<<前へ 次へ>>

質問 58/73

内部監査により、管理者権限を持たないユーザーが「seclogon.exe」(RunAs)や「psexec.exe」(Sysinternals)などのWindows組み込みツールを使用した権限昇格の試みを検出する際に、ギャップがあることが判明しました。これらのツールは正規のツールですが、悪用されることが少なくありません。目標は、標準ユーザーコンテキストから「seclogon.exe」または「psexec.exe」が呼び出され、その後に別のシステムで機密性の高いコマンドを実行しようとしたり、ローカルで権限を昇格しようとしたりするプロセスを検出することです。正当なIT運用による誤検知を最小限に抑えつつ、この動作をBIOCとして効果的に捕捉できるXQLクエリはどれでしょうか?

コメントを発表する

あなたのメールアドレスは公開されません。必要な部分に * が付きます。

質問一覧「73問」
質問1 An XSIAM deployment utilizes a robust custom role definition...
質問2 A cybersecurity analyst consistently searches for suspicious...
質問3 XSIAM導入における重要な要件の一つは、サードパーティ製SOARプ...
質問4 An organization is struggling with alert fatigue from a poor...
質問5 A company is planning to integrate XSIAM with its highly cus...
質問6 Palo Alto Networks の XSIAM エンジニアが、取り込まれたエンド...
質問7 XSIAM 管理者は、ブローカー VM のファームウェア更新後に特定の...
質問8 A multinational corporation uses Palo Alto Networks XSIAM to...
質問9 A red team exercise revealed that traditional IOCs (e.g., ha...
質問10 A cybersecurity firm develops a proprietary threat intellige...
質問11 A new zero-day exploit targeting a widely used web server ap...
質問12 An XSIAM engineer is troubleshooting why a specific 'Lateral...
質問13 XSIAM 管理者がエンドポイント セキュリティ ポスチャのダッシュ...
質問14 Consider a large enterprise that uses XSIAM and also has a s...
質問15 貴社では XSIAM を使用しており、Linux 環境内での「権限昇格」...
質問16 ルールレビュー中に、XSIAMエンジニアは、疑わしいパターンに一...
質問17 新しいコンテンツパックをデプロイした後、ユーザーが関連するプ
質問18 A Cortex XSIAM engineer is implementing role-based access co...
質問19 An XSIAM engineer is troubleshooting why a specific 'Malware...
質問20 Cortex XSIAMテナントをアクティブ化する際、保存されているデー...
質問21 XSIAM の展開では、独自の複数行 JSON 形式でログをエクスポート...
質問22 A security analyst is designing an automation workflow in XS...
質問23 ある金融機関がXSIAMを導入しており、堅牢な脅威インテリジェン...
質問24 A large enterprise is migrating security logs from an on-pre...
質問25 Cortex XDRエージェントの管理にローリングトークンを使用する目...
質問26 An XSIAM engineer is troubleshooting a scenario where endpoi...
質問27 What should be considered when creating a custom incident do...
質問28 Palo Alto Networks XSIAM を使用しているセキュリティオペレー...
質問29 Consider an organization deploying Palo Alto Networks XSIAM ...
質問30 大規模な XSIAM 展開では、さまざまなベンダー (Palo Alto Netwo...
質問31 To enable authentication integration for automated user prov...
質問32 The CISO requests a custom XSIAM reporting template that pro...
質問33 ルールレビュー中に、XSIAMエンジニアは、疑わしいパターンに一...
質問34 Which installer type should be used when upgrading a non-Lin...
質問35 A company's XSIAM instance is generating a high volume of 'P...
質問36 XSIAM エンジニアは、重要な「データ漏洩試行」検出ルールのアラ...
質問37 A critical XSIAM dashboard needs to display the health of in...
質問38 Your organization requires a 'Chain of Custody' section on e...
質問39 ある企業が、Ansible を使用して Cortex XSIAM エージェントのデ...
質問40 Which two requirements must be met for a Cortex XDR agent to...
質問41 A financial institution uses XSIAM and has a critical requir...
質問42 A Palo Alto Networks XSIAM engineer is tasked with optimizin...
質問43 ある組織が、従来のSIEMからPalo Alto Networks XSIAMへの移行を...
質問44 A systems engineer overseeing the integration of data from v...
質問45 大手多国籍企業がCortex XSIAMをグローバルに展開しています。同...
質問46 A critical application exports its security audit logs in a ...
質問47 Windowsイベントログを収集し、XSIAMブローカーに送信するPython...
質問48 The following string is a value of a key named "Data2" in th...
質問49 (Exhibit) この問題の最も可能性の高い原因は何ですか?...
質問50 最高情報セキュリティ責任者(CISO)が、特定のユーザーに割り当...
質問51 An XSIAM engineer is tasked with optimizing a 'Phishing Emai...
質問52 大手ソフトウェア開発会社が、LinuxベースのビルドサーバーにCor...
質問53 A Security Operations Center (SOC) using Palo Alto Networks ...
質問54 A new XSIAM content pack deployment for cloud security postu...
質問55 A Security Orchestration, Automation, and Response (SOAR) pl...
質問56 An XSIAM engineer is reviewing an existing detection rule de...
質問57 A security architect is designing the integration of XSIAM w...
質問58 内部監査により、管理者権限を持たないユーザーが「seclogon.exe...
質問59 XSIAM 設定のデバッグを行っています。重大な「DLP 情報漏洩」ア...
質問60 A distributed organization with multiple branch offices, eac...
質問61 A financial institution is planning to deploy Palo Alto Netw...
質問62 あるグローバル金融機関が、Palo Alto Networks XSIAM導入のため...
質問63 Which type of parsing error is categorized in the dataset "p...
質問64 Consider an XSIAM deployment receiving 'Network Connection' ...
質問65 A newly deployed XSIAM indicator rule designed to detect 'Ra...
質問66 A critical XSIAM automation rule is designed to automaticall...
質問67 'PsExec' の横方向移動への不審な使用を検出するために、XSIAM ...
質問68 As a Palo Alto Networks XSIAM Engineer, you are tasked with ...
質問69 An XSIAM engineer is observing that a specific custom log so...
質問70 A Security Operations Center (SOC) using Palo Alto Networks ...
質問71 A critical XSIAM dashboard needs to display the health of in...
質問72 What are two commonly used automation integrations in Cortex...
質問73 A global conglomerate with operations in multiple geopolitic...