{"id":953,"date":"2024-05-26T23:53:46","date_gmt":"2024-05-26T14:53:46","guid":{"rendered":"https:\/\/emeth.jp\/diary\/?p=953"},"modified":"2024-05-29T23:19:38","modified_gmt":"2024-05-29T14:19:38","slug":"yamatosecurity-aws-incident-response","status":"publish","type":"post","link":"https:\/\/emeth.jp\/diary\/2024\/05\/yamatosecurity-aws-incident-response\/","title":{"rendered":"\u5927\u548c\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u52c9\u5f37\u4f1a: AWS\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u5bfe\u5fdc\u5165\u9580 \u306b\u53c2\u52a0\u3057\u305f"},"content":{"rendered":"\n<p>4\/6\u306b\u795e\u6238\u3067\u3042\u3063\u305f\u3001\u5927\u548c\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306e\u52c9\u5f37\u4f1a\u300cAWS\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u5bfe\u5fdc\u5165\u9580\u300d\u306b\u53c2\u52a0\u3057\u3066\u304d\u305f\u3068\u3044\u3046\u30ec\u30dd\u3002<\/p>\n\n\n<div class=\"wp-block-su-blogcard\">\n\t<article class=\"wp-blogcard\" cite=\"https:\/\/yamatosecurity.connpass.com\/event\/313396\/\">\n\t\t<a\n\t\t\thref=\"https:\/\/yamatosecurity.connpass.com\/event\/313396\/\"\n\t\t\taria-label=\"\"\n\t\t\t\t\t\t\ttarget=\"_blank\"\n\t\t\t\t\t\t\t\t\t\trel=\"noopener noreferrer nofollow\"\n\t\t\t\t\t\tclass=\"wp-blogcard-item\"\n\t\t>\n\t\t\t\t\t\t<div class=\"wp-blogcard-content\">\n\t\t\t\t<div class=\"wp-blogcard-title\"><\/div>\n\t\t\t\t<div class=\"wp-blogcard-description\"><\/div>\n\t\t\t\t<div class=\"wp-blogcard-cite\">\n\t\t\t\t\t\t\t\t\t\t\t<img\n\t\t\t\t\t\t\tclass=\"wp-blogcard-favicon\"\n\t\t\t\t\t\t\tsrc=\"https:\/\/www.google.com\/s2\/favicons?domain=yamatosecurity.connpass.com&#038;sz=16\"\n\t\t\t\t\t\t\talt=\"\"\n\t\t\t\t\t\t\taria-hidden=\"true\"\n\t\t\t\t\t\t\/>\n\t\t\t\t\t\t\t\t\t\t<div class=\"wp-blogcard-domain\">yamatosecurity.connpass.com<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/a>\n\t<\/article>\n<\/div>\n\n\n\n<!--more-->\n\n\n\n<p>\u8cea\u306e\u9ad8\u3044\u52c9\u5f37\u4f1a\u3067\u5b9a\u8a55\u306e\u3042\u308b\u3001\u307e\u305fWindows\u30a4\u30d9\u30f3\u30c8\u30ed\u30b0\u306e\u89e3\u6790\u30c4\u30fc\u30eb<a href=\"https:\/\/github.com\/Yamato-Security\/hayabusa\/blob\/main\/README-Japanese.md\" target=\"_blank\" rel=\"noopener\" title=\"Hayabusa\">Hayabusa<\/a>\u306e\u958b\u767a\u3067\u77e5\u3089\u308c\u308b\u5927\u548c\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306e\u52c9\u5f37\u4f1a\u3067\u3042\u308b\u3002\u524d\u56de\u306e\u30aa\u30d5\u30e9\u30a4\u30f3\u52c9\u5f37\u4f1a\u306f\u6628\u5e743\u6708\u306e<a href=\"https:\/\/yamatosecurity.connpass.com\/event\/275368\/\" target=\"_blank\" rel=\"noopener\" title=\"2023\u5e74 TMCIT \u00d7 \u5927\u548c\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 WELA\u5fcd\u8005\u30c1\u30e3\u30ec\u30f3\u30b8\">2023\u5e74 TMCIT \u00d7 \u5927\u548c\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3 WELA\u5fcd\u8005\u30c1\u30e3\u30ec\u30f3\u30b8<\/a>\u3067\u3042\u3063\u305f\u306e\u3067\u5b9f\u306b1\u5e74\u3076\u308a\u306e\u30aa\u30d5\u30e9\u30a4\u30f3\u958b\u50ac\u3067\u3042\u308b\u3002\u4eca\u56de\u306e\u958b\u50ac\u5730\u306f\u795e\u6238\u3067\u79fb\u52d5\u3068\u5bbf\u6cca\u304c\u5fc5\u8981\u306b\u306a\u308b\u304c\u3001\u7fcc\u65e5\u306b<a href=\"https:\/\/yamatosecurity.connpass.com\/event\/312401\/\" target=\"_blank\" rel=\"noopener\" title=\"\u59eb\u8def\u57ce\u3067\u306e\u82b1\u898b\">\u59eb\u8def\u57ce\u3067\u306e\u82b1\u898b<\/a>\u3082\u4e88\u5b9a\u3055\u308c\u3066\u3044\u305f\u305f\u3081\u65c5\u884c\u6c17\u5206\u3067\u884c\u3053\u3046\u3068\u7533\u3057\u8fbc\u3093\u3060\u3089\u5f53\u9078\u3057\u305f\u306e\u3067\u884c\u3063\u3066\u304d\u305f\u3002<\/p>\n\n\n\n<p>\u8b1b\u5e2b\u306f\u3046\u3069\u3093\u5927\u597d\u304d\u3046\u3069\u3093\u5148\u751f\u3002\u7fcc\u65e5\u306e\u82b1\u898b\u306e\u5f8c\u3001\u9999\u5ddd\u770c\u306b\u3046\u3069\u3093\u3092\u98df\u3079\u306b\u65c5\u7acb\u3063\u3066\u3044\u304b\u308c\u305f\u3002\u3046\u3069\u3093\u611b\u304c\u3059\u3054\u3044\u3002<\/p>\n\n\n\n<p>\u52c9\u5f37\u4f1a\u306e\u304a\u984c\u306fAWS\u306e\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u5bfe\u5fdc\u3002\u30aa\u30f3\u30d7\u30ec\u30df\u30b9\u3067\u306e\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u5bfe\u5fdc\u6280\u8853\u306f\u305d\u308c\u306a\u308a\u306b\u7d4c\u9a13\u304c\u3042\u308b\u3051\u308c\u3069\u3001AWS\u3068\u3044\u3046\u304b\u30af\u30e9\u30a6\u30c9\u5168\u822c\u306f\u307e\u3060\u307e\u3060\u3088\u304f\u308f\u304b\u3063\u3066\u306a\u3044\u3053\u3068\u304c\u591a\u3044\u306e\u3067\u3053\u3046\u3044\u3046\u52c9\u5f37\u4f1a\u306f\u52a9\u304b\u308b\u3002<\/p>\n\n\n\n<p>\u4eca\u56de\u306e\u52c9\u5f37\u4f1a\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u5185\u5bb9\u3060\u3063\u305f\u3002<\/p>\n\n\n\n<dl class=\"wp-block-simple-definition-list-blocks-list\">\n<div class=\"wp-block-simple-definition-list-blocks-div\"><\/div>\n\n\n\n<dt class=\"wp-block-simple-definition-list-blocks-term\">AWS\u306e\u57fa\u790e<\/dt>\n\n\n\n<dd class=\"wp-block-simple-definition-list-blocks-details\">IAM\u307e\u308f\u308a\u3001\u30ea\u30fc\u30b8\u30e7\u30f3\u3001ARN\u306a\u3069\u3002\u3053\u306e\u8fba\u306f\u7406\u89e3\u3057\u3066\u3044\u308b\u3064\u3082\u308a\u3067\u3082\u308f\u304b\u3063\u3066\u306a\u304f\u3066\u3001\u8a71\u3092\u805e\u304f\u305f\u3073\u306b\u306a\u308b\u307b\u3069\u30fc\u3068\u306a\u308b\u3002<\/dd>\n\n\n\n<dt class=\"wp-block-simple-definition-list-blocks-term\">AWS\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b5\u30fc\u30d3\u30b9<\/dt>\n\n\n\n<dd class=\"wp-block-simple-definition-list-blocks-details\">CloudTrail\u3084GuardDuty\u306a\u3069\u306b\u3064\u3044\u3066\u3002\u307e\u305f\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30b5\u30fc\u30d3\u30b9\u5229\u7528\u6642\u306e\u6ce8\u610f\u70b9\u306b\u3064\u3044\u3066\u3001\u306a\u3069\u3002<\/dd>\n\n\n\n<dt class=\"wp-block-simple-definition-list-blocks-term\">AWS\u30ed\u30b0\u306e\u5206\u6790\u306b\u4f7f\u3046\u30b5\u30fc\u30d3\u30b9<\/dt>\n\n\n\n<dd class=\"wp-block-simple-definition-list-blocks-details\">CloudTrail\u306a\u3069\u306e\u30ed\u30b0\u306e\u5206\u6790\u306b\u4f7f\u3046\u30b5\u30fc\u30d3\u30b9\u306e\u8aac\u660e\u3002OpenSearch\u306b\u3064\u3044\u3066\u3002<\/dd>\n\n\n\n<dt class=\"wp-block-simple-definition-list-blocks-term\">\u653b\u6483\u8005\u306e\u6226\u7565<\/dt>\n\n\n\n<dd class=\"wp-block-simple-definition-list-blocks-details\">AWS\u30a2\u30ab\u30a6\u30f3\u30c8\u306e\u4fb5\u5bb3\u306e\u8d77\u70b9\u306b\u3064\u3044\u3066\u3002\u307e\u305f\u4fb5\u5bb3\u5f8c\u3001\u653b\u6483\u8005\u306f\u3069\u306e\u3088\u3046\u306a\u6d3b\u52d5\u3092\u3059\u308b\u304b\u3002<\/dd>\n\n\n\n<dt class=\"wp-block-simple-definition-list-blocks-term\">\u6f14\u7fd2<\/dt>\n\n\n\n<dd class=\"wp-block-simple-definition-list-blocks-details\">\u30b7\u30ca\u30ea\u30aa\u30d9\u30fc\u30b9\u306e\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u5bfe\u5fdc\u6f14\u7fd2\u3002<\/dd>\n<\/dl>\n\n\n\n<p>\u611f\u60f3\u3002<br>AWS\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306b\u3064\u3044\u3066\u306f\u4f55\u5ea6\u304b\u5b66\u3076\u6a5f\u4f1a\u304c\u3042\u3063\u305f\u3082\u306e\u306e\u3001\u306a\u304b\u306a\u304bIAM\u306a\u3069\u30a2\u30af\u30bb\u30b9\u6a29\u5468\u308a\u304c\u3046\u307e\u304f\u7406\u89e3\u3057\u304d\u308c\u306a\u3044\u307e\u307e\u3067\u3042\u3063\u305f\u3002\u904e\u53bb\u306e\u6559\u80b2\u8cc7\u6599\u3084\u4eca\u56de\u306e\u8cc7\u6599\u3092\u5b66\u3073\u306a\u304a\u3057\u3066\u3061\u3083\u3093\u3068\u6b63\u3057\u3044\u7406\u89e3\u3092\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u305f\u3044\u3002<\/p>\n\n\n\n<p>\u307e\u305f\u3001\u5f53\u7136\u3068\u3044\u3048\u3070\u5f53\u7136\u3060\u304c\u3001AWS\u306e\u5bfe\u5fdc\u3092\u3059\u308b\u305f\u3081\u306b\u306fAWS\u306b\u3064\u3044\u3066\u306e\u81a8\u5927\u306a\u77e5\u8b58\u3068\u6df1\u3044\u7406\u89e3\u304c\u5fc5\u8981\u306b\u306a\u308a\u3001\u540c\u69d8\u306e\u4e8b\u60c5\u304c\u30af\u30e9\u30a6\u30c9\u30d9\u30f3\u30c0\u306e\u6570\u3060\u3051\u5b58\u5728\u3059\u308b\u3001\u3068\u3044\u3046\u3053\u3068\u3092\u5b9f\u611f\u3057\u305f\u3002\u30aa\u30f3\u30d7\u30ec\u306e\u5834\u5408\u306fWindows\u3084Linux\u3042\u305f\u308a\u304c\u308f\u304b\u308c\u3070\u3044\u3044\uff08\u3068\u7c21\u5358\u306b\u8a00\u3048\u308b\u3082\u306e\u3067\u3082\u306a\u3044\uff09\u304c\u3001\u30af\u30e9\u30a6\u30c9\u306b\u5bfe\u5fdc\u3059\u308b\u305f\u3081\u306b\u306f\u305d\u308c\u306b\u52a0\u3048\u3066\u5225\u6b21\u5143\u306e\u5b66\u7fd2\u304c\u5fc5\u8981\u306b\u306a\u308b\u3002\u30af\u30e9\u30a6\u30c9\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u3092\u5f37\u3081\u308b\u306e\u306f\u306a\u304b\u306a\u304b\u9053\u304c\u967a\u3057\u3044\u3002<\/p>\n\n\n\n<p>\u305d\u306e\u4e0a\u3001AWS\u306b\u306fAWS\u7279\u6709\u306e\u7656\u304c\u3042\u3063\u305f\u308a\u3059\u308b\u306e\u3067\u3042\u308b\u3002GuardDuty\u306f\u30ea\u30fc\u30b8\u30e7\u30f3\u3054\u3068\u306b\u6709\u52b9\u306b\u3057\u306a\u3044\u3068\u3044\u3051\u306a\u3044\u306e\u3067\u5168\u30ea\u30fc\u30b8\u30e7\u30f3\u305d\u308c\u305e\u308c\u3067\u6709\u52b9\u306b\u3057\u306a\u3044\u3068\u7a74\u304c\u3042\u308b\u72b6\u614b\u306b\u306a\u3063\u3066\u3057\u307e\u3046\u3001\u3068\u304b\u7f60\u306b\u3082\u307b\u3069\u304c\u3042\u308b\u3002<\/p>\n\n\n\n<p>\u30b7\u30ca\u30ea\u30aa\u30d9\u30fc\u30b9\u306e\u6f14\u7fd2\u3082\u826f\u304b\u3063\u305f\u3002\u5b9f\u969b\u306b\u8d77\u3053\u308a\u3046\u308b\u30b1\u30fc\u30b9\u3068\u3057\u3066\u6f14\u7fd2\u3092\u3059\u308b\u3053\u3068\u3067\u9ad8\u3044\u30ea\u30a2\u30ea\u30c6\u30a3\u3092\u611f\u3058\u3089\u308c\u308b\u3002\u8abf\u67fb\u3092\u9032\u3081\u3066\u3044\u304f\u969b\u306e\u7740\u773c\u70b9\u3082\u53c2\u8003\u306b\u306a\u3063\u305f\u3002\u3053\u308c\u3092\u30ce\u30fc\u30d2\u30f3\u30c8\u3067\u3067\u304d\u308b\u304b\u3068\u3044\u3046\u3068\u5f53\u7136\u3067\u304d\u306a\u3044\u306e\u3067\u3001\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308b\u305f\u3081\u306b\u306f\u3053\u306e\u3088\u3046\u306a\u6f14\u7fd2\u306a\u3069\u3067\u77e5\u898b\u3092\u84c4\u3048\u3066\u52d8\u6240\u3092\u80b2\u3066\u3066\u3044\u304f\u3053\u3068\u304c\u5fc5\u8981\u306a\u306e\u3060\u3002<\/p>\n\n\n\n<p>\u5b66\u3073\u306e\u591a\u3044\u826f\u3044\u52c9\u5f37\u4f1a\u3060\u3063\u305f\u3002\u4e16\u306e\u4e2d\u3053\u308c\u3060\u3051\u30af\u30e9\u30a6\u30c9\u304c\u4f7f\u308f\u308c\u3066\u3044\u308b\u4e2d\u3067\u3001\u5b88\u308b\u5074\u306e\u4eba\u9593\u304c\u4f55\u3082\u77e5\u3089\u306a\u3044\u3067\u3044\u3044\u308f\u3051\u304c\u306a\u3044\u306e\u3067\u3001\u3057\u3063\u304b\u308a\u5b66\u3093\u3067\u3044\u3053\u3046\u3068\u601d\u3046\u3002\u307e\u3060\u307e\u3060\u3072\u3088\u3063\u3053\u3067\u3059\u304c\u3088\u308d\u3057\u304f\u304a\u9858\u3044\u3057\u307e\u3059\u3002\u3074\u3088\u3074\u3088\u3002<\/p>\n\n\n\n<p>\u6b21\u306fAzure\u306e\u4f1a\u304c\u3042\u308b\u3088\u3046\u306a\u306e\u3067\u3001\u8208\u5473\u306e\u3042\u308b\u65b9\u306f\u662f\u975e\u7533\u3057\u8fbc\u307f\u3057\u3088\u3046\u3002\u3051\u3058\u3081\u3068\u3057\u3066\u3053\u306e\u8a18\u4e8b\u3092\u66f8\u304d\u7d42\u3048\u305f\u306e\u3067\u79c1\u3082\u7533\u3057\u8fbc\u3080\u3088\u3002<\/p>\n\n\n<div class=\"wp-block-su-blogcard\">\n\t<article class=\"wp-blogcard\" cite=\"https:\/\/yamatosecurity.connpass.com\/event\/319143\/\">\n\t\t<a\n\t\t\thref=\"https:\/\/yamatosecurity.connpass.com\/event\/319143\/\"\n\t\t\taria-label=\"\"\n\t\t\t\t\t\t\ttarget=\"_blank\"\n\t\t\t\t\t\t\t\t\t\trel=\"noopener noreferrer nofollow\"\n\t\t\t\t\t\tclass=\"wp-blogcard-item\"\n\t\t>\n\t\t\t\t\t\t<div class=\"wp-blogcard-content\">\n\t\t\t\t<div class=\"wp-blogcard-title\"><\/div>\n\t\t\t\t<div class=\"wp-blogcard-description\"><\/div>\n\t\t\t\t<div class=\"wp-blogcard-cite\">\n\t\t\t\t\t\t\t\t\t\t\t<img\n\t\t\t\t\t\t\tclass=\"wp-blogcard-favicon\"\n\t\t\t\t\t\t\tsrc=\"https:\/\/www.google.com\/s2\/favicons?domain=yamatosecurity.connpass.com&#038;sz=16\"\n\t\t\t\t\t\t\talt=\"\"\n\t\t\t\t\t\t\taria-hidden=\"true\"\n\t\t\t\t\t\t\/>\n\t\t\t\t\t\t\t\t\t\t<div class=\"wp-blogcard-domain\">yamatosecurity.connpass.com<\/div>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/a>\n\t<\/article>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>4\/6\u306b\u795e\u6238\u3067\u3042\u3063\u305f\u3001\u5927\u548c\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u306e\u52c9\u5f37\u4f1a\u300cAWS\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u5bfe\u5fdc\u5165\u9580\u300d\u306b\u53c2\u52a0\u3057\u3066\u304d\u305f\u3068\u3044\u3046\u30ec\u30dd\u3002<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"cybocfi_hide_featured_image":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-953","post","type-post","status-publish","format-standard","hentry","category-1"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/emeth.jp\/diary\/wp-json\/wp\/v2\/posts\/953","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/emeth.jp\/diary\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/emeth.jp\/diary\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/emeth.jp\/diary\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/emeth.jp\/diary\/wp-json\/wp\/v2\/comments?post=953"}],"version-history":[{"count":7,"href":"https:\/\/emeth.jp\/diary\/wp-json\/wp\/v2\/posts\/953\/revisions"}],"predecessor-version":[{"id":962,"href":"https:\/\/emeth.jp\/diary\/wp-json\/wp\/v2\/posts\/953\/revisions\/962"}],"wp:attachment":[{"href":"https:\/\/emeth.jp\/diary\/wp-json\/wp\/v2\/media?parent=953"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/emeth.jp\/diary\/wp-json\/wp\/v2\/categories?post=953"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/emeth.jp\/diary\/wp-json\/wp\/v2\/tags?post=953"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}