Spacebar Campaigns

HAC-002 AWS Control-Plane Local Admin Bridge Verification

Log ID:
HAC-002
Source:
AD-JBOSS\verify_aws_control_plane_win01_admin.py
Representative Path:
C:\Users\LG\Desktop\침해사고분석_프로젝트\AD-JBOSS\verify_aws_control_plane_win01_admin.py
Collection:
Manual redacted JSON output, optional HTTP collector -> current ELK index langflow-agent-*
Current Status:
현재 환경에서 검증 성공
Primary Use:
PMS SYSTEM 실행만으로 DPAPI 복호화가 된 것처럼 과장하지 않고, AWS control-plane으로 확보한 win01 local Administrator 컨텍스트를 별도 증거로 분리

검증 요약

이 로그는 dc_cred.xml 복호화 성공의 컨텍스트를 명확히 분리하기 위한 SB-07 보강 증거다.

확인된 흐름:

PMS patch compromise
-> win01 SYSTEM execution
-> dc_cred.xml discovered
-> SYSTEM Import-Clixml failed
-> AWS ec2:GetPasswordData with EC2 private key
-> win01 local Administrator WinRM/RDP context
-> local Administrator Import-Clixml succeeds
-> HANGUEL\Administrator credential object
-> DC WinRM/C$ access succeeds

대표 event.action

aws_get_password_data_win01_local_admin_verified
win01_local_admin_context
dc_cred_xml_imported
dc_winrm_whoami
dc_c_admin_share_access

주요 필드

필드의미예시
aws_get_password_data.password_data_presentEC2 password data 복호화 결과 존재 여부true
aws_get_password_data.password_data_length평문을 출력하지 않고 길이만 기록32
plaintext_printed비밀값 출력 여부false
win01_local_admin_context.whoamiwin01에서 확보된 local Administrator 컨텍스트ec2amaz-n2ogtl7\administrator
win01_local_admin_context.import_clixml_succeededlocal Administrator 컨텍스트에서 dc_cred.xml 복호화 성공 여부true
win01_local_admin_context.credential_username복호화된 credential object의 사용자명HANGUEL\Administrator
win01_local_admin_context.dc_winrm_succeeded해당 credential object로 DC WinRM whoami 성공 여부true
win01_local_admin_context.dc_c_admin_share_succeeded해당 credential object로 \\10.60.20.10\C$ 접근 성공 여부true

증거 경계

실행 예시

python .\AD-JBOSS\verify_aws_control_plane_win01_admin.py

선택적으로 HTTP collector에 redacted event를 보낼 수 있다.

python .\AD-JBOSS\verify_aws_control_plane_win01_admin.py --collector-url http://10.60.40.10:8088

Analyst Hunting KQL

collector로 전송한 경우:

campaign.id:"SB-07" and event.action:"aws_get_password_data_win01_local_admin_verified"
campaign.id:"SB-07" and event.action:("aws_get_password_data_win01_local_admin_verified" or "win01_local_admin_context" or "dc_cred_xml_imported" or "dc_winrm_whoami" or "dc_c_admin_share_access")
run.id:"SB07-AWS-BRIDGE-20260531135457" and log.id:"HAC-002"
campaign.id:"SB-07" and data.win01_local_admin_context.dc_winrm_succeeded:true and data.win01_local_admin_context.dc_c_admin_share_succeeded:true

현재 검증 결과