- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-09-2019 02:00 AM
こんにちは、スペシャリストの皆さん
私はPan-OS 8.1でwannacryに対する設定をする予定です
その設定が間違いなく動作するかを事前に確認したいです
ですが、私が本物のwannacryをPCに用意するわけにはいかないです
そこで、偽のwannacryをどうやって用意するかを悩んでいます
良いアイデアはありますか
ありがとう
09-09-2019 07:55 AM
The firewall itself can only prevent you from downloading the file in the first place, so testing this won't actually require you to run anything. Ransomware samples are prevelant; try to download some and if it actually downloads successfully.
The firewall should really only be one of the layers involved in your defence, and I wouldn't rely on it actually stopping users from downloading ransomware. If you are fully decrypting the traffic it should be able to catch files already identified by WildFire, but that only goes so far. I would recommend that you ensure you have something like Traps or CrowdStrike installed on your endpoints, as they both actually serve to stop the ransomware from actually locking down the system or spreading within your network.
When it comes to actual testing you don't do malware testing on just any machine. You want to make it so that the machine you are using for testing is actually isolated from anything else on your network if it needs any network connectivity at all; and I would generally recommend utilizing a sandboxed VM on an isolated host.
09-11-2019 09:45 AM
Hello,
Please listen to what BPry is saying. Always use a test machine and make sure its segregated from the rest of the network. If you subscribe to wildfire, you can test it as they have a test file to use.
https://wildfire.paloaltonetworks.com/wildfire/account
Regards,
09-24-2019 02:23 AM
エキスパートの皆さん
いくつかのアドバイスをありがとう
ぺネストレーションのツールとして、metasploitを選びました
脅威のアラートを確認することができました
みなさん、ありがとうございました
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!