Chuyển đến nội dung chính

Bài 22: Blue Team — Detection Engineering

SIEM/SOAR, Sigma rules, detection-as-code, EDR bypass detection, threat hunting, SOC metrics, alert triage.

🔒 DevSecOps — Bài 22 Bài 22: Blue Team — Detection Engineering

Performance Testing & Pentest: Quy trình Chuẩn Doanh nghiệp 2026

Phần 5: Red/Blue/Purple Team & Compliance

xdev.asia

1. Blue Team — Tổng quan

Blue Team Responsibilities:

Detection:
  ├── SIEM monitoring & alerting
  ├── EDR/XDR event analysis
  ├── Network traffic analysis (NDR)
  ├── Log correlation & anomaly detection
  └── Threat intelligence integration

Response:
  ├── Incident triage & classification
  ├── Containment & eradication
  ├── Forensic investigation
  ├── Recovery & lessons learned
  └── Post-incident reporting

Engineering:
  ├── Detection rule development
  ├── Playbook/runbook creation
  ├── Tool integration & automation
  ├── Log source onboarding
  └── Detection gap analysis

Blue Team Stack:
  ┌──────────────────────────────────┐
  │   SOAR (Cortex XSOAR, Tines)    │
  ├──────────────────────────────────┤
  │   SIEM (Splunk, Elastic, Wazuh) │
  ├──────────────────────────────────┤
  │   EDR (CrowdStrike, Defender)   │
  ├──────────────────────────────────┤
  │   NDR (Zeek, Suricata, Corelight)│
  ├──────────────────────────────────┤
  │   Threat Intel (MISP, OTX)      │
  └──────────────────────────────────┘

2. Sigma Rules — Detection-as-Code

# Sigma rule — Detect credential dumping (Mimikatz)
title: Potential Credential Dumping via Mimikatz
id: 0d65a640-3f85-4f8c-8f76-74810a5b1234
status: stable
level: critical
description: Detects Mimikatz credential dumping activity
author: xDev Security Team
date: 2026/01/15
tags:
  - attack.credential_access
  - attack.t1003.001
  - attack.t1003.002

logsource:
  category: process_creation
  product: windows

detection:
  selection_binary:
    Image|endswith:
      - '\mimikatz.exe'
      - '\mimi.exe'
    
  selection_cmdline:
    CommandLine|contains:
      - 'sekurlsa::logonpasswords'
      - 'sekurlsa::wdigest'
      - 'lsadump::sam'
      - 'lsadump::dcsync'
      - 'token::elevate'
    
  selection_access:
    TargetImage|endswith: '\lsass.exe'
    GrantedAccess|contains:
      - '0x1010'
      - '0x1038'
      - '0x1fffff'

  condition: selection_binary or selection_cmdline or selection_access

falsepositives:
  - Legitimate security tools accessing LSASS
  
fields:
  - User
  - CommandLine
  - ParentImage
  - TargetImage
# Sigma rule — Detect reverse shell
title: Potential Reverse Shell Connection
id: 1a2b3c4d-5e6f-7890-abcd-reverseshell01
status: experimental
level: high
description: Detects processes spawning interactive reverse shells

logsource:
  category: process_creation
  product: linux

detection:
  selection_bash:
    CommandLine|contains:
      - 'bash -i >& /dev/tcp/'
      - 'bash -c "sh -i'
      - '/bin/sh -i'
    
  selection_netcat:
    CommandLine|contains:
      - 'nc -e /bin/sh'
      - 'ncat -e /bin/bash'
      - 'nc.traditional -e'
    
  selection_python:
    CommandLine|contains:
      - 'python -c "import socket,subprocess,os'
      - 'python3 -c "import socket'
      - 'import pty;pty.spawn'
    
  selection_socat:
    CommandLine|contains:
      - 'socat exec:'
      - 'socat tcp-connect:'

  condition: selection_bash or selection_netcat or selection_python or selection_socat

falsepositives:
  - Legitimate remote administration tools
  - Development/testing activities
# Convert Sigma rules to SIEM queries

# Install sigmac (Sigma converter)
pip install sigma-cli pySigma-backend-splunk pySigma-backend-elasticsearch

# Convert to Splunk query
sigma convert -t splunk -p sysmon sigma_rule.yml

# Convert to Elasticsearch (EQL)
sigma convert -t elasticsearch -p ecs_windows sigma_rule.yml

# Convert to QRadar AQL
sigma convert -t qradar sigma_rule.yml

# Batch convert all rules
sigma convert -t splunk -p sysmon rules/ -o splunk_rules/

3. SIEM Detection — Wazuh/Elastic

# Wazuh custom detection rules
# /var/ossec/etc/rules/custom_rules.xml



  
  
    5710
    SSH brute force detected: 5+ failed logins in 2 min
    
      T1110
    
  

  
  
    5901
    useradd
    New user account created
    
      T1136.001
    
  

  
  
    550
    chmod +s|chmod u+s|chmod 4
    SUID bit set on file — potential privilege escalation
    
      T1548.001
    
  

  
  
    550
    rm.*\.log|truncate.*\.log|echo.*>.*\.log
    Log file tampering detected
    
      T1070.002
    
  


4. Threat Hunting

Threat Hunting Process:

  Hypothesis
     │
     ▼
  Data Collection → What logs do we need?
     │
     ▼
  Investigation → Search for indicators
     │
     ├── Found? → Incident Response
     │
     └── Not found? → Refine hypothesis or new detection rule
     │
     ▼
  Documentation → Update playbooks, detections

Hunting Hypotheses (examples):
  1. "An attacker has compromised a service account
      and is performing lateral movement via SSH"
     → Hunt: Unusual SSH sessions from service accounts

  2. "A compromised CI/CD pipeline is deploying
      malicious container images"
     → Hunt: Container images from untrusted registries

  3. "Data exfiltration is occurring via DNS tunneling"
     → Hunt: Unusually long DNS queries, high DNS volume
# Threat Hunting Queries (Elastic/KQL)

# Hunt: Unusual outbound connections
# process.name:("curl" OR "wget" OR "python" OR "nc") AND
# destination.ip:* AND NOT destination.ip:(10.* OR 172.16.* OR 192.168.*)

# Hunt: Scheduled tasks created
# event.category:"process" AND process.name:"crontab" AND
# process.args:("-e" OR "-l")

# Hunt: SSH from unusual sources
# event.category:"authentication" AND event.action:"ssh_login" AND
# source.ip:* AND NOT source.ip:(10.0.0.* OR 192.168.1.*)

# Hunt: Large file transfers
# network.bytes > 100000000 AND
# destination.port:(443 OR 80 OR 8443) AND
# event.category:"network"

# Hunt: DNS tunneling indicators
# dns.question.name:* AND
# length(dns.question.name) > 50
# Group by source.ip, count unique dns.question.name > 100

5. SOC Metrics & KPIs

SOC Performance Metrics:

Detection:
  ├── MTTD (Mean Time to Detect)     Target: < 1 hour
  ├── Detection Coverage (ATT&CK %)  Target: > 80%
  ├── False Positive Rate             Target: < 10%
  └── True Positive Rate              Target: > 90%

Response:
  ├── MTTR (Mean Time to Respond)    Target: < 4 hours
  ├── MTTC (Mean Time to Contain)    Target: < 1 hour
  └── MTTR (Mean Time to Remediate)  Target: < 24 hours

Operational:
  ├── Alert Volume per analyst/day   Target: < 50
  ├── Alerts auto-resolved (SOAR)    Target: > 60%
  ├── Playbook coverage              Target: > 80%
  └── Analyst satisfaction score     Target: > 7/10

Reporting Dashboard:
  ├── Weekly: Alert trends, top detections
  ├── Monthly: MTTD/MTTR trends, coverage gaps
  └── Quarterly: ATT&CK coverage heat map

6. Tổng kết

  • Sigma Rules: Detection-as-code — write once, convert to any SIEM
  • SIEM: Wazuh/Elastic/Splunk for log correlation and alerting
  • Threat Hunting: Hypothesis-driven search for undetected threats
  • SOC Metrics: MTTD, MTTR, detection coverage, false positive rate
  • Stack: SIEM + EDR + NDR + SOAR + Threat Intel

Bài tiếp theo sẽ kết hợp Red + Blue thành Purple Team — Collaborative Security.