conf.d/ssl.conf&quot;  (설정 작업)</code></pre>
<p>관리자가 설정을 작업·점검하는 것은 정상입니다(변경관리와 일치). 공격자는 <strong>읽기만·연속·자격증명 파일 집중</strong>이 특징입니다.</p>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">02:16:35 auid=devops ses=12 comm=&quot;cat&quot; name=&quot;/var/www/html/.env&quot;
02:16:37 auid=devops ses=12 comm=&quot;cat&quot; name=&quot;/etc/my.cnf&quot;
02:16:40 auid=devops ses=12 comm=&quot;cat&quot; name=&quot;/etc/httpd/conf/httpd.conf&quot;</code></pre>
<ul>
<li>.env(자격증명) + my.cnf(DB) + httpd.conf(웹) 연속 열람 → 자격증명·구성 수집</li>
<li>.env의 DB_PASSWORD 확보 → 내부 DB 접근(C18 연결 정찰과 결합, E영역)</li>
<li>계정(C21<del>)·네트워크(C11</del>)·설정(C39) 연속 → 정찰이 자격증명 수집으로 수렴</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>설정 파일 정찰 흐름입니다(가상의 예시 로그).</p>
<pre><code class="language-text">type=PATH ... name=&quot;/var/www/html/.env&quot; nametype=NORMAL
type=SYSCALL ... auid=devops ses=12 comm=&quot;cat&quot; key=&quot;recon_file&quot;
type=PATH ... name=&quot;/etc/my.cnf&quot;</code></pre>
<table>
<thead>
<tr>
<th>관찰</th>
<th>해석</th>
</tr>
</thead>
<tbody><tr>
<td>cat .env</td>
<td>앱 자격증명</td>
</tr>
<tr>
<td>cat my.cnf</td>
<td>DB 설정</td>
</tr>
<tr>
<td>cat httpd.conf</td>
<td>웹 구성</td>
</tr>
<tr>
<td>연속 열람</td>
<td>자격증명 수집</td>
</tr>
</tbody></table>
<p>설정에서 얻은 자격증명으로 DB·API 접근(E영역)이 이어지는지 연계합니다.</p>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>설정 파일 <strong>읽기 전용·연속·자격증명 파일 집중</strong>을 정찰로 봅니다(작업=쓰기와 구분).</li>
<li>.env·my.cnf 등 자격증명 포함 설정 열람은 C09(환경변수)와 함께 자격증명 수집으로 봅니다.</li>
<li>설정 조회가 계정·네트워크 정찰과 연속되면 정찰 수렴 단계로 판정합니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;group name=&quot;local,syssec_c,recon,credential,&quot;&gt;
  &lt;rule id=&quot;102380&quot; level=&quot;9&quot;&gt;
    &lt;if_group&gt;audit&lt;/if_group&gt;
    &lt;field name=&quot;audit.key&quot;&gt;recon_file&lt;/field&gt;
    &lt;regex type=&quot;pcre2&quot;&gt;\.env|my\.cnf|application\.(yml|properties)|credentials&lt;/regex&gt;
    &lt;description&gt;자격증명 포함 설정 파일 열람(자격증명 수집 정찰)&lt;/description&gt;
    &lt;mitre&gt;&lt;id&gt;T1552.001&lt;/id&gt;&lt;/mitre&gt;
  &lt;/rule&gt;
&lt;/group&gt;</code></pre>
<p><code>T1552.001</code>(Credentials In Files)에 매핑됩니다. 설정 열람 + DB 접근(E영역)을 상관하면 자격증명 수집→악용을 포착합니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — 설정 조회의 대상(자격증명 파일 포함)·연속성·주체를 확인합니다.</li>
<li><strong>범위 확인</strong> — 설정에서 얻은 자격증명으로 DB·API 접근(E영역)이 이어졌는지 확인합니다.</li>
<li><strong>증거 확보</strong> — 세션 조회 흐름과 열람 설정 목록을 보존합니다.</li>
<li><strong>차단/조치</strong> — 탈취 세션이면 B영역 대응과 노출 자격증명 교체를 진행합니다.</li>
<li><strong>재발 방지</strong> — 설정 파일 열람을 자격증명 수집 상관에 포함합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td>웹/DB 설정</td>
<td>경로·연결</td>
</tr>
<tr>
<td>.env/yml</td>
<td>평문 자격증명</td>
</tr>
<tr>
<td>sshd_config</td>
<td>인증 방식</td>
</tr>
<tr>
<td>구분</td>
<td>설정 작업(쓰기, 정상) vs 자격증명 파일 연속 열람(정찰)</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;설정 파일 평문 자격증명은 추가 인증 없는 DB·API 접근의 열쇠&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c40">140. Linux 정보 수집 — 프로세스·서비스·파일 정보 수집 종합 분석</a></strong> 에서는 4단계를 마무리하는 <strong>프로세스·서비스·파일 정보 수집 종합 분석</strong>을 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c38">138. Linux 정보 수집 — 중요 파일 존재 여부 확인</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[138. Linux 정보 수집 — 중요 파일 존재 여부 확인]]></title>
            <link>https://velog.io/@cs_security/syssec-c38</link>
            <guid>https://velog.io/@cs_security/syssec-c38</guid>
            <pubDate>Thu, 01 Oct 2026 10:33:57 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>38/50편</strong> (전체 138/450)
학습 단계: 프로세스·서비스·파일 정보 수집
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c37">137. Linux 정보 수집 — 파일·디렉터리 구조 탐색 흔적</a></li>
<li><a href="https://velog.io/@cs_security/linsec-25-critical-files">25. 중요 파일 권한 점검(linsec)</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>광범위 탐색(C37) 다음은 <strong>특정 중요 파일의 존재·속성 확인</strong>입니다. 공격자는 SSH 키·백업·DB 덤프·인증서 같은 고가치 파일이 <strong>실제로 있고, 읽을 수 있는지</strong> 확인해 탈취 대상을 특정합니다.</p>
<pre><code class="language-text">중요 파일 존재·속성 확인
 ls -l /path/to/key      → 존재·권한·소유자
 stat 파일               → 상세 속성(시각·inode)
 test -f 파일 &amp;&amp; echo    → 존재 여부(스크립트)
 head -c 0 파일          → 읽기 가능 여부 확인

대상: ~/.ssh/id_rsa, *.pem, DB 덤프, backup.tar, .env, credentials</code></pre>
<p>C37이 &quot;광범위 탐색(무엇이 있나)&quot;이라면, 이 편은 &quot;특정 고가치 파일 확인(이게 있나, 읽을 수 있나)&quot;입니다. E영역(중요 정보 접근)의 직접 선행입니다.</p>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>중요 파일 존재·권한 확인은 <strong>탈취 대상 특정</strong>입니다. 읽기 가능하면 바로 접근(E영역)으로 이어집니다.</li>
<li>존재만 확인하고 접근은 나중에 하는 경우, 이 확인 단계가 조기 탐지 기회입니다.</li>
<li>특정 고가치 파일(키·.env·덤프)을 콕 집어 확인하는 것은 명확한 목표를 드러냅니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td><code>ls -l 파일</code></td>
<td>존재·권한·소유자</td>
</tr>
<tr>
<td><code>stat 파일</code></td>
<td>상세 속성</td>
</tr>
<tr>
<td><code>test -f</code>/<code>[ -f ]</code></td>
<td>존재 여부</td>
</tr>
<tr>
<td>대상</td>
<td>id_rsa·.pem·.env·덤프·백업</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># 중요 파일 접근 감사 (실습 예시) — 고가치 파일 읽기/속성 확인
-w /root/.ssh -p r -k recon_file
-a always,exit -F arch=b64 -S execve -F path=/usr/bin/stat -F auid&gt;=1000 -F auid!=unset -k recon_file

# 고가치 파일 대상 확인인지 (분석 방법)
sudo ausearch -k recon_file -i --start recent | grep -E &#39;id_rsa|\.pem|\.env|backup|dump|stat&#39; | tail</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">$ sudo ausearch -k recon_file -i --start today | grep stat | tail -1
11:10:02 auid=admin1 ses=8 comm=&quot;stat&quot; (대상 /etc/httpd/conf/httpd.conf)  (설정 점검)</code></pre>
<p>관리자가 특정 설정 파일 속성을 확인하는 단발 조회는 정상입니다. 고가치 파일(키·덤프)을 콕 집어 확인하는 것이 이상 신호입니다.</p>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">02:16:25 auid=devops ses=12 comm=&quot;ls&quot; (대상 /home/admin1/.ssh/id_rsa)
02:16:27 auid=devops ses=12 comm=&quot;stat&quot; (대상 /var/backup/db_dump.sql)
02:16:29 auid=devops ses=12 comm=&quot;ls&quot; (대상 /var/www/html/.env)</code></pre>
<ul>
<li>SSH 키 + DB 덤프 + .env(자격증명) 존재·권한 확인 → 탈취 대상 특정</li>
<li>읽기 가능 여부 확인 → 바로 접근(E영역) 또는 권한 상승 후 접근 판단</li>
<li>광범위 탐색(C37)으로 찾은 파일을 콕 집어 확인 → 표적 확정</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>중요 파일 확인 → 탈취 준비 흐름입니다(가상의 예시 로그).</p>
<pre><code class="language-text">type=EXECVE ... a0=&quot;ls&quot; a1=&quot;-l&quot; a2=&quot;/home/admin1/.ssh/id_rsa&quot;
type=SYSCALL ... auid=devops ses=12 comm=&quot;ls&quot; key=&quot;recon_file&quot;
type=EXECVE ... a0=&quot;stat&quot; a1=&quot;/var/backup/db_dump.sql&quot;</code></pre>
<table>
<thead>
<tr>
<th>관찰</th>
<th>해석</th>
</tr>
</thead>
<tbody><tr>
<td>ls id_rsa</td>
<td>SSH 키 존재·권한</td>
</tr>
<tr>
<td>stat db_dump.sql</td>
<td>백업 데이터 확인</td>
</tr>
<tr>
<td>ls .env</td>
<td>자격증명 파일</td>
</tr>
<tr>
<td>ses=12</td>
<td>표적 확인 정찰</td>
</tr>
</tbody></table>
<p>확인된 파일에 대한 실제 접근(E영역 중요 정보 접근)이 이어지는지 연계합니다.</p>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>고가치 파일(키·덤프·.env)의 존재·권한 확인을 <strong>탈취 대상 특정</strong>으로 봅니다.</li>
<li>확인 뒤 실제 접근(E영역)·복사·유출이 이어지는지 연계 감시합니다.</li>
<li>광범위 탐색(C37)+표적 확인(C38)이 결합되면 데이터 탈취 임박으로 봅니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;group name=&quot;local,syssec_c,recon,&quot;&gt;
  &lt;rule id=&quot;102370&quot; level=&quot;9&quot;&gt;
    &lt;if_group&gt;audit&lt;/if_group&gt;
    &lt;field name=&quot;audit.key&quot;&gt;recon_file&lt;/field&gt;
    &lt;regex type=&quot;pcre2&quot;&gt;(id_rsa|\.pem|\.key|\.env|db_dump|backup\.|credentials)&lt;/regex&gt;
    &lt;description&gt;고가치 파일 존재·속성 확인(탈취 대상 특정)&lt;/description&gt;
    &lt;mitre&gt;&lt;id&gt;T1083&lt;/id&gt;&lt;/mitre&gt;
  &lt;/rule&gt;
&lt;/group&gt;</code></pre>
<p>표적 확인은 E영역(중요 정보 접근) 룰과 연계해 확인→접근을 포착합니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — 확인된 중요 파일(키·덤프·.env)·권한·주체를 확인합니다.</li>
<li><strong>범위 확인</strong> — 확인 뒤 실제 접근·복사·유출(E영역)이 이어졌는지 확인합니다.</li>
<li><strong>증거 확보</strong> — 세션 조회 흐름과 대상 파일 목록을 보존합니다.</li>
<li><strong>차단/조치</strong> — 탈취 세션이면 B영역 대응과 해당 파일 접근 통제·자격증명 교체를 진행합니다.</li>
<li><strong>재발 방지</strong> — 표적 파일 확인을 데이터 탈취 상관에 포함합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td>ls -l 파일</td>
<td>존재·권한</td>
</tr>
<tr>
<td>stat</td>
<td>상세 속성</td>
</tr>
<tr>
<td>test -f</td>
<td>존재 여부</td>
</tr>
<tr>
<td>대상</td>
<td>id_rsa·.pem·.env·덤프·백업</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;고가치 파일 콕 집은 존재 확인은 탈취 대상 특정 — E영역 접근의 선행&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c39">139. Linux 정보 수집 — 설정 파일 탐색 흔적</a></strong> 에서는 설정 탐색 정찰인 <strong>설정 파일 탐색 흔적</strong>을 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c37">137. Linux 정보 수집 — 파일·디렉터리 구조 탐색 흔적</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[137. Linux 정보 수집 — 파일·디렉터리 구조 탐색 흔적]]></title>
            <link>https://velog.io/@cs_security/syssec-c37</link>
            <guid>https://velog.io/@cs_security/syssec-c37</guid>
            <pubDate>Thu, 01 Oct 2026 10:33:56 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>37/50편</strong> (전체 137/450)
학습 단계: 프로세스·서비스·파일 정보 수집
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c36">136. Linux 정보 수집 — cron 관련 정보 수집</a></li>
<li><a href="https://velog.io/@cs_security/linsec-25-critical-files">25. 중요 파일 권한 점검(linsec)</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>파일·디렉터리 탐색은 공격자가 <strong>&quot;어디에 무엇이 있는가&quot;</strong> 를 파악하는 광범위 정찰입니다. 민감 데이터·설정·쓰기 가능 위치를 찾습니다. 정상 작업은 특정 디렉터리를 보지만, 정찰은 <strong>광범위·재귀·전체 파일시스템</strong>을 훑습니다.</p>
<pre><code class="language-text">파일 탐색
 ls -laR /경로       → 재귀적 목록
 find / -name &#39;*.conf&#39;  → 전체 설정 파일 탐색
 find / -writable       → 쓰기 가능 위치
 find /home -name &#39;id_rsa&#39; → SSH 키 탐색
 tree /경로          → 구조 시각화

정상: 특정 디렉터리 작업 / 정찰: 전체·재귀·패턴 기반 광범위 탐색</code></pre>
<p>linsec 25편(중요 파일 권한 점검)이 방어라면, 여기서는 공격자가 <strong>파일을 광범위하게 탐색하는</strong> 정찰입니다.</p>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>광범위 파일 탐색은 민감 데이터(개인정보·키·백업)·설정·쓰기 가능 위치(지속성 장소)를 한 번에 찾습니다.</li>
<li>전체 파일시스템 <code>find</code>는 부하가 크고 정상 운영에서 드물어, 그 자체로 탐지 가치가 높습니다(C27 SUID 탐색과 유사).</li>
<li>패턴 기반 탐색(<code>*.conf</code>, <code>id_rsa</code>, <code>*.bak</code>)은 명확한 목표(설정·키·백업)를 드러냅니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td><code>ls -laR</code></td>
<td>재귀 목록</td>
</tr>
<tr>
<td><code>find / -name 패턴</code></td>
<td>패턴 파일 탐색</td>
</tr>
<tr>
<td><code>find / -writable</code></td>
<td>쓰기 가능 위치</td>
</tr>
<tr>
<td><code>find /home -name id_rsa</code></td>
<td>SSH 키(E영역 연계)</td>
</tr>
<tr>
<td><code>tree</code></td>
<td>구조</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># 파일 탐색 감사 (C27의 recon_priv와 별도 recon_file)
-a always,exit -F arch=b64 -S execve -F path=/usr/bin/find -F auid&gt;=1000 -F auid!=unset -k recon_file

# 광범위/패턴 탐색인지 (분석 방법) — find 인자 확인
sudo ausearch -k recon_file -i --start recent | grep &#39;find&#39; | tail
sudo ausearch --session 12 -i 2&gt;/dev/null | grep -A1 &#39;comm=&quot;find&quot;&#39; | grep -E &#39;a[0-9]=&#39; | tail</code></pre>
<p>전체 <code>find</code>는 많으므로, 대상이 <code>/</code>·<code>/home</code>이거나 <code>-name</code>/<code>-writable</code> 패턴인 경우로 좁힙니다(147편).</p>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">$ sudo ausearch -k recon_file -i --start today | grep find | tail -1
11:00:02 auid=admin1 ses=8 comm=&quot;find&quot; a1=&quot;/var/log&quot; a2=&quot;-name&quot; a3=&quot;*.log&quot;  (로그 작업)</code></pre>
<p>관리자가 특정 디렉터리에서 특정 파일을 찾는 것은 정상입니다. <strong>전체 파일시스템·민감 패턴</strong> 탐색이 이상 신호입니다.</p>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">02:16:10 auid=devops ses=12 comm=&quot;find&quot; a1=&quot;/&quot; a2=&quot;-name&quot; a3=&quot;*.conf&quot;
02:16:15 auid=devops ses=12 comm=&quot;find&quot; a1=&quot;/home&quot; a2=&quot;-name&quot; a3=&quot;id_rsa&quot;
02:16:20 auid=devops ses=12 comm=&quot;find&quot; a1=&quot;/&quot; a2=&quot;-writable&quot; a3=&quot;-type&quot; a4=&quot;d&quot;</code></pre>
<ul>
<li>전체 설정 파일 + SSH 키 + 쓰기 가능 디렉터리 탐색 → 민감 파일·지속성 위치 전수 조사</li>
<li><code>id_rsa</code> 탐색 → SSH 키 탈취 목표(E영역 중요 정보 접근)</li>
<li>쓰기 가능 위치 탐색 → 지속성·도구 배치 장소(F영역)</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>광범위 파일 탐색 흐름입니다(가상의 예시 로그).</p>
<pre><code class="language-text">type=EXECVE ... a0=&quot;find&quot; a1=&quot;/&quot; a2=&quot;-name&quot; a3=&quot;*.conf&quot;
type=SYSCALL ... auid=devops ses=12 comm=&quot;find&quot; key=&quot;recon_file&quot;
type=EXECVE ... a0=&quot;find&quot; a1=&quot;/home&quot; a2=&quot;-name&quot; a3=&quot;id_rsa&quot;</code></pre>
<table>
<thead>
<tr>
<th>관찰</th>
<th>해석</th>
</tr>
</thead>
<tbody><tr>
<td>find / -name *.conf</td>
<td>전체 설정 탐색</td>
</tr>
<tr>
<td>find /home -name id_rsa</td>
<td>SSH 키 탈취 목표</td>
</tr>
<tr>
<td>find / -writable</td>
<td>지속성 위치</td>
</tr>
<tr>
<td>ses=12</td>
<td>파일 정찰</td>
</tr>
</tbody></table>
<p>발견된 민감 파일 접근(E영역)·쓰기 위치 사용(F영역)이 이어지는지 연계합니다.</p>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>광범위·패턴 기반 파일 탐색을 <strong>민감 파일·지속성 위치 정찰</strong>로 봅니다.</li>
<li><code>id_rsa</code>·<code>*.bak</code>·<code>*.conf</code> 등 민감 패턴 탐색은 명확한 목표를 드러내 우선순위를 높입니다.</li>
<li>탐색 뒤 민감 파일 접근(E영역)·쓰기 위치 사용(F영역)을 연계 감시합니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;group name=&quot;local,syssec_c,recon,&quot;&gt;
  &lt;rule id=&quot;102360&quot; level=&quot;9&quot;&gt;
    &lt;if_group&gt;audit&lt;/if_group&gt;
    &lt;field name=&quot;audit.key&quot;&gt;recon_file&lt;/field&gt;
    &lt;regex type=&quot;pcre2&quot;&gt;a0=&quot;find&quot;.*(-name.*(id_rsa|\.key|\.pem|\.bak|shadow)|-writable)&lt;/regex&gt;
    &lt;description&gt;민감 파일·쓰기 위치 광범위 탐색&lt;/description&gt;
    &lt;mitre&gt;&lt;id&gt;T1083&lt;/id&gt;&lt;/mitre&gt;
  &lt;/rule&gt;
&lt;/group&gt;</code></pre>
<p><code>T1083</code>(File and Directory Discovery)에 매핑됩니다. 파일 탐색은 파일 정찰 세트(140편)·E영역과 연계합니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — 파일 탐색의 범위(전체/특정)·패턴·주체를 확인합니다.</li>
<li><strong>범위 확인</strong> — 발견된 민감 파일 접근(E영역)·쓰기 위치 사용(F영역)이 이어졌는지 확인합니다.</li>
<li><strong>증거 확보</strong> — 세션 조회 흐름과 탐색 패턴을 보존합니다.</li>
<li><strong>차단/조치</strong> — 탈취 세션이면 B영역 대응과 민감 파일 권한 점검(linsec 25편)을 진행합니다.</li>
<li><strong>재발 방지</strong> — 파일 탐색을 파일 정찰·E영역 상관에 포함합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td>ls -laR</td>
<td>재귀 목록</td>
</tr>
<tr>
<td>find / -name 패턴</td>
<td>민감 파일</td>
</tr>
<tr>
<td>find / -writable</td>
<td>지속성 위치</td>
</tr>
<tr>
<td>구분</td>
<td>특정 작업(정상) vs 전체·민감 패턴 탐색(정찰)</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;id_rsa·*.conf 광범위 탐색은 민감 파일·키 탈취 정찰&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c38">138. Linux 정보 수집 — 중요 파일 존재 여부 확인</a></strong> 에서는 표적 확인 정찰인 <strong>중요 파일 존재 여부 확인</strong>을 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c36">136. Linux 정보 수집 — cron 관련 정보 수집</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[136. Linux 정보 수집 — cron 관련 정보 수집]]></title>
            <link>https://velog.io/@cs_security/syssec-c36</link>
            <guid>https://velog.io/@cs_security/syssec-c36</guid>
            <pubDate>Thu, 01 Oct 2026 10:33:56 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>36/50편</strong> (전체 136/450)
학습 단계: 프로세스·서비스·파일 정보 수집
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c35">135. Linux 정보 수집 — systemd 서비스 정보 수집</a></li>
<li><a href="https://velog.io/@cs_security/syssec-a26">026. cron·at 접근 제어 점검(A영역)</a></li>
<li><a href="https://velog.io/@cs_security/linsec-31-cron-persistence">31. Cron 기반 지속성 탐지(linsec)</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>cron은 systemd와 함께 대표적 지속성 수단입니다. 공격자는 예약 작업 구조(어디에 등록되고, 어떤 작업이 이미 있는가)를 조회해 <strong>악성 예약 작업 등록</strong> 위치를 물색합니다.</p>
<pre><code class="language-text">cron 구조 조회
 crontab -l             → 현재 사용자 crontab
 ls /etc/cron.d/        → 시스템 cron 작업(A영역 26편)
 cat /etc/crontab       → 시스템 crontab
 ls /var/spool/cron/    → 사용자별 crontab
 ls /etc/cron.{hourly,daily,...} → 주기 작업 디렉터리

목적: 악성 cron을 어디에 등록할지, 기존 작업에 섞을 수 있는지 파악</code></pre>
<p>A영역 26편(cron 접근 제어)·linsec 31편(cron 지속성 탐지)이 방어라면, 여기서는 공격자가 <strong>등록 위치를 조회하는</strong> 정찰입니다.</p>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>cron 기반 지속성(F영역·linsec 31편)은 재부팅·세션 종료 후에도 실행돼, 공격자가 선호합니다.</li>
<li>기존 cron 작업을 조회해 <strong>그 작업에 섞거나 비슷하게 위장</strong>하면 눈에 덜 띕니다.</li>
<li>cron 디렉터리 조회 직후 예약 작업 생성(A영역 26편·F영역)이 이어지면 지속성 확보입니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td><code>crontab -l</code></td>
<td>현재 사용자 crontab</td>
</tr>
<tr>
<td><code>/etc/cron.d/</code>, <code>/etc/crontab</code></td>
<td>시스템 cron(A영역 26편)</td>
</tr>
<tr>
<td><code>/var/spool/cron/</code></td>
<td>사용자별 crontab</td>
</tr>
<tr>
<td><code>/etc/cron.{hourly,daily}</code></td>
<td>주기 작업</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># cron 구조 조회 감사 (실습 예시)
-w /etc/cron.d -p r -k recon_persist
-w /etc/crontab -p r -k recon_persist
-w /var/spool/cron -p r -k recon_persist
-a always,exit -F arch=b64 -S execve -F path=/usr/bin/crontab -F a1=&quot;-l&quot; -k recon_persist

# 세션에서 cron 구조 조회 (분석 방법)
sudo ausearch -k recon_persist -i --start recent | grep -E &#39;cron|crontab&#39; | tail</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">$ sudo ausearch -k recon_persist -i --start today | grep cron | tail -1
10:20:02 auid=admin1 ses=8 comm=&quot;crontab&quot; a1=&quot;-l&quot;  (예약 작업 점검)</code></pre>
<p>관리자가 자기 예약 작업을 점검하는 <code>crontab -l</code>은 정상입니다(A영역 26편 점검 포함).</p>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">02:16:00 auid=devops ses=12 comm=&quot;crontab&quot; a1=&quot;-l&quot;
02:16:02 auid=devops ses=12 comm=&quot;ls&quot; (대상 /etc/cron.d/)
02:16:04 auid=devops ses=12 comm=&quot;cat&quot; name=&quot;/etc/crontab&quot;</code></pre>
<ul>
<li>사용자 crontab + 시스템 cron.d + crontab 연속 조회 → 예약 작업 등록 위치 전수 파악</li>
<li>기존 작업 확인 후 그에 섞을 악성 예약 작업 등록(A영역 26편·F영역) 가능성</li>
<li>systemd 정찰(C35)에 이어 cron 정찰 → 지속성 수단 전수 조사</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>cron 구조 정찰 → 지속성 준비 흐름입니다(가상의 예시 로그).</p>
<pre><code class="language-text">type=EXECVE ... a0=&quot;crontab&quot; a1=&quot;-l&quot;
type=SYSCALL ... auid=devops ses=12 comm=&quot;crontab&quot; key=&quot;recon_persist&quot;
type=PATH ... name=&quot;/etc/cron.d/&quot; nametype=NORMAL
[이후 가능] /etc/cron.d/&lt;악성&gt; 또는 crontab 등록 (A영역 26편 100320, F영역)</code></pre>
<table>
<thead>
<tr>
<th>관찰</th>
<th>해석</th>
</tr>
</thead>
<tbody><tr>
<td>crontab -l</td>
<td>현재 작업 확인</td>
</tr>
<tr>
<td>ls /etc/cron.d</td>
<td>등록 위치</td>
</tr>
<tr>
<td>cat /etc/crontab</td>
<td>기존 작업(위장 참고)</td>
</tr>
<tr>
<td>이후 등록</td>
<td>지속성(F영역)</td>
</tr>
</tbody></table>
<p>cron 조회 직후 예약 작업 등록(A영역 26편 100320)이 나타나면 지속성 확보로 연계 탐지합니다.</p>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>cron 구조 조회는 <strong>지속성 등록 위치 물색</strong> 관점으로 봅니다(systemd C35와 묶음).</li>
<li>cron 조회 직후 예약 작업 등록(A영역 26편·F영역)이 이어지는지 연계합니다.</li>
<li>지속성 정찰(systemd+cron)이 결합되면 지속성 확보 임박으로 봅니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;group name=&quot;local,syssec_c,recon,&quot;&gt;
  &lt;rule id=&quot;102350&quot; level=&quot;7&quot;&gt;
    &lt;if_group&gt;audit&lt;/if_group&gt;
    &lt;field name=&quot;audit.key&quot;&gt;recon_persist&lt;/field&gt;
    &lt;regex type=&quot;pcre2&quot;&gt;cron|crontab&lt;/regex&gt;
    &lt;description&gt;cron 예약 작업 구조 조회(지속성 등록 정찰)&lt;/description&gt;
    &lt;mitre&gt;&lt;id&gt;T1053.003&lt;/id&gt;&lt;/mitre&gt;
  &lt;/rule&gt;
&lt;/group&gt;</code></pre>
<p><code>T1053.003</code>(Cron)에 매핑됩니다. cron 조회 + 등록(A영역 26편 100320)을 상관하면 지속성 준비→확보를 포착합니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — cron 구조 조회의 범위·주체와 이후 예약 작업 등록 여부를 확인합니다.</li>
<li><strong>범위 확인</strong> — cron 조회 직후 등록(A영역 26편·F영역)이 이어졌는지 확인합니다.</li>
<li><strong>증거 확보</strong> — 세션 조회 흐름과 cron 디렉터리 상태를 보존합니다.</li>
<li><strong>차단/조치</strong> — 탈취 세션이면 B영역 대응과 cron FIM 점검을 진행합니다.</li>
<li><strong>재발 방지</strong> — cron 정찰을 지속성 상관에 포함합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td>crontab -l</td>
<td>사용자 crontab</td>
</tr>
<tr>
<td>/etc/cron.d, crontab</td>
<td>시스템 cron</td>
</tr>
<tr>
<td>/var/spool/cron</td>
<td>사용자별</td>
</tr>
<tr>
<td>구분</td>
<td>예약 작업 점검(정상) vs 등록 위치 전수 조회(정찰)</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;기존 cron 조회는 섞어 넣을 악성 예약 작업의 위장 준비&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c37">137. Linux 정보 수집 — 파일·디렉터리 구조 탐색 흔적</a></strong> 에서는 파일 탐색 정찰인 <strong>파일·디렉터리 구조 탐색 흔적</strong>을 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c35">135. Linux 정보 수집 — systemd 서비스 정보 수집</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[135. Linux 정보 수집 — systemd 서비스 정보 수집]]></title>
            <link>https://velog.io/@cs_security/syssec-c35</link>
            <guid>https://velog.io/@cs_security/syssec-c35</guid>
            <pubDate>Thu, 01 Oct 2026 10:33:55 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>35/50편</strong> (전체 135/450)
학습 단계: 프로세스·서비스·파일 정보 수집
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c34">134. Linux 정보 수집 — 서비스 목록 조회</a></li>
<li><a href="https://velog.io/@cs_security/syssec-a27">27. systemd 보안 옵션(A영역)</a></li>
<li><a href="https://velog.io/@cs_security/linsec-30-malicious-systemd">30. 악성 systemd 서비스 탐지(linsec)</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>서비스 목록(C34)보다 깊게, systemd <strong>유닛 파일의 구조·경로</strong>를 조회하는 정찰입니다. 공격자는 유닛 파일이 어디에 있고(<code>/etc/systemd/system</code>), 어떻게 작성되는지 파악해 <strong>악성 유닛 등록</strong>(지속성, F영역) 위치를 물색합니다.</p>
<pre><code class="language-text">systemd 구조 조회
 systemctl cat 서비스        → 유닛 파일 내용(작성 예시 학습)
 ls /etc/systemd/system/     → 유닛 파일 위치
 systemctl list-unit-files   → 유닛 파일 목록
 ~/.config/systemd/user/     → 사용자 유닛(B영역 40편)

목적: 악성 유닛을 어디에·어떻게 등록할지 파악 (지속성 준비)</code></pre>
<p>A영역 27편(systemd 보안 옵션)·linsec 30편(악성 systemd 탐지)이 방어라면, 여기서는 공격자가 <strong>등록 위치·방법을 조회하는</strong> 정찰입니다.</p>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>systemd 유닛 등록은 대표적 지속성 수단(F영역)입니다. 공격자는 기존 유닛을 참고해 <strong>정상처럼 보이는 악성 유닛</strong>을 만듭니다.</li>
<li>사용자 유닛(<code>~/.config/systemd/user</code>)·linger(B영역 40편) 경로 조회는 일반 권한 지속성 준비입니다.</li>
<li>systemd 구조 정찰 뒤 유닛 파일 생성(F영역)이 이어지면 지속성 확보로 판정합니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td><code>systemctl cat 서비스</code></td>
<td>유닛 내용(작성 학습)</td>
</tr>
<tr>
<td><code>ls /etc/systemd/system/</code></td>
<td>유닛 위치</td>
</tr>
<tr>
<td><code>systemctl list-unit-files</code></td>
<td>유닛 목록</td>
</tr>
<tr>
<td><code>~/.config/systemd/user/</code></td>
<td>사용자 유닛(B영역 40편)</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># systemd 구조 조회 감사 (실습 예시)
-w /etc/systemd/system -p r -k recon_svc
-a always,exit -F arch=b64 -S execve -F path=/usr/bin/systemctl -F a1=&quot;cat&quot; -k recon_svc

# 세션에서 유닛 구조 조회 (분석 방법)
sudo ausearch -k recon_svc -i --start recent | grep -E &#39;systemd/system|a1=&quot;cat&quot;&#39; | tail</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">$ sudo ausearch -k recon_svc -i --start today | grep &#39;systemd/system&#39; | tail -1
10:10:02 auid=admin1 ses=8 comm=&quot;systemctl&quot; a1=&quot;cat&quot;  (유닛 점검)</code></pre>
<p>관리자가 서비스 유닛을 점검·수정하며 <code>systemctl cat</code>을 보는 것은 정상입니다(A영역 27편 점검 포함).</p>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">02:15:50 auid=devops ses=12 comm=&quot;systemctl&quot; a1=&quot;cat&quot; a2=&quot;httpd&quot;
02:15:52 auid=devops ses=12 comm=&quot;ls&quot; (대상 /etc/systemd/system/)</code></pre>
<ul>
<li>정상 유닛(<code>systemctl cat httpd</code>) 내용 확인 + 유닛 디렉터리 조회 → 악성 유닛 작성 준비</li>
<li>기존 유닛을 참고해 정상처럼 위장한 유닛 생성(A영역 13·27편·F영역) 가능성</li>
<li>서비스 목록(C34)에 이어 등록 위치·방법 정찰 → 지속성 준비</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>systemd 구조 정찰 → 지속성 준비 흐름입니다(가상의 예시 로그).</p>
<pre><code class="language-text">type=EXECVE ... a0=&quot;systemctl&quot; a1=&quot;cat&quot; a2=&quot;httpd&quot;
type=SYSCALL ... auid=devops ses=12 comm=&quot;systemctl&quot; key=&quot;recon_svc&quot;
type=PATH ... name=&quot;/etc/systemd/system/&quot; nametype=NORMAL
[이후 가능] /etc/systemd/system/&lt;악성&gt;.service 생성 (A영역 13편 100200, F영역)</code></pre>
<table>
<thead>
<tr>
<th>관찰</th>
<th>해석</th>
</tr>
</thead>
<tbody><tr>
<td>systemctl cat</td>
<td>유닛 작성 학습</td>
</tr>
<tr>
<td>ls /etc/systemd/system</td>
<td>등록 위치</td>
</tr>
<tr>
<td>이후 유닛 생성</td>
<td>지속성(F영역)</td>
</tr>
<tr>
<td>ses=12</td>
<td>지속성 정찰</td>
</tr>
</tbody></table>
<p>유닛 조회 직후 유닛 파일 생성(A영역 13편 100200)이 나타나면 지속성 확보로 연계 탐지합니다.</p>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>systemd 구조 조회는 <strong>악성 유닛 등록 위치·방법 물색</strong> 관점으로 봅니다.</li>
<li>유닛 조회 직후 유닛 파일 생성(A영역 13편·F영역)이 이어지는지 연계합니다.</li>
<li>사용자 유닛·linger(B영역 40편) 경로 조회는 일반 권한 지속성 준비로 봅니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;group name=&quot;local,syssec_c,recon,&quot;&gt;
  &lt;rule id=&quot;102340&quot; level=&quot;7&quot;&gt;
    &lt;if_group&gt;audit&lt;/if_group&gt;
    &lt;field name=&quot;audit.key&quot;&gt;recon_svc&lt;/field&gt;
    &lt;regex type=&quot;pcre2&quot;&gt;a1=&quot;cat&quot;|/etc/systemd/system&lt;/regex&gt;
    &lt;description&gt;systemd 유닛 구조 조회(지속성 등록 정찰)&lt;/description&gt;
    &lt;mitre&gt;&lt;id&gt;T1543.002&lt;/id&gt;&lt;/mitre&gt;
  &lt;/rule&gt;
&lt;/group&gt;</code></pre>
<p><code>T1543.002</code>(Systemd Service)에 매핑됩니다. 유닛 조회 + 생성(A영역 13편 100200)을 상관하면 지속성 준비→확보를 포착합니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — systemd 구조 조회의 대상·주체와 이후 유닛 생성 여부를 확인합니다.</li>
<li><strong>범위 확인</strong> — 유닛 조회 직후 악성 유닛 등록(A영역 13편·F영역)이 이어졌는지 확인합니다.</li>
<li><strong>증거 확보</strong> — 세션 조회 흐름과 유닛 디렉터리 상태를 보존합니다.</li>
<li><strong>차단/조치</strong> — 탈취 세션이면 B영역 대응과 유닛 디렉터리 FIM 점검을 진행합니다.</li>
<li><strong>재발 방지</strong> — systemd 정찰을 지속성 상관에 포함합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td>systemctl cat</td>
<td>유닛 작성 학습</td>
</tr>
<tr>
<td>ls /etc/systemd/system</td>
<td>등록 위치</td>
</tr>
<tr>
<td>사용자 유닛 경로</td>
<td>일반 권한 지속성</td>
</tr>
<tr>
<td>구분</td>
<td>유닛 점검(정상) vs 등록 위치·방법 물색(정찰)</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;기존 유닛 조회는 정상처럼 위장한 악성 유닛 작성의 준비&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c36">136. Linux 정보 수집 — cron 관련 정보 수집</a></strong> 에서는 예약 작업 지속성 정찰인 <strong>cron 관련 정보 수집</strong>을 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c34">134. Linux 정보 수집 — 서비스 목록 조회</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[134. Linux 정보 수집 — 서비스 목록 조회]]></title>
            <link>https://velog.io/@cs_security/syssec-c34</link>
            <guid>https://velog.io/@cs_security/syssec-c34</guid>
            <pubDate>Thu, 01 Oct 2026 10:33:54 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>34/50편</strong> (전체 134/450)
학습 단계: 프로세스·서비스·파일 정보 수집
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c33">133. Linux 정보 수집 — 실행 파일 경로 확인</a></li>
<li><a href="https://velog.io/@cs_security/syssec-a13">013. 불필요한 서비스 식별과 비활성화(A영역)</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>서비스 목록 조회는 공격자가 <strong>&quot;어떤 서비스가 돌고, 어디에 기생·등록할 수 있는가&quot;</strong> 를 파악하는 정찰입니다. 프로세스(C31)가 &quot;지금 돌고 있는 것&quot;이라면, 서비스 목록은 <strong>등록된 구성·자동 시작</strong>까지 보여줍니다.</p>
<pre><code class="language-text">서비스 조회
 systemctl list-units --type=service   → 실행 중 서비스
 systemctl list-unit-files             → 자동 시작 포함 전체(A영역 13편)
 systemctl status 서비스               → 특정 서비스 상세
 service --status-all                  → (구형) 서비스 상태

목적: 공격 표면(DB·웹), 보안 서비스(wazuh·auditd), 지속성 등록 대상(systemd, C35) 파악</code></pre>
<p>A영역 13편이 &quot;불필요한 서비스 식별&quot;(방어)이라면, 여기서는 공격자가 <strong>서비스 구성을 조회하는</strong> 정찰입니다.</p>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>서비스 목록으로 공격자는 공격 표면(DB·웹)과 보안 서비스를 함께 파악합니다(C31 프로세스 정찰 보완).</li>
<li>systemd 서비스 구조를 알면, 악성 서비스 등록(C35·F영역 지속성)의 위장 대상을 고릅니다.</li>
<li>보안 서비스(wazuh·auditd) 상태 조회는 C31과 함께 탐지 회피 준비 신호입니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td><code>systemctl list-units --type=service</code></td>
<td>실행 중 서비스</td>
</tr>
<tr>
<td><code>systemctl list-unit-files</code></td>
<td>자동 시작 포함 전체</td>
</tr>
<tr>
<td><code>systemctl status 서비스</code></td>
<td>특정 서비스</td>
</tr>
<tr>
<td><code>service --status-all</code></td>
<td>(구형) 상태</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># 서비스 조회 감사 (실습 예시)
-a always,exit -F arch=b64 -S execve -F path=/usr/bin/systemctl -F auid&gt;=1000 -F auid!=unset -k recon_svc

# 세션에서 서비스 조회 흐름 (분석 방법) — 보안 서비스 조회 포함 여부
sudo ausearch -k recon_svc -i --start recent | grep -E &#39;systemctl|list-unit&#39; | tail
sudo ausearch --session 12 -i 2&gt;/dev/null | grep -iE &#39;systemctl.*(status|list)|wazuh|auditd&#39; | tail</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">$ sudo ausearch -k recon_svc -i --start today | grep systemctl | tail -1
10:00:02 auid=admin1 ses=8 comm=&quot;systemctl&quot; (status httpd)  (서비스 점검)</code></pre>
<p>관리자가 서비스 상태를 점검·관리하는 <code>systemctl status/list</code>는 매우 흔하고 정상입니다. 차이는 <strong>전수 조회·보안 서비스 조준</strong>입니다.</p>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">02:15:40 auid=devops ses=12 comm=&quot;systemctl&quot; (list-unit-files)
02:15:43 auid=devops ses=12 comm=&quot;systemctl&quot; (status wazuh-agent)
02:15:45 auid=devops ses=12 comm=&quot;systemctl&quot; (status auditd)</code></pre>
<ul>
<li>전체 서비스(<code>list-unit-files</code>) + 보안 서비스(wazuh·auditd) 상태 조회 → 공격 표면·보안 서비스 파악</li>
<li>보안 서비스 조회(C31 프로세스 정찰과 중복 확인) → 탐지 회피 준비</li>
<li>이후 systemd 서비스 정보(C35)·악성 서비스 등록(F영역)으로 이어질 수 있음</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>서비스 정찰 흐름입니다(가상의 예시 로그).</p>
<pre><code class="language-text">type=EXECVE ... a0=&quot;systemctl&quot; a1=&quot;list-unit-files&quot;
type=SYSCALL ... auid=devops ses=12 comm=&quot;systemctl&quot; key=&quot;recon_svc&quot;
type=EXECVE ... a0=&quot;systemctl&quot; a1=&quot;status&quot; a2=&quot;wazuh-agent&quot;</code></pre>
<table>
<thead>
<tr>
<th>관찰</th>
<th>해석</th>
</tr>
</thead>
<tbody><tr>
<td>list-unit-files</td>
<td>전체 서비스·자동 시작</td>
</tr>
<tr>
<td>status wazuh/auditd</td>
<td>보안 서비스 조준</td>
</tr>
<tr>
<td>전수+보안 조회</td>
<td>공격 표면+회피 준비</td>
</tr>
<tr>
<td>ses=12</td>
<td>서비스 정찰</td>
</tr>
</tbody></table>
<p>보안 서비스 조회 직후 중지(A영역 39편)·악성 서비스 등록(F영역)이 이어지는지 연계합니다.</p>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>서비스 목록 조회 중 <strong>보안 서비스 조준</strong>은 C31과 함께 회피 준비로 봅니다.</li>
<li>전체 서비스 전수 조회는 공격 표면·지속성 등록 대상 파악 정찰입니다.</li>
<li>서비스 정찰 뒤 systemd 정보(C35)·악성 등록(F영역)을 연계 감시합니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;group name=&quot;local,syssec_c,recon,&quot;&gt;
  &lt;rule id=&quot;102330&quot; level=&quot;7&quot;&gt;
    &lt;if_group&gt;audit&lt;/if_group&gt;
    &lt;field name=&quot;audit.key&quot;&gt;recon_svc&lt;/field&gt;
    &lt;regex type=&quot;pcre2&quot;&gt;list-unit|status.*(wazuh|auditd|falco)&lt;/regex&gt;
    &lt;description&gt;서비스 구성·보안 서비스 조회&lt;/description&gt;
    &lt;mitre&gt;&lt;id&gt;T1518.001&lt;/id&gt;&lt;/mitre&gt;
  &lt;/rule&gt;
&lt;/group&gt;</code></pre>
<p>보안 서비스 조회는 C31(프로세스)과 함께 회피 탐지 상관에, 전체 조회는 프로세스 정찰 세트(140편)에 포함합니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — 서비스 조회의 범위(전수/특정)·보안 서비스 포함 여부·주체를 확인합니다.</li>
<li><strong>범위 확인</strong> — 보안 서비스 조회 뒤 중지(A영역 39편)·악성 등록(F영역)이 이어졌는지 확인합니다.</li>
<li><strong>증거 확보</strong> — 세션 조회 흐름을 보존합니다.</li>
<li><strong>차단/조치</strong> — 탈취 세션이면 B영역 대응과 서비스·보안 솔루션 점검을 진행합니다.</li>
<li><strong>재발 방지</strong> — 서비스 정찰을 회피·프로세스 정찰 상관에 포함합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td>list-unit-files</td>
<td>전체·자동 시작</td>
</tr>
<tr>
<td>status 보안서비스</td>
<td>회피 준비</td>
</tr>
<tr>
<td>service --status-all</td>
<td>(구형) 상태</td>
</tr>
<tr>
<td>구분</td>
<td>서비스 관리(정상) vs 전수·보안 서비스 조회(정찰)</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;서비스 전수 조회는 공격 표면+지속성 등록 대상 파악&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c35">135. Linux 정보 수집 — systemd 서비스 정보 수집</a></strong> 에서는 systemd 구조 정찰인 <strong>systemd 서비스 정보 수집</strong>을 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c33">133. Linux 정보 수집 — 실행 파일 경로 확인</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[133. Linux 정보 수집 — 실행 파일 경로 확인]]></title>
            <link>https://velog.io/@cs_security/syssec-c33</link>
            <guid>https://velog.io/@cs_security/syssec-c33</guid>
            <pubDate>Thu, 01 Oct 2026 10:33:53 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>33/50편</strong> (전체 133/450)
학습 단계: 프로세스·서비스·파일 정보 수집
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c32">132. Linux 정보 수집 — 프로세스 트리 확인 분석</a></li>
<li><a href="https://velog.io/@cs_security/syssec-a24">24. 보안 패치·업데이트 상태(A영역)</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>공격자는 침입한 서버에 <strong>어떤 도구가 이미 있는가</strong>(추가 설치 없이 쓸 수 있는 것)를 확인합니다. 컴파일러(gcc)·인터프리터(python·perl)·네트워크 도구(curl·wget·nc)의 존재는 공격 가능성을 좌우합니다. 이를 LOLBins(Living off the Land) 탐색이라 합니다.</p>
<pre><code class="language-text">도구 존재 확인
 which gcc python3 curl   → 경로 확인(있으면 사용 가능)
 whereis nc socat         → 바이너리 위치
 type -a python           → 셸이 찾는 경로
 /proc/[PID]/exe          → 실행 중 바이너리 경로

목적: 추가 설치(A영역 24편 탐지) 없이 기존 도구로 공격
      → 설치 흔적을 남기지 않는 LOLBins 전략</code></pre>
<p>A영역 24편이 &quot;도구 설치 탐지&quot;였다면, 여기서는 설치 없이 <strong>기존 도구를 탐색하는</strong> 정찰입니다. 설치보다 조용합니다.</p>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>기존 도구(LOLBins)를 쓰면 설치 로그(A영역 24편)를 남기지 않아 탐지가 어렵습니다. 그래서 도구 탐색 단계가 탐지 기회입니다.</li>
<li>gcc 존재 확인은 커널 익스플로잇 컴파일 가능성(C02 커널 정찰과 연계)을, curl/nc 존재는 외부 통신·데이터 유출 가능성을 시사합니다.</li>
<li>짧은 시간에 여러 도구를 <code>which</code>로 확인하는 패턴은 LOLBins 탐색의 전형입니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td><code>which gcc python curl</code></td>
<td>도구 경로</td>
</tr>
<tr>
<td><code>whereis nc socat</code></td>
<td>바이너리 위치</td>
</tr>
<tr>
<td><code>type -a</code></td>
<td>셸 탐색 경로</td>
</tr>
<tr>
<td><code>/proc/[PID]/exe</code></td>
<td>실행 바이너리</td>
</tr>
<tr>
<td>관심</td>
<td>컴파일러·인터프리터·네트워크 도구</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># 도구 탐색 감사 (실습 예시)
-a always,exit -F arch=b64 -S execve -F path=/usr/bin/which -F auid&gt;=1000 -F auid!=unset -k recon_tool
-a always,exit -F arch=b64 -S execve -F path=/usr/bin/whereis -F auid&gt;=1000 -F auid!=unset -k recon_tool

# 짧은 시간 다수 도구 탐색인지 (분석 방법)
sudo ausearch -k recon_tool -i --start recent | grep -E &#39;which|whereis&#39; | tail
sudo ausearch --session 12 -i 2&gt;/dev/null | grep -E &#39;which|whereis&#39; | tail -10</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">$ sudo ausearch -k recon_tool -i --start today | grep which | tail -1
11:00:02 auid=admin1 ses=8 comm=&quot;which&quot; a1=&quot;python3&quot;  (스크립트 작업)</code></pre>
<p>관리자가 작업 중 특정 도구 경로를 확인하는 단발 <code>which</code>는 정상입니다. 다수 도구 연속 확인이 이상 신호입니다.</p>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">02:15:30 auid=devops ses=12 comm=&quot;which&quot; a1=&quot;gcc&quot;
02:15:31 auid=devops ses=12 comm=&quot;which&quot; a1=&quot;python3&quot;
02:15:32 auid=devops ses=12 comm=&quot;which&quot; a1=&quot;curl&quot;
02:15:33 auid=devops ses=12 comm=&quot;which&quot; a1=&quot;nc&quot;</code></pre>
<ul>
<li>gcc·python·curl·nc를 <strong>4초 내 연속 탐색</strong> → LOLBins 전수 조사</li>
<li>컴파일러·인터프리터·네트워크 도구 조합 → 공격 역량 파악</li>
<li>설치(A영역 24편) 없이 기존 도구 탐색 → 조용한 준비</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>도구 탐색 정찰 흐름입니다(가상의 예시 로그).</p>
<pre><code class="language-text">type=EXECVE ... a0=&quot;which&quot; a1=&quot;gcc&quot;
type=SYSCALL ... auid=devops ses=12 comm=&quot;which&quot; key=&quot;recon_tool&quot;
type=EXECVE ... a0=&quot;which&quot; a1=&quot;nc&quot;</code></pre>
<table>
<thead>
<tr>
<th>관찰</th>
<th>해석</th>
</tr>
</thead>
<tbody><tr>
<td>which gcc</td>
<td>컴파일 가능성(커널 익스플로잇)</td>
</tr>
<tr>
<td>which python/perl</td>
<td>스크립트 실행 가능</td>
</tr>
<tr>
<td>which curl/nc</td>
<td>외부 통신·유출</td>
</tr>
<tr>
<td>연속 탐색</td>
<td>LOLBins 전수 조사</td>
</tr>
</tbody></table>
<p>탐색 뒤 그 도구를 이용한 행위(F영역 비정상 프로세스·외부 연결)가 이어지는지 연계합니다.</p>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>짧은 시간 <strong>다수 도구 연속 탐색</strong>(which/whereis)을 LOLBins 정찰로 봅니다.</li>
<li>gcc·인터프리터·네트워크 도구 조합 탐색은 공격 역량 파악 신호입니다.</li>
<li>탐색 뒤 해당 도구 사용(F영역)·외부 통신(C16)을 연계 감시합니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;group name=&quot;local,syssec_c,recon,&quot;&gt;
  &lt;rule id=&quot;102320&quot; level=&quot;8&quot; frequency=&quot;4&quot; timeframe=&quot;60&quot;&gt;
    &lt;if_group&gt;audit&lt;/if_group&gt;
    &lt;field name=&quot;audit.key&quot;&gt;recon_tool&lt;/field&gt;
    &lt;same_field field=&quot;audit.session&quot; /&gt;
    &lt;description&gt;단시간 다수 도구 경로 탐색(LOLBins 정찰)&lt;/description&gt;
    &lt;mitre&gt;&lt;id&gt;T1518&lt;/id&gt;&lt;/mitre&gt;
  &lt;/rule&gt;
&lt;/group&gt;</code></pre>
<p><code>T1518</code>(Software Discovery)에 매핑됩니다. 도구 탐색은 프로세스 정찰 세트(140편)에 포함합니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — 도구 탐색의 종류·밀도·주체와 탐색된 도구(gcc·nc 등)를 확인합니다.</li>
<li><strong>범위 확인</strong> — 탐색 뒤 해당 도구 사용·외부 통신(F·C16)이 이어졌는지 확인합니다.</li>
<li><strong>증거 확보</strong> — 세션 조회 흐름을 보존합니다.</li>
<li><strong>차단/조치</strong> — 탈취 세션이면 B영역 대응과 불필요 도구 제거를 검토합니다.</li>
<li><strong>재발 방지</strong> — 도구 탐색을 프로세스 정찰 상관에 포함합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td>which/whereis</td>
<td>도구 경로</td>
</tr>
<tr>
<td>type -a</td>
<td>셸 탐색 경로</td>
</tr>
<tr>
<td>관심 도구</td>
<td>gcc·python·perl·curl·nc·socat</td>
</tr>
<tr>
<td>구분</td>
<td>단발 확인(정상) vs 다수 연속 탐색(LOLBins 정찰)</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;기존 도구 탐색(LOLBins)은 설치 흔적 없는 조용한 공격 준비&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c34">134. Linux 정보 수집 — 서비스 목록 조회</a></strong> 에서는 서비스 구성 정찰인 <strong>서비스 목록 조회</strong>를 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c32">132. Linux 정보 수집 — 프로세스 트리 확인 분석</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[132. Linux 정보 수집 — 프로세스 트리 확인 분석]]></title>
            <link>https://velog.io/@cs_security/syssec-c32</link>
            <guid>https://velog.io/@cs_security/syssec-c32</guid>
            <pubDate>Thu, 01 Oct 2026 10:33:52 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>32/50편</strong> (전체 132/450)
학습 단계: 프로세스·서비스·파일 정보 수집
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c31">131. Linux 정보 수집 — 프로세스 목록 조회 흔적</a></li>
<li><a href="https://velog.io/@cs_security/linsec-28-process-tree-analysis">28. 프로세스 트리 기반 침해 분석(linsec)</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>프로세스 트리는 <strong>&quot;어떤 프로세스가 무엇을 낳았는가(부모-자식)&quot;</strong> 를 보여줍니다. 공격자는 자기 프로세스의 계보를 확인해 은닉 가능성을 재거나, 데몬을 부모로 둔 프로세스(서비스 침해 흔적)를 파악합니다.</p>
<pre><code class="language-text">프로세스 트리 조회
 pstree -p           → 트리(PID 포함)
 ps -ejH / ps axjf   → 계층 구조
 /proc/[PID]/stat    → PPID(부모)

관점
 - 자기 셸의 부모가 무엇인가(sshd? httpd? → 은닉 여부)
 - 데몬 → 셸 계보(B영역 35편 서비스 침해)
 - 고아 프로세스(PPID=1)로 재부모화해 은닉</code></pre>
<p>linsec 28편이 &quot;프로세스 트리 기반 침해 분석&quot;(방어)이라면, 여기서는 공격자가 <strong>트리를 조회하는</strong> 정찰입니다.</p>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>공격자는 자기 프로세스가 <strong>어떻게 보이는지</strong>(부모가 sshd인지, 데몬인지)를 확인해 은닉 전략을 세웁니다.</li>
<li>PPID=1(init)로 재부모화된 프로세스는 백그라운드 지속성(F영역)의 단서이며, 공격자가 이를 미리 확인합니다.</li>
<li>데몬→셸 계보 조회는 서비스 침해(B영역 35편)의 자기 점검일 수 있습니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td><code>pstree -p</code></td>
<td>트리(PID)</td>
</tr>
<tr>
<td><code>ps -ejH</code>/<code>ps axjf</code></td>
<td>계층</td>
</tr>
<tr>
<td><code>/proc/[PID]/stat</code></td>
<td>PPID</td>
</tr>
<tr>
<td>관심</td>
<td>자기 계보, 데몬→셸, PPID=1</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># 프로세스 트리 조회 감사 (실습 예시)
-a always,exit -F arch=b64 -S execve -F path=/usr/bin/pstree -F auid&gt;=1000 -F auid!=unset -k recon_proc

# 세션에서 트리 조회 (분석 방법)
sudo ausearch -k recon_proc -i --start recent | grep -E &#39;pstree|ps.*axjf|ps.*ejH&#39; | tail</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">$ sudo ausearch -k recon_proc -i --start today | grep pstree | tail -1
10:00:02 auid=admin1 ses=8 comm=&quot;pstree&quot;  (프로세스 관계 점검)</code></pre>
<p>관리자가 프로세스 관계·부하 원인을 점검하는 단발 조회는 정상입니다.</p>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">02:15:20 auid=devops ses=12 comm=&quot;pstree&quot; a1=&quot;-p&quot;
02:15:22 auid=devops ses=12 comm=&quot;cat&quot; name=&quot;/proc/12901/stat&quot; (자기 셸 PPID 확인)</code></pre>
<ul>
<li>트리 조회 + 자기 셸의 PPID 확인 → 프로세스 계보·은닉 가능성 점검</li>
<li>자기 셸의 부모가 sshd인지 확인 → 세션 노출 여부 파악</li>
<li>프로세스 목록(C31)에 이어 관계 정찰 → 은닉 전략 수립</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>프로세스 트리 정찰 흐름입니다(가상의 예시 로그).</p>
<pre><code class="language-text">type=EXECVE ... a0=&quot;pstree&quot; a1=&quot;-p&quot;
type=SYSCALL ... auid=devops ses=12 comm=&quot;pstree&quot; key=&quot;recon_proc&quot;
type=PATH ... name=&quot;/proc/12901/stat&quot; nametype=NORMAL</code></pre>
<table>
<thead>
<tr>
<th>관찰</th>
<th>해석</th>
</tr>
</thead>
<tbody><tr>
<td>pstree -p</td>
<td>전체 트리</td>
</tr>
<tr>
<td>/proc/[자기PID]/stat</td>
<td>자기 계보 확인</td>
</tr>
<tr>
<td>부모 확인</td>
<td>은닉 여부 판단</td>
</tr>
<tr>
<td>ses=12</td>
<td>프로세스 정찰</td>
</tr>
</tbody></table>
<p>이후 재부모화·백그라운드 은닉(F영역)이 나타나는지 연계합니다.</p>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>프로세스 트리 조회는 <strong>자기 계보 확인·은닉 점검</strong> 관점으로 봅니다.</li>
<li>트리 조회 뒤 재부모화·백그라운드 지속성(F영역)이 이어지는지 연계합니다.</li>
<li>프로세스 목록(C31)+트리(C32) 조회를 묶어 프로세스 정찰로 봅니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;group name=&quot;local,syssec_c,recon,&quot;&gt;
  &lt;rule id=&quot;102310&quot; level=&quot;6&quot;&gt;
    &lt;if_group&gt;audit&lt;/if_group&gt;
    &lt;field name=&quot;audit.key&quot;&gt;recon_proc&lt;/field&gt;
    &lt;regex type=&quot;pcre2&quot;&gt;a0=&quot;pstree&quot;|a0=&quot;ps&quot;.*axjf&lt;/regex&gt;
    &lt;description&gt;프로세스 트리·계보 조회&lt;/description&gt;
    &lt;mitre&gt;&lt;id&gt;T1057&lt;/id&gt;&lt;/mitre&gt;
  &lt;/rule&gt;
&lt;/group&gt;</code></pre>
<p><code>T1057</code>(Process Discovery)에 매핑됩니다. 프로세스 정찰 세트(140편)에 포함합니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — 트리 조회의 대상(자기/전체)·연속성·주체를 확인합니다.</li>
<li><strong>범위 확인</strong> — 트리 조회 뒤 재부모화·은닉(F영역)이 이어졌는지 확인합니다.</li>
<li><strong>증거 확보</strong> — 세션 조회 흐름을 보존합니다.</li>
<li><strong>차단/조치</strong> — 탈취 세션이면 B영역 대응과 프로세스 점검을 진행합니다.</li>
<li><strong>재발 방지</strong> — 프로세스 트리 조회를 프로세스 정찰 상관에 포함합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td>pstree -p</td>
<td>트리(PID)</td>
</tr>
<tr>
<td>ps axjf</td>
<td>계층</td>
</tr>
<tr>
<td>/proc/stat</td>
<td>PPID</td>
</tr>
<tr>
<td>구분</td>
<td>관계 점검(정상) vs 자기 계보·은닉 점검(정찰)</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;프로세스 트리 조회는 자기 프로세스의 은닉 가능성 점검&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c33">133. Linux 정보 수집 — 실행 파일 경로 확인</a></strong> 에서는 실행 파일 정찰인 <strong>실행 파일 경로 확인</strong>을 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c31">131. Linux 정보 수집 — 프로세스 목록 조회 흔적</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
        <item>
            <title><![CDATA[131. Linux 정보 수집 — 프로세스 목록 조회 흔적]]></title>
            <link>https://velog.io/@cs_security/syssec-c31</link>
            <guid>https://velog.io/@cs_security/syssec-c31</guid>
            <pubDate>Thu, 01 Oct 2026 10:33:52 GMT</pubDate>
            <description><![CDATA[<blockquote>
<p><strong>시스템 보안 · 취약점</strong> › C. Linux 정보 노출 및 수집 · <strong>31/50편</strong> (전체 131/450)
학습 단계: 프로세스·서비스·파일 정보 수집
실습 표기: 이 글의 명령어·출력·로그는 로컬 VMware 테스트 VM(Rocky Linux 9 / Ubuntu 22.04) 기준의 <strong>「실습 예시」</strong>이며, IP·계정·호스트명은 가상의 값입니다.</p>
</blockquote>
<h2 id="선행-학습">선행 학습</h2>
<ul>
<li><a href="https://velog.io/@cs_security/syssec-c30">130. Linux 정보 수집 — 사용자·권한 정보 수집 종합 분석</a></li>
<li><a href="https://velog.io/@cs_security/linsec-26-process-security">26. Linux 프로세스 보안(linsec)</a></li>
<li><a href="https://velog.io/@cs_security/linsec-27-suspicious-process">27. 의심 프로세스 탐지(linsec)</a></li>
</ul>
<h2 id="1-개념">1. 개념</h2>
<p>프로세스 목록 조회는 공격자가 <strong>&quot;이 서버에서 무엇이 돌고 있는가&quot;</strong> 를 파악하는 정찰입니다. 특히 <strong>보안 솔루션(Wazuh agent·백신·EDR)</strong> 의 실행 여부를 확인해 탐지 회피를 준비하거나, 다른 사용자 활동을 관찰합니다.</p>
<pre><code class="language-text">프로세스 조회
 ps aux / ps -ef        → 전체 프로세스(사용자·명령)
 /proc/[PID]/           → 프로세스 상세(cmdline·exe)
 top / htop             → 실시간 프로세스

목적
 - 보안 솔루션 실행 여부(wazuh·auditd·falco) → 회피 준비
 - 서비스·DB 프로세스 → 공격 표면
 - 다른 사용자 프로세스 → 활동 관찰</code></pre>
<p>linsec 26·27편이 &quot;프로세스 보안·의심 프로세스 탐지&quot;(방어)라면, 여기서는 공격자가 <strong>프로세스 목록을 조회하는</strong> 정찰입니다.</p>
<h2 id="2-왜-중요한가">2. 왜 중요한가</h2>
<ul>
<li>공격자가 <code>ps</code>로 Wazuh agent·auditd를 확인하면, 이후 그것을 중지(A영역 39편 하드닝 해제)하려 할 수 있습니다.</li>
<li>전체 프로세스 조회는 서비스·DB 등 공격 표면과 다른 사용자 활동을 한 번에 드러냅니다.</li>
<li>보안 솔루션 프로세스 조회 직후 그 솔루션 중지가 이어지면, 탐지 회피의 강한 신호입니다.</li>
</ul>
<h2 id="3-핵심-명령어--설정">3. 핵심 명령어 / 설정</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td><code>ps aux</code>/<code>ps -ef</code></td>
<td>전체 프로세스</td>
</tr>
<tr>
<td><code>/proc/[PID]/cmdline</code></td>
<td>명령줄</td>
</tr>
<tr>
<td><code>top</code>/<code>htop</code></td>
<td>실시간</td>
</tr>
<tr>
<td><code>pgrep 이름</code></td>
<td>특정 프로세스</td>
</tr>
<tr>
<td>관심</td>
<td>보안 솔루션(wazuh·auditd·falco)</td>
</tr>
</tbody></table>
<h2 id="4-실습-실습-예시">4. 실습 (실습 예시)</h2>
<pre><code class="language-bash"># 프로세스 조회 감사 (실습 예시)
-a always,exit -F arch=b64 -S execve -F path=/usr/bin/ps -F auid&gt;=1000 -F auid!=unset -k recon_proc
-a always,exit -F arch=b64 -S execve -F path=/usr/bin/pgrep -F auid&gt;=1000 -F auid!=unset -k recon_proc

# 보안 솔루션 프로세스를 조회했는지 (분석 방법)
sudo ausearch -k recon_proc -i --start recent | grep -E &#39;comm=&quot;ps&quot;|comm=&quot;pgrep&quot;&#39; | tail
sudo ausearch --session 12 -i 2&gt;/dev/null | grep -iE &#39;wazuh|auditd|pgrep|ps &#39; | tail</code></pre>
<h2 id="5-정상-상태">5. 정상 상태</h2>
<pre><code class="language-text">$ sudo ausearch -k recon_proc -i --start today | grep &#39;comm=&quot;ps&quot;&#39; | tail -1
09:30:02 auid=admin1 ses=8 comm=&quot;ps&quot;  (서비스 상태 점검)</code></pre>
<p>관리자가 서비스 상태·부하를 점검하며 <code>ps</code>를 보는 것은 매우 흔하고 정상입니다. 차이는 <strong>보안 솔루션 조준·연속 정찰</strong>입니다.</p>
<h2 id="6-이상-상태">6. 이상 상태</h2>
<pre><code class="language-text">02:15:10 auid=devops ses=12 comm=&quot;ps&quot; a1=&quot;aux&quot;
02:15:12 auid=devops ses=12 comm=&quot;pgrep&quot; a1=&quot;wazuh&quot;
02:15:14 auid=devops ses=12 comm=&quot;pgrep&quot; a1=&quot;auditd&quot;</code></pre>
<ul>
<li>전체 프로세스(<code>ps aux</code>) + <strong>보안 솔루션 특정 조회</strong>(<code>pgrep wazuh</code>, <code>pgrep auditd</code>) → 탐지 회피 준비</li>
<li>Wazuh·auditd 실행 확인 후 중지(A영역 39편)로 이어질 위험</li>
<li>계정·권한 정찰(C21~30)에 이어 프로세스 정찰 → 환경 장악 파악</li>
</ul>
<h2 id="7-로그-분석-분석-방법">7. 로그 분석 (분석 방법)</h2>
<p>프로세스 정찰 → 회피 준비 흐름입니다(가상의 예시 로그).</p>
<pre><code class="language-text">type=EXECVE ... a0=&quot;ps&quot; a1=&quot;aux&quot;
type=SYSCALL ... auid=devops ses=12 comm=&quot;ps&quot; key=&quot;recon_proc&quot;
type=EXECVE ... a0=&quot;pgrep&quot; a1=&quot;wazuh-agentd&quot;
[이후 가능] systemctl stop wazuh-agent (A영역 39편 하드닝 해제)</code></pre>
<table>
<thead>
<tr>
<th>관찰</th>
<th>해석</th>
</tr>
</thead>
<tbody><tr>
<td>ps aux</td>
<td>전체 프로세스</td>
</tr>
<tr>
<td>pgrep wazuh/auditd</td>
<td>보안 솔루션 조준</td>
</tr>
<tr>
<td>직후 중지 가능</td>
<td>탐지 회피(A영역 39편)</td>
</tr>
<tr>
<td>ses=12</td>
<td>프로세스 정찰</td>
</tr>
</tbody></table>
<p>보안 솔루션 조회 직후 중지가 나타나면 A영역 39편(하드닝 해제)과 연계해 탐지합니다.</p>
<h2 id="8-soc-관제-포인트">8. SOC 관제 포인트</h2>
<ul>
<li>프로세스 조회 중 <strong>보안 솔루션(wazuh·auditd·falco) 특정 조회</strong>를 최우선 확인합니다.</li>
<li>보안 솔루션 조회 직후 중지(A영역 39편)로 이어지는지 연계 감시합니다.</li>
<li>전체 프로세스 조회는 흔하므로, 보안 솔루션 조준·연속 정찰로 좁혀 판정합니다.</li>
</ul>
<h2 id="9-탐지-규칙">9. 탐지 규칙</h2>
<pre><code class="language-xml">&lt;!-- 실습 예시 룰: 적용 전 wazuh-logtest 및 테스트 환경 검증 필요 --&gt;
&lt;group name=&quot;local,syssec_c,recon,&quot;&gt;
  &lt;rule id=&quot;102300&quot; level=&quot;9&quot;&gt;
    &lt;if_group&gt;audit&lt;/if_group&gt;
    &lt;field name=&quot;audit.key&quot;&gt;recon_proc&lt;/field&gt;
    &lt;regex type=&quot;pcre2&quot;&gt;a1=&quot;?(wazuh|auditd|falco|clamav|osquery)&lt;/regex&gt;
    &lt;description&gt;보안 솔루션 프로세스 조회(탐지 회피 준비)&lt;/description&gt;
    &lt;mitre&gt;&lt;id&gt;T1518.001&lt;/id&gt;&lt;/mitre&gt;
  &lt;/rule&gt;
&lt;/group&gt;</code></pre>
<p><code>T1518.001</code>(Security Software Discovery)에 매핑됩니다. 보안 솔루션 조회(102300) + 중지(A영역 39편)를 상관하면 회피를 포착합니다.</p>
<h2 id="10-대응-방법">10. 대응 방법</h2>
<ol>
<li><strong>초기 확인</strong> — 프로세스 조회의 대상(보안 솔루션 포함)·연속성·주체를 확인합니다.</li>
<li><strong>범위 확인</strong> — 보안 솔루션 조회 직후 중지(A영역 39편)가 이어졌는지 확인합니다.</li>
<li><strong>증거 확보</strong> — 세션 조회 흐름을 보존합니다.</li>
<li><strong>차단/조치</strong> — 탈취 세션이면 B영역 대응과 보안 솔루션 상태 점검을 진행합니다.</li>
<li><strong>재발 방지</strong> — 보안 솔루션 조회를 회피 탐지 상관에 포함합니다.</li>
</ol>
<h2 id="11-핵심-정리">11. 핵심 정리</h2>
<table>
<thead>
<tr>
<th>조회</th>
<th>정보</th>
</tr>
</thead>
<tbody><tr>
<td>ps aux &#124; 전체 프로세스</td>
<td></td>
</tr>
<tr>
<td>pgrep wazuh/auditd &#124; 보안 솔루션 조준</td>
<td></td>
</tr>
<tr>
<td>top/htop &#124; 실시간</td>
<td></td>
</tr>
<tr>
<td>구분</td>
<td>서비스 점검(정상) vs 보안 솔루션 조회(회피 정찰)</td>
</tr>
<tr>
<td>면접 포인트</td>
<td>&quot;보안 솔루션 프로세스 조회는 탐지 회피 준비 — 직후 중지를 함께 본다&quot;</td>
</tr>
</tbody></table>
<h2 id="12-다음-편-예고">12. 다음 편 예고</h2>
<p>다음 편 <strong><a href="https://velog.io/@cs_security/syssec-c32">132. Linux 정보 수집 — 프로세스 트리 확인 분석</a></strong> 에서는 프로세스 관계 정찰인 <strong>프로세스 트리 확인 분석</strong>을 다룹니다.</p>
<hr>
<p>이전 편: <a href="https://velog.io/@cs_security/syssec-c30">130. Linux 정보 수집 — 사용자·권한 정보 수집 종합 분석</a><br>📚 시리즈 전체 보기: <a href="https://velog.io/@cs_security/series/system-security-vuln">시스템 보안 · 취약점</a></p>
]]></description>
        </item>
    </channel>
</rss>