本帖最后由 t0kenzero 于 2023-11-5 21:52 编辑
最近在测试样本中发现华为的个人版Hips日志中有检测但是没有阻断功能。提示是Subgraph is empty or front is nullptr. 不知道是没有做页面还是什么情况。
[2023-11-05 21:21:28.601][Info] [5892] [GRAPH THREAT ROOT]: [hitRule] TN0138, [riskScore] 90, [filePath] C:\Users\RhineLab\Desktop\Sample\svchost.exe, [rootType] NORMAL@EC
[2023-11-05 21:21:28.601][Info] [5892] [GRAPH THREAT RESULT]: [riskScore] 90,[hitRules] TN0138,NORMAL@EC,,[techniques] ,TN0138
[2023-11-05 21:21:28.603][Info] [5892] [HIPS ALERT]: Push, [ALERT INFO]: [threat_num]:TN0138, [severity]:4, [confidence_level]:90, [attack_count]:1, [ori_evt_count]:1, [disposal_count]:0
[2023-11-05 21:21:28.603][Info] [5892] [HIPS ATTACK EVIDENCE]: [PROCESS INFO] [pid]:8140, [process_name]:svchost.exe, [file_path]:C:\Users\RhineLab\Desktop\Sample\svchost.exe, [parent_pid]:6904, [parent_name]:explorer.exe, [command_line]:"C:\Users\RhineLab\Desktop\Sample\svchost.exe" , [action]:START
[2023-11-05 21:21:28.603][Info] [5892] [HIPS PERF ANALYSE]: [TIME CONSUME]:32(ms), [BYTE SIZE]:646
[2023-11-05 21:21:28.603][Info] [5892] [HIPS HipsAdapter][IsNeedShowInClient] Subgraph is empty or front is
nullptr.
而云端版本是检测有提示,但是无法自动拦截。可以手动处置(似乎报法也不大准,这个希望日后规则细化了
所以想问一下Hips功能是否会下放至个人版本。
然后提交一个误报,hips会把onedrive也一起给杀了
|