⫷⟦🧑💻💻 𝑬𝑻𝑯𝑰𝑪𝑨𝑳 𝑪𝒀𝑩𝑬𝑹𝑺𝑬𝑪𝑼𝑹𝑰𝑻𝒀 𝑨𝑾𝑨𝑹𝑬𝑵𝑬𝑺𝑺 𝑪𝑯𝑨𝑵𝑵𝑬𝑳 ™ 🇱🇰 💻🧑💻⟧⫸
رفتن به کانال در Telegram
✳️ What Followers Will Get (Classy & Ethical) ✳️ 💻 Daily Cybersecurity & Safety Tips 🛡️ Ethical Digital Practices & Privacy 🔐 Encryption, Password & Data Protection 💎 Motivation & Tech Growth 👻 Tech, Mysticism & Digital Curiosities
نمایش بیشتر334
مشترکین
+124 ساعت
+47 روز
+1230 روز
در حال بارگیری داده...
کانالهای مشابه
هیچ دادهای
مشکلی وجود دارد؟ لطفاً صفحه را تازه کنید یا با مدیر پشتیبانی ما تماس بگیرید.
ابر برچسبها
اشارات ورودی و خروجی
---
---
---
---
---
---
جذب مشترکین
سپتامبر '26
سپتامبر '26
+7
در 1 کانالها
اوت '26
+31
در 1 کانالها
Get PRO
ژوئیه '26
+16
در 1 کانالها
Get PRO
ژوئن '26
+20
در 1 کانالها
Get PRO
مه '26
+45
در 1 کانالها
Get PRO
آوریل '26
+34
در 1 کانالها
Get PRO
مارس '26
+50
در 1 کانالها
Get PRO
فوریه '26
+177
در 1 کانالها
Get PRO
ژانویه '260
در 1 کانالها
Get PRO
دسامبر '25
+49
در 1 کانالها
| تاریخ | رشد مشترکین | اشارات | کانالها | |
| 05 سپتامبر | +1 | |||
| 04 سپتامبر | +1 | |||
| 03 سپتامبر | +1 | |||
| 02 سپتامبر | 0 | |||
| 01 سپتامبر | +4 |
پستهای کانال
🦠 MALWARE BIBLE — FREE LEARNING RESOURCE
Looking to learn more about the defensive side of cybersecurity.? 🔐
This open educational project focuses on:
🔹 Malware Analysis
🔹 Reverse Engineering
🔹 Cybersecurity
🔹 Programming
🔹 Threat Research
🔹 Security Education
📚 Useful for students, researchers, aspiring malware analysts, and anyone interested in understanding malicious software and defending systems.
🔗 Explore / Access:
Malware Bible on GitHub : https://github.com/Perkins-Fund/Malware-Bible
🛡 Learn to understand threats not create them.
| 2 | • මෙතන GPS Latitude සහ Longitude values තිබුණොත්, ඒවා map service එකක භාවිතා කරලා photo එක ගත්ත location එක ගැන හොයාගන්න පුළුවන්.
🌍 REAL-WORLD USE CASE
• 2012 අවුරුද්දේදී VICE සඟරාව John McAfee සමඟ සිටින බව කියමින් ඔහුගේ photo එකක් online publish කළා.
• ඒ අවස්ථාවේ photo එකේ තිබුණු EXIF metadata ගැන විශාල අවධානයක් යොමු වුණා. Reports අනුව metadata එකෙන් photo එකේ location ගැන තොරතුරු ලබාගත හැකි වුණා.
• ඉන්පසු John McAfee Guatemala හි සිටින බව හෙළි වීමත් සමඟ ඔහු එහිදී අත්අඩංගුවට ගත්තා.
• මේ සිදුවීමෙන් පේන්නේ photo එකක metadata එකක් වුණත් privacy සහ investigation පැත්තෙන් කොච්චර වැදගත් වෙන්න පුළුවන්ද කියන එක.
⚠️ COMMON MISTAKES.
• Beginners ලා ExifTool පාවිච්චි කරද්දී කරන වැරදි කිහිපයක් තියෙනවා.
1️⃣ Social Media Images Scan කිරීම
• Facebook, WhatsApp, Instagram වගේ platforms වලට photo එකක් upload කළාම platform එක අනුව metadata remove හෝ alter වෙන්න පුළුවන්.
• ඒ නිසා social media එකෙන් download කරපු image එකක original GPS metadata තියෙනවා කියලා assume කරන්න බැහැ.
2️⃣ ExifTool එක Steganography එක්ක පටලවාගැනීම.
• Steghide වගේ tools වලින් image එකක් ඇතුළේ වෙනත් data/file එකක් hide කරන්න පුළුවන්.
• ExifTool වලින් ප්රධාන වශයෙන් බලන්නේ file එකේ metadata.
• දෙක සම්පූර්ණයෙන්ම වෙනස් concepts දෙකක්.
3️⃣ Original File එක නොමැතිව Metadata හොයන්න යාම.
• Metadata හොයනකොට හැකි තරම් original file එක පාවිච්චි කරන එක වැදගත්.
• Screenshot එකක්, social media download එකක්, compressed copy එකක් වගේ එකක් පාවිච්චි කළොත් original metadata දැනටමත් නැති වෙලා තිබෙන්න පුළුවන්.
💡 BEGINNER TIP
• ඔයා WhatsApp එකෙන් photo එකක් යවනකොට සාමාන්ය photo එකක් විදිහට යැව්වොත්, WhatsApp එක processing/compression කරන නිසා original metadata එකේ කොටස් ඉවත් වෙන්න පුළුවන්.
• හැබැයි photo එක Document/File එකක් විදිහට යවනකොට original file එක preserve වෙන අවස්ථා තියෙනවා.
• ඒ නිසා private photo එකක් document/file එකක් විදිහට යවනකොට, ඒකේ metadata තුළ location වගේ sensitive information තියෙනවද කියලා දැනගෙන ඉන්න එක වැදගත්.
⚠️ SECURITY NOTE.
• Internet එකට හෝ forums වලට sensitive photos සහ PDF documents — Resumes, Reports වගේ files — upload කරන්න කලින් ඒවායේ metadata ගැන check කරන්න.
• අවශ්ය නම් ExifTool හෝ ඒ හා සමාන metadata sanitization tool එකක් භාවිතා කරලා personal information remove කරන්න.
• මොකද photo එකේ පේන දේ විතරක් නෙවෙයි.
• Photo එක ඇතුළේ නොපෙනෙන දත්තත් ඔයා ගැන තොරතුරු කියන්න පුළුවන්.
📚 Sources / Further Reading
ExifTool Official Website:
```exiftool.org
```
• OWASP Metadata Vulnerabilities | 180 |
| 3 | 📸 ෆොටෝ එකක් ගත්තේ කොහෙදිද.? කීයටද.? පාවිච්චි කළේ මොන ෆෝන් එකද.? හරියටම දැනගන්න පුළුවන්ද.?
• ඔයා යාළුවෙක්ට යවන සාමාන්ය ෆොටෝ එකක් ඇතුළේ, ඔයා ඉන්න තැනේ GPS location එක, පාවිච්චි කරපු ෆෝන් එකේ model එක, ෆොටෝ එක ගත්ත වෙලාව වගේ දේවල් හැංගිලා තියෙන්න පුළුවන් කිව්වොත් විශ්වාස කරනවද.?
• බැලූ බැල්මට මේ කිසිම දෙයක් පේන්නේ නැහැ. හැබැයි digital forensics සහ OSINT කරන අයට මේ වගේ තොරතුරු හොයාගන්න පුළුවන්.
• ඒකට පාවිච්චි කරන ප්රසිද්ධ tool එකක් තමයි ExifTool.
🛠️ ExifTool කියන්නේ මොකක්ද.?
• ExifTool කියන්නේ Phil Harvey විසින් Perl language එකෙන් නිර්මාණය කරපු powerful, open-source command-line application එකක්.
• මේකෙන් photos, videos, PDFs, audio files වගේ files ඇතුළේ තියෙන Metadata කියවන එක, වෙනස් කරන එක එහෙම නැත්නම් සම්පූර්ණයෙන්ම මකා දාන එක කරන්න පුළුවන්.
• Metadata කියන්නේ සරලව කිව්වොත් “දත්ත ගැන තියෙන දත්ත”.
📱 මේක වැඩ කරන්නේ කොහොමද.?
• අපි digital camera එකකින් හෝ smartphone එකකින් photo එකක් ගන්නකොට device එකෙන් ඒ photo එකට ස්වයංක්රීයවම විවිධ metadata එකතු වෙන්න පුළුවන්.
ඒ අතරේ
📷 Camera Model
📐 Resolution
⏱️ Shutter Speed
💡 ISO
🖥️ Software
📅 Date & Time
• වගේ තොරතුරු තියෙන්න පුළුවන්.
• ඒ වගේම phone එකේ Location Services on කරලා තිබුණොත්, photo එකට GPS coordinates පවා save වෙලා තියෙන්න පුළුවන්.
• ExifTool එකෙන් කරන්නේ මේ file එක ඇතුළේ තියෙන metadata extract කරලා අපිට කියවන්න පුළුවන් විදිහට terminal එකේ පෙන්නන එක.
🕵️ Cybersecurity වලට මේක වැදගත් ඇයි.?
• Digital Forensics සහ OSINT (Open-Source Intelligence) වලදී metadata කියන්නේ වැදගත් source එකක්.
• කෙනෙක් internet එකට upload කරන photo එකක හෝ PDF එකක metadata ඉතුරු වෙලා තිබුණොත්, ඒකෙන් device එක, software එක, creation date එක වගේ තොරතුරු හොයාගන්න පුළුවන්.
• සමහර අවස්ථාවල location information පවා තිබෙන්න පුළුවන්.
• ඒ නිසා පොඩි metadata එකකින් පවා investigation එකකට වැදගත් clue එකක් ලැබෙන්න පුළුවන්. 🔎
🐉 Kali Linux Setup
• ExifTool Kali Linux වල බොහෝ වෙලාවට available වෙන tool එකක්.
• Terminal එකේ මේ command එක ගහලා version එක check කරලා බලන්න:
exiftool -ver
• System එකේ නැත්නම් install කරගන්න පුළුවන්:
sudo apt update && sudo apt install libimage-exiftool-perl
🧪 LAB SCENARIO
• අද අපි මේ tool එක test කරන්නේ අපේම computer එකේ තියෙන test photo එකක් පාවිච්චි කරලා.
• Analyst: Kali Linux User
• Target: Local Image File (target_image.jpg)
• Purpose: Metadata Extraction (තොරතුරු රැස් කිරීම) සහ Data Sanitization (දත්ත මකා දැමීම)
• Authorization: Own files (Authorized Testing)
1️⃣ STEP 1 — Photo එකේ සියලුම Metadata කියවීම.
• මුලින්ම photo එකේ තියෙන metadata ටික බලමු.
exiftool target_image.jpg
• මේකෙන් වෙන්නේ photo එක scan කරලා ඒකේ තියෙන File Size, Create Date, Camera Make, Software Version වගේ metadata ගොඩක් terminal එකේ list එකක් විදිහට පෙන්නන එක.
2️⃣ STEP 2 — GPS Location එක විතරක් බලමු.
• Output එක ගොඩක් දිග නම්, GPS සම්බන්ධ metadata විතරක් filter කරගන්න පුළුවන්.
exiftool -gps* target_image.jpg
• මෙතන -gps* wildcard එක නිසා GPS සම්බන්ධ tags පෙන්නනවා.
• Photo එකේ GPS metadata තිබුණොත්, Latitude සහ Longitude වගේ coordinates මෙතනින් දැකගන්න පුළුවන්.
• ඒ coordinates map එකක දාලා photo එක ගත්ත location එක ගැන තොරතුරු ලබාගන්න පුළුවන්.
3️⃣ STEP 3 — Photo එකේ Metadata මකා දැමීම.
• ඔයා internet එකට photo එකක් හෝ document එකක් upload කරන්න කලින් ඒකේ තියෙන personal metadata remove කරන්න ඕනේ නම් ExifTool භාවිතා කරන්න පුළුවන්.
exiftool -all= target_image.jpg
• මෙතන -all= කියන්නේ metadata tags ඉවත් කරන විදිහට ExifTool එකට කියන එක.
• මේක privacy protection සඳහා ප්රයෝජනවත්.
⚠️ හැබැයි original file එක overwrite කිරීමේදී පරිස්සම් වෙන්න. වැදගත් original file එකක් නම් backup එකක් තියාගෙන වැඩ කරන එක හොඳ පුරුද්දක්.
📊 OUTPUT එක කියවන්නේ කොහොමද.?
• සාමාන්ය photo එකක් scan කළාම මෙන්න මේ වගේ output එකක් බලාගන්න පුළුවන්:
Make : Apple
Camera Model Name : iPhone 13 Pro
Date/Time Original : 2023:10:15 14:30:00
Software : iOS 16.5
GPS Latitude : 6 deg 55' 38.2" N
GPS Longitude : 79 deg 51' 29.5" E | 160 |
| 4 | بدون متن... | 131 |
| 5 | 🔐 ගෙදර Wi-Fi එකට හොඳට අමාරු password එකක් දාලා තියෙන නිසා 100% safe කියලා හිතනවද.?
එහෙනම් මේ ගැන දැනගෙන ඉන්න එක වටිනවා.
ගොඩක් අය හිතන්නේ Wi-Fi එකක් hack කරන්න නම් hacker කෙනෙක් ගෙදර ළඟට වෙලා, laptop එකෙන් password එකින් password එක try කර කර ඉන්න ඕනේ කියලා.
ඒත් WPA2 Wi-Fi එකක වැඩේ ඊට ටිකක් වෙනස්.
📡 මේ 4-Way Handshake එක මොකක්ද.?
ඔයාගේ phone එක Wi-Fi router එකට connect වෙනකොට phone එකයි router එකයි අතර authentication process එකක් සිද්ධ වෙනවා.
ඔයාගේ Wi-Fi password එක plain text විදිහට air එකේ යන්නේ නෑ. ඒ වෙනුවට cryptographic information පාවිච්චි කරලා phone එකයි router එකයි එකිනෙක verify කරගන්නවා.
මේ exchange එක attacker කෙනෙක් capture කරගත්තොත් පස්සේ Wi-Fi එක ළඟ ඉන්නෙ නැතුවත් ඒ captured data එක අරගෙන password guesses offline විදිහට test කරන්න පුළුවන්.
🖐️ ඒක තමයි මෙතන තියෙන ලොකුම අවදානම.
Password එක නමක්, birthday එකක්, phone number එකක් dictionary word එකක් වගේ ලේසියෙන් guess කරන්න පුළුවන් එකක් නම් තත්වය තවත් අවදානම්.
තව දෙයක් handshake එක capture කරන්න deauthentication වගේ techniques භාවිතා කරන්න පුළුවන්. හැබැයි හැම වෙලාවෙම deauth attack එකක් කරන්නම ඕනේ නෑ. Client එකක් සාමාන්ය විදිහට reconnect වෙන වෙලාවකත් handshake එක capture වෙන්න පුළුවන්.
🛡️ එහෙනම් Wi-Fi එක ආරක්ෂිත කරගන්නේ කොහොමද.?
• Router එක support කරනවා නම් WPA3-Personal භාවිතා කරන්න
• දිග unique සහ guess කරන්න අමාරු password එකක් දාන්න
• WPS අවශ්ය නැත්නම් disable කරන්න
• Router firmware එක update කරගෙන යන්න
• Router එකේ default admin password එක අනිවාර්යයෙන්ම වෙනස් කරන්න
අන්තිමට එක දෙයක් මතක තියාගන්න. 👇
Strong password එකක් තියෙන එක හොඳ ආරක්ෂාවක්. හැබැයි ඒකෙන් Wi-Fi එක 100% unhackable වෙනවා කියලා අදහස් වෙන්නේ නෑ.
Cybersecurity කියන්නේ එක security setting එකක් ගැන නෙවෙයි.
Layers කිහිපයක් එකට තියෙන එක ගැන. 🔒💻 | 150 |
| 6 | 🔐 ගෙදර Wi-Fi එකට හොඳට අමාරු password එකක් දාලා තියෙන නිසා 100% safe කියලා හිතනවද.?
එහෙනම් මේ ගැන දැනගෙන ඉන්න එක වටිනවා. 👀
ගොඩක් අය හිතන්නේ Wi-Fi එකක් hack කරන්න නම් hacker කෙනෙක් ගෙදර ළඟට වෙලා, laptop එකෙන් password එකින් password එක try කර කර ඉන්න ඕනේ කියලා.
ඒත් WPA2 Wi-Fi එකක වැඩේ ඊට ටිකක් වෙනස්.
📡 මේ 4-Way Handshake එක මොකක්ද?
ඔයාගේ phone එක Wi-Fi router එකට connect වෙනකොට, phone එකයි router එකයි අතර authentication process එකක් සිද්ධ වෙනවා.
ඔයාගේ Wi-Fi password එක plain text විදිහට air එකේ යන්නේ නෑ. ඒ වෙනුවට cryptographic information පාවිච්චි කරලා phone එකයි router එකයි එකිනෙක verify කරගන්නවා.
මේ exchange එක attacker කෙනෙක් capture කරගත්තොත්, පස්සේ Wi-Fi එක ළඟ ඉන්නෙ නැතුවත් ඒ captured data එක අරගෙන password guesses offline විදිහට test කරන්න පුළුවන්.
😬 ඒක තමයි මෙතන තියෙන ලොකුම අවදානම.
Password එක නමක්, birthday එකක්, phone number එකක්, dictionary word එකක් වගේ ලේසියෙන් guess කරන්න පුළුවන් එකක් නම් තත්වය තවත් අවදානම්.
තව දෙයක් — handshake එක capture කරන්න deauthentication වගේ techniques භාවිතා කරන්න පුළුවන්. හැබැයි හැම වෙලාවෙම deauth attack එකක් කරන්නම ඕනේ නෑ. Client එකක් සාමාන්ය විදිහට reconnect වෙන වෙලාවකත් handshake එක capture වෙන්න පුළුවන්.
🛡️ එහෙනම් Wi-Fi එක ආරක්ෂිත කරගන්නේ කොහොමද?
• Router එක support කරනවා නම් WPA3-Personal භාවිතා කරන්න
• දිග, unique සහ guess කරන්න අමාරු password එකක් දාන්න
• WPS අවශ්ය නැත්නම් disable කරන්න
• Router firmware එක update කරගෙන යන්න
• Router එකේ default admin password එක අනිවාර්යයෙන්ම වෙනස් කරන්න
අන්තිමට එක දෙයක් මතක තියාගන්න. 👇
Strong password එකක් තියෙන එක හොඳ ආරක්ෂාවක්. හැබැයි ඒකෙන් Wi-Fi එක 100% unhackable වෙනවා කියලා අදහස් වෙන්නේ නෑ.
Cybersecurity කියන්නේ එක security setting එකක් ගැන නෙවෙයි.
Layers කිහිපයක් එකට තියෙන එක ගැන. 🔒💻 | 1 |
| 7 | بدون متن... | 136 |
| 8 | 🦾 6 AI Tos Used by H4ckers
🔹Poisongpt
🔹Wormgpt
🔹 Speechif.ai
🔹 Deepl.ai
🔹 Freedom.ai
🔹 Passgan.ai | 207 |
| 9 | بدون متن... | 1 |
| 10 | بدون متن... | 60 |
| 11 | Context එක අනිවාර්යයි.
2️⃣ Command-Line Monitoring
Executable name එක විතරක් log කරන එක ප්රමාණවත් නැහැ.
Security telemetry වලදී:
• Process name
• Parent process
• Command-line arguments
• User account
• Timestamp
• Network destination
• File activity
• Process ancestry
වැනි data useful.
Tool එකට වඩා tool එක භාවිතා කළ ආකාරය වැදගත්.
3️⃣ EDR / Behavioral Detection
Modern EDR solutions සාමාන්යයෙන් single indicator එකකට පමණක් depend නොවී, multiple behavioral signals correlate කිරීමට උත්සාහ කරනවා.
උදාහරණයක්:
Unknown Office document → unusual child process → script interpreter → external connection → suspicious file activity
වගේ chain එකක් තිබුණොත් risk එක වැඩි වෙන්න පුළුවන්.
🔐 DEFENSE SIDE එකෙන් කරන්න පුළුවන් දේවල්
✅ Least Privilege
Users ලාට අවශ්ය තරමට පමණක් permissions දෙන්න.
✅ Application Control
Environment එකට ගැළපෙන application-control policies භාවිතා කරන්න.
Windows environments වල:
AppLocker / WDAC
වැනි technologies consider කළ හැකියි.
✅ PowerShell Logging
විශේෂයෙන් enterprise Windows environments වල appropriate PowerShell logging සහ centralized monitoring වැදගත්.
✅ Centralized Logging
Endpoint logs වෙන වෙනම devices වල තියාගෙන ඉන්නවාට වඩා centralized collection + correlation මගින් suspicious patterns හඳුනාගැනීම පහසු වෙනවා.
✅ Network Monitoring
Process එකක් external destination එකකට සම්බන්ධ වෙන්නේ ඇයි.?
Destination එක trusted ද.?
Connection එක user/device behavior එකට match වෙනවද.?
මේවාත් බලන්න ඕනේ.
✅ User & Process Baselines
“Normal” behavior එක දන්නේ නැත්නම් “abnormal” behavior එක හඳුනාගන්න අමාරුයි.
🧠 අවසාන පාඩම
Cybersecurity වල තියෙන ලොකු misconception එකක් තමයි:
“Antivirus scan එක clean නම් machine එක safe.”
ඒක සම්පූර්ණ සත්යයක් නෙවෙයි.
Modern security එකේ වැදගත් ප්රශ්නය:
❌ “මේ file එක malware ද.?”
විතරක් නෙවෙයි.
ඒ වෙනුවට:
✅ “මේ activity එක සිදුවෙන්නේ ඇයි.?”
✅ “කවුද ඒක execute කළේ.?”
✅ “මොන process එකෙන්ද spawn වුණේ.?”
✅ “මොන arguments ද භාවිතා කළේ.?”
✅ “මොන network destination එකකටද සම්බන්ධ වුණේ.?”
✅ “මේ behavior එක මේ machine එකට normal ද.?”
කියන ප්රශ්නත් අහන්න ඕනේ.
🔥 Living off the Land එකේ භයානකම point එක මෙන්න:
හැම suspicious activity එකක්ම suspicious-looking file එකකින් එන්නේ නැහැ.
සමහර වෙලාවට attacker කෙනෙක්ට අවශ්ය tools දැනටමත් system එක ඇතුළේ තියෙන්න පුළුවන්.
ඒ නිසා modern cybersecurity එකේ:
“What is this file.?”
විතරක් නොව,
“What is this system doing, and why.?”
කියන ප්රශ්නයත් අතිශයින් වැදගත්.
🛡️ Security is not just about detecting malware.
It is about understanding behavior. | 197 |
| 12 | 🛡️ Antivirus එක “No Threats Found” කිව්වම System එක 100% Safe ද.?
නැහැ. ❌
Antivirus scan එකක් clean කියලා පෙන්වීම කියන්නේ system එකේ හඳුනාගත් malicious files නොමැති බවට හොඳ signal එකක්. ඒත් ඒකෙන් “මේ machine එක 100% ආරක්ෂිතයි” කියලා තීරණය කරන්න බැහැ.
ඒකට හේතුවක් තමයි Living off the Land (LotL) කියන attack technique එක.
🔥 LIVING OFF THE LAND (LotL) කියන්නේ මොකක්ද.?
හොරෙක් ගෙදරකට පනින්න තමන්ගේ tools අරගෙන එනවා කියලා හිතන්න.
Security system එකට ඒ අලුත් tools හඳුනාගන්න පුළුවන්.
නමුත් ඔහු ගෙදර ඇතුළට ගිහින් ගෙදරම තිබුණු පිහියක්, පොරවක් හෝ screwdriver එකක් අරගෙන වැඩේ කරනවා නම්.?
හඳුනාගන්න එක වඩාත් අපහසුයි.
Cyber attacks වලදීත් ඒ වගේ දෙයක් සිදුවෙන්න පුළුවන්.
Attacker කෙනෙක් අලුත් malicious executable එකක් drop කරනවා වෙනුවට, target operating system එකේ දැනටමත් තිබෙන legitimate tools තමන්ගේ අරමුණට විරුද්ධව භාවිතා කරයි.
මේ technique එකට කියන්නේ:
👉 Living off the Land (LotL)
🧩 LOLBins කියන්නේ.?
• LOLBins = Living Off the Land Binaries
• Operating system එකේ legitimate ලෙස තිබෙන binaries/tools, attacker කෙනෙක් malicious activity සඳහා abuse කරන අවස්ථා මේ category එකට ඇතුළත් වෙනවා.
• Windows environment එකේ මෙවැනි tools සඳහා LOLBins / LOLBAS වැනි references භාවිතා වෙනවා.
• Linux/Unix systems වලත් built-in utilities abuse කිරීම සිදුවිය හැකියි.
• උදාහරණ ලෙස:
• PowerShell
• Command Prompt
• certutil
• mshta
• curl
• wget
• bash
⚠️ වැදගත්: මේ tools තමන් විසින්ම malware නෙවෙයි.
ඒවා legitimate administrative/development purposes සඳහා නිර්මාණය කරපු tools.
ප්රශ්නය ඇතිවෙන්නේ ඒවා භාවිතා කරන context එක සහ behavior එක වෙනස් වුණාමයි.
🎯 ඇයි LotL Attackers ලාට වැදගත්.?
1️⃣ Antivirus Evasion
Traditional antivirus detection එක බොහෝවිට suspicious files, known malware signatures සහ suspicious patterns හඳුනාගැනීමට භාවිතා කරනවා.
නමුත් attacker කෙනෙක් legitimate system utility එකක් භාවිතා කරනවා නම්:
“Tool එක legitimate” ≠ “Activity එක legitimate”
ඒ නිසා binary එකේ නම විතරක් බලලා threat එකක් තීරණය කරන්න බැහැ.
```
2️⃣ අලුත් Malware File එකක් අවශ්ය නොවිය හැක
Attacker කෙනෙක් තමන්ගේ custom executable එකක් system එකට drop නොකර, තිබෙන utilities භාවිතා කළොත් traditional file scanning වලින් හඳුනාගැනීමට තිබෙන evidence එක අඩු වෙන්න පුළුවන්.
ඒක නිසා:
File-based detection පමණක් ප්රමාණවත් නොවෙන්න පුළුවන්.
3️⃣ Normal Activity එකක් වගේ පෙනෙන්න පුළුවන්
Administrator කෙනෙක් PowerShell භාවිතා කරනවා.
Developer කෙනෙක් curl භාවිතා කරනවා.
System administrator කෙනෙක් command-line utilities භාවිතා කරනවා.
ඒ නිසා:
Tool එක legitimate වීමෙන් activity එක automatically safe වෙන්නේ නැහැ.
Defender කෙනෙක් බලන්න ඕනේ:
"Who + What + How + When + Where + Why"
• කවුද run කළේ.?
• මොන process එකෙන්ද.?
• මොන arguments ද.?
• මොන file/network resource එකකටද සම්බන්ධ වුණේ.?
• එය සිදුවුණේ කවදාද.?
• ඒ user/device එකට එය සාමාන්ය behavior එකක්ද.?
🔬 SAFE LAB CONCEPTS
මෙහිදී වැදගත් distinction එකක් තියෙනවා.
certutil.exe
Windows වල certificate-related operations සඳහා legitimate utility එකක්.
නමුත් security monitoring වලදී defender කෙනෙක් suspicious command-line usage, unusual parent process සහ unexpected network activity වැනි දේවල් ගැන අවධානය යොමු කරනවා.
ඒ නිසා:
certutil.exe detected → Malware
කියන logic එක වැරදියි.
ඒ වෙනුවට:
certutil.exe + unusual arguments + unexpected parent process + suspicious network behavior
වැනි signals එකට evaluate කළ යුතුයි.
🐧 Linux වලත් එයමයි
curl, wget, bash වැනි tools legitimate.
Developer කෙනෙක්ට ඒවා අවශ්ය වෙන්න පුළුවන්.
System administrator කෙනෙක්ටත් ඒවා අවශ්ය වෙන්න පුළුවන්.
ඒ නිසා security analyst කෙනෙක්:
“curl run වුණා”
`
කියන එකෙන් threat එකක් තීරණය කරන්නේ නැහැ.
බලන්නේ process chain, arguments, user context, destination, timing සහ resulting behavior වගේ signals.
🕵️ BLUE TEAM එක LotL Detect කරන්නේ කොහොමද?
1️⃣ Parent → Child Process Analysis
මේක ඉතා වැදගත්.
උදාහරණයක් ලෙස:
Office Application → Script Interpreter → Network Activity
වගේ unusual process chain එකක් ඇතිවුණොත් investigation එකකට signal එකක් වෙන්න පුළුවන්.
හැබැයි:
⚠️ “මේ process එක මේ process එකෙන් spawn වුණා = 100% malware”
කියලා කියන්නත් බැහැ. | 168 |
| 13 | 2️⃣ Command-Line Monitoring
Executable name එක විතරක් log කරන එක ප්රමාණවත් නැහැ. Security telemetry වලදී Process name, Parent process, Command-line arguments, User account, Timestamp, Network destination, File activity, සහ Process ancestry වැනි data useful. Tool එකට වඩා tool එක භාවිතා කළ ආකාරය වැදගත්.
3️⃣ EDR / Behavioral Detection
Modern EDR solutions සාමාන්යයෙන් single indicator එකකට පමණක් depend නොවී, multiple behavioral signals correlate කිරීමට උත්සාහ කරනවා. උදාහරණයක්: Unknown Office document → unusual child process → script interpreter → external connection → suspicious file activity වගේ chain එකක් තිබුණොත් risk එක වැඩි වෙන්න පුළුවන්.
---
🔐 DEFENSE SIDE එකෙන් කරන්න පුළුවන් දේවල්
✅ Least Privilege: Users ලාට අවශ්ය තරමට පමණක් permissions දෙන්න.
✅ Application Control: Environment එකට ගැළපෙන application-control policies භාවිතා කරන්න (Windows environments වල AppLocker / WDAC වැනි technologies).
✅ PowerShell Logging: විශේෂයෙන් enterprise Windows environments වල appropriate PowerShell logging සහ centralized monitoring වැදගත්.
✅ Centralized Logging: Endpoint logs වෙන වෙනම devices වල තියාගෙන ඉන්නවාට වඩා centralized collection + correlation මගින් suspicious patterns හඳුනාගැනීම පහසු වෙනවා.
✅ Network Monitoring: Process එකක් external destination එකකට සම්බන්ධ වෙන්නේ ඇයි? Destination එක trusted ද? Connection එක user/device behavior එකට match වෙනවද?
✅ User & Process Baselines: “Normal” behavior එක දන්නේ නැත්නම් “abnormal” behavior එක හඳුනාගන්න අමාරුයි.
---
🧠 අවසාන පාඩම
Cybersecurity වල තියෙන ලොකු misconception එකක් තමයි:
*“Antivirus scan එක clean නම් machine එක safe.”*
ඒක සම්පූර්ණ සත්යයක් නෙවෙයි.
Modern security එකේ වැදගත් ප්රශ්නය:
❌ “මේ file එක malware ද?” විතරක් නෙවෙයි.
ඒ වෙනුවට අහන්න ඕන ප්රශ්න:
✅ “මේ activity එක සිදුවෙන්නේ ඇයි?”
✅ “කවුද ඒක execute කළේ?”
✅ “මොන process එකෙන්ද spawn වුණේ?”
✅ “මොන arguments ද භාවිතා කළේ?”
✅ “මොන network destination එකකටද සම්බන්ධ වුණේ?”
✅ “මේ behavior එක මේ machine එකට normal ද?”
🔥 Living off the Land එකේ භයානකම point එක මෙන්න:
හැම suspicious activity එකක්ම suspicious-looking file එකකින් එන්නේ නැහැ. සමහර වෙලාවට attacker කෙනෙක්ට අවශ්ය tools දැනටමත් system එක ඇතුළේ තියෙන්න පුළුවන්. ඒ නිසා modern cybersecurity එකේ:
“What is this file?” විතරක් නොව, “What is this system doing, and why?” කියන ප්රශ්නයත් අතිශයින් වැදගත්.
🛡️ *Security is not just about detecting malware. It is about understanding behavior.* | 1 |
| 14 | 🛡️ Antivirus එක “No Threats Found” කිව්වම System එක 100% Safe ද?
නැහැ. ❌
Antivirus scan එකක් clean කියලා පෙන්වීම කියන්නේ system එකේ හඳුනාගත් malicious files නොමැති බවට හොඳ signal එකක්. ඒත් ඒකෙන් “මේ machine එක 100% ආරක්ෂිතයි” කියලා තීරණය කරන්න බැහැ. ඒකට හේතුවක් තමයි Living off the Land (LotL) කියන attack technique එක.
---
🔥 LIVING OFF THE LAND (LotL) කියන්නේ මොකක්ද?
හොරෙක් ගෙදරකට පනින්න තමන්ගේ tools අරගෙන එනවා කියලා හිතන්න. Security system එකට ඒ අලුත් tools හඳුනාගන්න පුළුවන්. නමුත් ඔහු ගෙදර ඇතුළට ගිහින් ගෙදරම තිබුණු පිහියක්, පොරවක් හෝ screwdriver එකක් අරගෙන වැඩේ කරනවා නම්? හඳුනාගන්න එක වඩාත් අපහසුයි.
Cyber attacks වලදීත් ඒ වගේ දෙයක් සිදුවෙන්න පුළුවන්. Attacker කෙනෙක් අලුත් malicious executable එකක් drop කරනවා වෙනුවට, target operating system එකේ දැනටමත් තිබෙන legitimate tools තමන්ගේ අරමුණට විරුද්ධව භාවිතා කරයි. මේ technique එකට කියන්නේ: Living off the Land (LotL).
---
🧩 LOLBins කියන්නේ?
LOLBins = Living Off the Land Binaries
Operating system එකේ legitimate ලෙස තිබෙන binaries/tools, attacker කෙනෙක් malicious activity සඳහා abuse කරන අවස්ථා මේ category එකට ඇතුළත් වෙනවා. Windows environment එකේ මෙවැනි tools සඳහා LOLBins / LOLBAS වැනි references භාවිතා වෙනවා. Linux/Unix systems වලත් built-in utilities abuse කිරීම සිදුවිය හැකියි.
උදාහරණ ලෙස:
* PowerShell
* Command Prompt
* certutil
* mshta
* curl
* wget
* bash
⚠️ වැදගත්: මේ tools තමන් විසින්ම malware නෙවෙයි. ඒවා legitimate administrative/development purposes සඳහා නිර්මාණය කරපු tools. ප්රශ්නය ඇතිවෙන්නේ ඒවා භාවිතා කරන context එක සහ behavior එක වෙනස් වුණාමයි.
---
🎯 ඇයි LotL Attackersලාට වැදගත්?
1️⃣ Antivirus Evasion
Traditional antivirus detection එක බොහෝවිට suspicious files, known malware signatures සහ suspicious patterns හඳුනාගැනීමට භාවිතා කරනවා. නමුත් attacker කෙනෙක් legitimate system utility එකක් භාවිතා කරනවා නම්: “Tool එක legitimate” ≠ “Activity එක legitimate”. ඒ නිසා binary එකේ නම විතරක් බලලා threat එකක් තීරණය කරන්න බැහැ.
2️⃣ අලුත් Malware File එකක් අවශ්ය නොවිය හැක
Attacker කෙනෙක් තමන්ගේ custom executable එකක් system එකට drop නොකර, තිබෙන utilities භාවිතා කළොත් traditional file scanning වලින් හඳුනාගැනීමට තිබෙන evidence එක අඩු වෙන්න පුළුවන්. ඒක නිසා: File-based detection පමණක් ප්රමාණවත් නොවෙන්න පුළුවන්.
3️⃣ Normal Activity එකක් වගේ පෙනෙන්න පුළුවන්
Administrator කෙනෙක් PowerShell භාවිතා කරනවා. Developer කෙනෙක් curl භාවිතා කරනවා. System administrator කෙනෙක් command-line utilities භාවිතා කරනවා. ඒ නිසා: Tool එක legitimate වීමෙන් activity එක automatically safe වෙන්නේ නැහැ.
Defender කෙනෙක් බලන්න ඕනේ:
> Who + What + How + When + Where + Why
කවුද run කළේ? මොන process එකෙන්ද? මොන arguments ද? මොන file/network resource එකකටද සම්බන්ධ වුණේ? එය සිදුවුණේ කවදාද? ඒ user/device එකට එය සාමාන්ය behavior එකක්ද?
---
🔬 SAFE LAB CONCEPTS
මෙහිදී වැදගත් distinction එකක් තියෙනවා.
* certutil.exe: Windows වල certificate-related operations සඳහා legitimate utility එකක්. නමුත් security monitoring වලදී defender කෙනෙක් suspicious command-line usage, unusual parent process සහ unexpected network activity වැනි දේවල් ගැන අවධානය යොමු කරනවා.
* ඒ නිසා: certutil.exe detected → Malware කියන logic එක වැරදියි.
* ඒ වෙනුවට: certutil.exe + unusual arguments + unexpected parent process + suspicious network behavior වැනි signals එකට evaluate කළ යුතුයි.
🐧 Linux වලත් එයමයි:
curl, wget, bash වැනි tools legitimate. Developer කෙනෙක්ට හෝ System administrator කෙනෙක්ට ඒවා අවශ්ය වෙන්න පුළුවන්. ඒ නිසා security analyst කෙනෙක් “curl run වුණා” කියන එකෙන් threat එකක් තීරණය කරන්නේ නැහැ. බලන්නේ process chain, arguments, user context, destination, timing සහ resulting behavior වගේ signals.
---
🕵️ BLUE TEAM එක LotL Detect කරන්නේ කොහොමද?
1️⃣ Parent → Child Process Analysis
මේක ඉතා වැදගත්. උදාහරණයක් ලෙස: Office Application → Script Interpreter → Network Activity වගේ unusual process chain එකක් ඇතිවුණොත් investigation එකකට signal එකක් වෙන්න පුළුවන්. හැබැයි, “මේ process එක මේ process එකෙන් spawn වුණා = 100% malware” කියලා කියන්නත් බැහැ. Context එක අනිවාර්යයි. | 1 |
| 15 | • Command-line arguments
• User account
• Timestamp
• Network destination
• File activity
• Process ancestry
වැනි data useful.
Tool එකට වඩා tool එක භාවිතා කළ ආකාරය වැදගත්.
3️⃣ EDR / Behavioral Detection
Modern EDR solutions සාමාන්යයෙන් single indicator එකකට පමණක් depend නොවී, multiple behavioral signals correlate කිරීමට උත්සාහ කරනවා.
උදාහරණයක්:
Unknown Office document → unusual child process → script interpreter → external connection → suspicious file activity
වගේ chain එකක් තිබුණොත් risk එක වැඩි වෙන්න පුළුවන්.
🔐 DEFENSE SIDE එකෙන් කරන්න පුළුවන් දේවල්
✅ Least Privilege
Users ලාට අවශ්ය තරමට පමණක් permissions දෙන්න.
✅ Application Control
Environment එකට ගැළපෙන application-control policies භාවිතා කරන්න.
Windows environments වල:
AppLocker / WDAC
වැනි technologies consider කළ හැකියි.
✅ PowerShell Logging
විශේෂයෙන් enterprise Windows environments වල appropriate PowerShell logging සහ centralized monitoring වැදගත්.
✅ Centralized Logging
Endpoint logs වෙන වෙනම devices වල තියාගෙන ඉන්නවාට වඩා centralized collection + correlation මගින් suspicious patterns හඳුනාගැනීම පහසු වෙනවා.
✅ Network Monitoring
Process එකක් external destination එකකට සම්බන්ධ වෙන්නේ ඇයි?
Destination එක trusted ද?
Connection එක user/device behavior එකට match වෙනවද?
මේවාත් බලන්න ඕනේ.
✅ User & Process Baselines
“Normal” behavior එක දන්නේ නැත්නම් “abnormal” behavior එක හඳුනාගන්න අමාරුයි.
🧠 අවසාන පාඩම
Cybersecurity වල තියෙන ලොකු misconception එකක් තමයි:
“Antivirus scan එක clean නම් machine එක safe.”
ඒක සම්පූර්ණ සත්යයක් නෙවෙයි.
Modern security එකේ වැදගත් ප්රශ්නය:
❌ “මේ file එක malware ද?”
විතරක් නෙවෙයි.
ඒ වෙනුවට:
✅ “මේ activity එක සිදුවෙන්නේ ඇයි?”
✅ “කවුද ඒක execute කළේ?”
✅ “මොන process එකෙන්ද spawn වුණේ?”
✅ “මොන arguments ද භාවිතා කළේ?”
✅ “මොන network destination එකකටද සම්බන්ධ වුණේ?”
✅ “මේ behavior එක මේ machine එකට normal ද?”
කියන ප්රශ්නත් අහන්න ඕනේ.
🔥 Living off the Land එකේ භයානකම point එක මෙන්න:
හැම suspicious activity එකක්ම suspicious-looking file එකකින් එන්නේ නැහැ.
සමහර වෙලාවට attacker කෙනෙක්ට අවශ්ය tools දැනටමත් system එක ඇතුළේ තියෙන්න පුළුවන්.
ඒ නිසා modern cybersecurity එකේ:
“What is this file?”
විතරක් නොව,
“What is this system doing, and why?”
කියන ප්රශ්නයත් අතිශයින් වැදගත්.
🛡️ Security is not just about detecting malware.
It is about understanding behavior.
#CyberSecurity #LivingOffTheLand #LOLBins #LOLBAS #BlueTeam #SOC #EDR #ThreatDetection #CyberDefense #InfoSec #SecurityAnalyst #WindowsSecurity #LinuxSecurity #MalwareAnalysis #ThreatHunting | 1 |
| 16 | 🛡️ Antivirus එක “No Threats Found” කිව්වම System එක 100% Safe ද?
නැහැ. ❌
Antivirus scan එකක් clean කියලා පෙන්වීම කියන්නේ system එකේ හඳුනාගත් malicious files නොමැති බවට හොඳ signal එකක්. ඒත් ඒකෙන් “මේ machine එක 100% ආරක්ෂිතයි” කියලා තීරණය කරන්න බැහැ.
ඒකට හේතුවක් තමයි Living off the Land (LotL) කියන attack technique එක.
🔥 LIVING OFF THE LAND (LotL) කියන්නේ මොකක්ද?
හොරෙක් ගෙදරකට පනින්න තමන්ගේ tools අරගෙන එනවා කියලා හිතන්න.
Security system එකට ඒ අලුත් tools හඳුනාගන්න පුළුවන්.
නමුත් ඔහු ගෙදර ඇතුළට ගිහින් ගෙදරම තිබුණු පිහියක්, පොරවක් හෝ screwdriver එකක් අරගෙන වැඩේ කරනවා නම්?
හඳුනාගන්න එක වඩාත් අපහසුයි.
Cyber attacks වලදීත් ඒ වගේ දෙයක් සිදුවෙන්න පුළුවන්.
Attacker කෙනෙක් අලුත් malicious executable එකක් drop කරනවා වෙනුවට, target operating system එකේ දැනටමත් තිබෙන legitimate tools තමන්ගේ අරමුණට විරුද්ධව භාවිතා කරයි.
මේ technique එකට කියන්නේ:
👉 Living off the Land (LotL)
🧩 LOLBins කියන්නේ?
LOLBins = Living Off the Land Binaries
Operating system එකේ legitimate ලෙස තිබෙන binaries/tools, attacker කෙනෙක් malicious activity සඳහා abuse කරන අවස්ථා මේ category එකට ඇතුළත් වෙනවා.
Windows environment එකේ මෙවැනි tools සඳහා LOLBins / LOLBAS වැනි references භාවිතා වෙනවා.
Linux/Unix systems වලත් built-in utilities abuse කිරීම සිදුවිය හැකියි.
උදාහරණ ලෙස:
• PowerShell
• Command Prompt
• certutil
• mshta
• curl
• wget
• bash
⚠️ වැදගත්: මේ tools තමන් විසින්ම malware නෙවෙයි.
ඒවා legitimate administrative/development purposes සඳහා නිර්මාණය කරපු tools.
ප්රශ්නය ඇතිවෙන්නේ ඒවා භාවිතා කරන context එක සහ behavior එක වෙනස් වුණාමයි.
🎯 ඇයි LotL Attackersලාට වැදගත්?
1️⃣ Antivirus Evasion
Traditional antivirus detection එක බොහෝවිට suspicious files, known malware signatures සහ suspicious patterns හඳුනාගැනීමට භාවිතා කරනවා.
නමුත් attacker කෙනෙක් legitimate system utility එකක් භාවිතා කරනවා නම්:
“Tool එක legitimate” ≠ “Activity එක legitimate”
ඒ නිසා binary එකේ නම විතරක් බලලා threat එකක් තීරණය කරන්න බැහැ.
2️⃣ අලුත් Malware File එකක් අවශ්ය නොවිය හැක
Attacker කෙනෙක් තමන්ගේ custom executable එකක් system එකට drop නොකර, තිබෙන utilities භාවිතා කළොත් traditional file scanning වලින් හඳුනාගැනීමට තිබෙන evidence එක අඩු වෙන්න පුළුවන්.
ඒක නිසා:
File-based detection පමණක් ප්රමාණවත් නොවෙන්න පුළුවන්.
3️⃣ Normal Activity එකක් වගේ පෙනෙන්න පුළුවන්
Administrator කෙනෙක් PowerShell භාවිතා කරනවා.
Developer කෙනෙක් curl භාවිතා කරනවා.
System administrator කෙනෙක් command-line utilities භාවිතා කරනවා.
ඒ නිසා:
Tool එක legitimate වීමෙන් activity එක automatically safe වෙන්නේ නැහැ.
Defender කෙනෙක් බලන්න ඕනේ:
Who + What + How + When + Where + Why
කවුද run කළේ?
මොන process එකෙන්ද?
මොන arguments ද?
මොන file/network resource එකකටද සම්බන්ධ වුණේ?
එය සිදුවුණේ කවදාද?
ඒ user/device එකට එය සාමාන්ය behavior එකක්ද?
🔬 SAFE LAB CONCEPTS
මෙහිදී වැදගත් distinction එකක් තියෙනවා.
certutil.exe
Windows වල certificate-related operations සඳහා legitimate utility එකක්.
නමුත් security monitoring වලදී defender කෙනෙක් suspicious command-line usage, unusual parent process සහ unexpected network activity වැනි දේවල් ගැන අවධානය යොමු කරනවා.
ඒ නිසා:
certutil.exe detected → Malware
කියන logic එක වැරදියි.
ඒ වෙනුවට:
certutil.exe + unusual arguments + unexpected parent process + suspicious network behavior
වැනි signals එකට evaluate කළ යුතුයි.
🐧 Linux වලත් එයමයි
curl, wget, bash වැනි tools legitimate.
Developer කෙනෙක්ට ඒවා අවශ්ය වෙන්න පුළුවන්.
System administrator කෙනෙක්ටත් ඒවා අවශ්ය වෙන්න පුළුවන්.
ඒ නිසා security analyst කෙනෙක්:
“curl run වුණා”
කියන එකෙන් threat එකක් තීරණය කරන්නේ නැහැ.
බලන්නේ process chain, arguments, user context, destination, timing සහ resulting behavior වගේ signals.
🕵️ BLUE TEAM එක LotL Detect කරන්නේ කොහොමද?
1️⃣ Parent → Child Process Analysis
මේක ඉතා වැදගත්.
උදාහරණයක් ලෙස:
Office Application → Script Interpreter → Network Activity
වගේ unusual process chain එකක් ඇතිවුණොත් investigation එකකට signal එකක් වෙන්න පුළුවන්.
හැබැයි:
⚠️ “මේ process එක මේ process එකෙන් spawn වුණා = 100% malware”
කියලා කියන්නත් බැහැ.
Context එක අනිවාර්යයි.
2️⃣ Command-Line Monitoring
Executable name එක විතරක් log කරන එක ප්රමාණවත් නැහැ.
Security telemetry වලදී:
• Process name
• Parent process | 1 |
| 17 | Executable name එක විතරක් log කරන එක ප්රමාණවත් නැහැ.
Security telemetry වලදී:
• Process name
• Parent process
• Command-line arguments
• User account
• Timestamp
• Network destination
• File activity
• Process ancestry
වැනි data useful.
Tool එකට වඩා tool එක භාවිතා කළ ආකාරය වැදගත්.
---
3️⃣ EDR / Behavioral Detection
Modern EDR solutions සාමාන්යයෙන් single indicator එකකට පමණක් depend නොවී, multiple behavioral signals correlate කිරීමට උත්සාහ කරනවා.
උදාහරණයක්:
Unknown Office document → unusual child process → script interpreter → external connection → suspicious file activity
වගේ chain එකක් තිබුණොත් risk එක වැඩි වෙන්න පුළුවන්.
---
🔐 DEFENSE SIDE එකෙන් කරන්න පුළුවන් දේවල්
✅ Least Privilege
Users ලාට අවශ්ය තරමට පමණක් permissions දෙන්න.
✅ Application Control
Environment එකට ගැළපෙන application-control policies භාවිතා කරන්න.
Windows environments වල:
AppLocker / WDAC
වැනි technologies consider කළ හැකියි.
✅ PowerShell Logging
විශේෂයෙන් enterprise Windows environments වල appropriate PowerShell logging සහ centralized monitoring වැදගත්.
✅ Centralized Logging
Endpoint logs වෙන වෙනම devices වල තියාගෙන ඉන්නවාට වඩා centralized collection + correlation මගින් suspicious patterns හඳුනාගැනීම පහසු වෙනවා.
✅ Network Monitoring
Process එකක් external destination එකකට සම්බන්ධ වෙන්නේ ඇයි?
Destination එක trusted ද?
Connection එක user/device behavior එකට match වෙනවද?
මේවාත් බලන්න ඕනේ.
✅ User & Process Baselines
“Normal” behavior එක දන්නේ නැත්නම් “abnormal” behavior එක හඳුනාගන්න අමාරුයි.
---
🧠 අවසාන පාඩම
Cybersecurity වල තියෙන ලොකු misconception එකක් තමයි:
«“Antivirus scan එක clean නම් machine එක safe.”»
ඒක සම්පූර්ණ සත්යයක් නෙවෙයි.
Modern security එකේ වැදගත් ප්රශ්නය:
❌ “මේ file එක malware ද?”
විතරක් නෙවෙයි.
ඒ වෙනුවට:
✅ “මේ activity එක සිදුවෙන්නේ ඇයි?”
✅ “කවුද ඒක execute කළේ?”
✅ “මොන process එකෙන්ද spawn වුණේ?”
✅ “මොන arguments ද භාවිතා කළේ?”
✅ “මොන network destination එකකටද සම්බන්ධ වුණේ?”
✅ “මේ behavior එක මේ machine එකට normal ද?”
කියන ප්රශ්නත් අහන්න ඕනේ.
---
🔥 Living off the Land එකේ භයානකම point එක මෙන්න:
හැම suspicious activity එකක්ම suspicious-looking file එකකින් එන්නේ නැහැ.
සමහර වෙලාවට attacker කෙනෙක්ට අවශ්ය tools දැනටමත් system එක ඇතුළේ තියෙන්න පුළුවන්.
ඒ නිසා modern cybersecurity එකේ:
“What is this file?”
විතරක් නොව,
“What is this system doing, and why?”
කියන ප්රශ්නයත් අතිශයින් වැදගත්.
🛡️ Security is not just about detecting malware.
It is about understanding behavior. | 1 |
| 18 | 🛡️ Antivirus එක “No Threats Found” කිව්වම System එක 100% Safe ද?
නැහැ. ❌
Antivirus scan එකක් clean කියලා පෙන්වීම කියන්නේ system එකේ හඳුනාගත් malicious files නොමැති බවට හොඳ signal එකක්. ඒත් ඒකෙන් “මේ machine එක 100% ආරක්ෂිතයි” කියලා තීරණය කරන්න බැහැ.
ඒකට හේතුවක් තමයි Living off the Land (LotL) කියන attack technique එක.
---
🔥 LIVING OFF THE LAND (LotL) කියන්නේ මොකක්ද?
හොරෙක් ගෙදරකට පනින්න තමන්ගේ tools අරගෙන එනවා කියලා හිතන්න.
Security system එකට ඒ අලුත් tools හඳුනාගන්න පුළුවන්.
නමුත් ඔහු ගෙදර ඇතුළට ගිහින් ගෙදරම තිබුණු පිහියක්, පොරවක් හෝ screwdriver එකක් අරගෙන වැඩේ කරනවා නම්?
හඳුනාගන්න එක වඩාත් අපහසුයි.
Cyber attacks වලදීත් ඒ වගේ දෙයක් සිදුවෙන්න පුළුවන්.
Attacker කෙනෙක් අලුත් malicious executable එකක් drop කරනවා වෙනුවට, target operating system එකේ දැනටමත් තිබෙන legitimate tools තමන්ගේ අරමුණට විරුද්ධව භාවිතා කරයි.
මේ technique එකට කියන්නේ:
👉 Living off the Land (LotL)
---
🧩 LOLBins කියන්නේ?
LOLBins = Living Off the Land Binaries
Operating system එකේ legitimate ලෙස තිබෙන binaries/tools, attacker කෙනෙක් malicious activity සඳහා abuse කරන අවස්ථා මේ category එකට ඇතුළත් වෙනවා.
Windows environment එකේ මෙවැනි tools සඳහා LOLBins / LOLBAS වැනි references භාවිතා වෙනවා.
Linux/Unix systems වලත් built-in utilities abuse කිරීම සිදුවිය හැකියි.
උදාහරණ ලෙස:
• PowerShell
• Command Prompt
• certutil
• mshta
• curl
• wget
• bash
⚠️ වැදගත්: මේ tools තමන් විසින්ම malware නෙවෙයි.
ඒවා legitimate administrative/development purposes සඳහා නිර්මාණය කරපු tools.
ප්රශ්නය ඇතිවෙන්නේ ඒවා භාවිතා කරන context එක සහ behavior එක වෙනස් වුණාමයි.
---
🎯 ඇයි LotL Attackersලාට වැදගත්?
1️⃣ Antivirus Evasion
Traditional antivirus detection එක බොහෝවිට suspicious files, known malware signatures සහ suspicious patterns හඳුනාගැනීමට භාවිතා කරනවා.
නමුත් attacker කෙනෙක් legitimate system utility එකක් භාවිතා කරනවා නම්:
“Tool එක legitimate” ≠ “Activity එක legitimate”
ඒ නිසා binary එකේ නම විතරක් බලලා threat එකක් තීරණය කරන්න බැහැ.
---
2️⃣ අලුත් Malware File එකක් අවශ්ය නොවිය හැක
Attacker කෙනෙක් තමන්ගේ custom executable එකක් system එකට drop නොකර, තිබෙන utilities භාවිතා කළොත් traditional file scanning වලින් හඳුනාගැනීමට තිබෙන evidence එක අඩු වෙන්න පුළුවන්.
ඒක නිසා:
File-based detection පමණක් ප්රමාණවත් නොවෙන්න පුළුවන්.
---
3️⃣ Normal Activity එකක් වගේ පෙනෙන්න පුළුවන්
Administrator කෙනෙක් PowerShell භාවිතා කරනවා.
Developer කෙනෙක් curl භාවිතා කරනවා.
System administrator කෙනෙක් command-line utilities භාවිතා කරනවා.
ඒ නිසා:
Tool එක legitimate වීමෙන් activity එක automatically safe වෙන්නේ නැහැ.
Defender කෙනෙක් බලන්න ඕනේ:
«Who + What + How + When + Where + Why»
කවුද run කළේ?
මොන process එකෙන්ද?
මොන arguments ද?
මොන file/network resource එකකටද සම්බන්ධ වුණේ?
එය සිදුවුණේ කවදාද?
ඒ user/device එකට එය සාමාන්ය behavior එකක්ද?
---
🔬 SAFE LAB CONCEPTS
මෙහිදී වැදගත් distinction එකක් තියෙනවා.
"certutil.exe"
Windows වල certificate-related operations සඳහා legitimate utility එකක්.
නමුත් security monitoring වලදී defender කෙනෙක් suspicious command-line usage, unusual parent process සහ unexpected network activity වැනි දේවල් ගැන අවධානය යොමු කරනවා.
ඒ නිසා:
certutil.exe detected → Malware
කියන logic එක වැරදියි.
ඒ වෙනුවට:
certutil.exe + unusual arguments + unexpected parent process + suspicious network behavior
වැනි signals එකට evaluate කළ යුතුයි.
---
🐧 Linux වලත් එයමයි
"curl", "wget", "bash" වැනි tools legitimate.
Developer කෙනෙක්ට ඒවා අවශ්ය වෙන්න පුළුවන්.
System administrator කෙනෙක්ටත් ඒවා අවශ්ය වෙන්න පුළුවන්.
ඒ නිසා security analyst කෙනෙක්:
«“curl run වුණා”»
කියන එකෙන් threat එකක් තීරණය කරන්නේ නැහැ.
බලන්නේ process chain, arguments, user context, destination, timing සහ resulting behavior වගේ signals.
---
🕵️ BLUE TEAM එක LotL Detect කරන්නේ කොහොමද?
1️⃣ Parent → Child Process Analysis
මේක ඉතා වැදගත්.
උදාහරණයක් ලෙස:
Office Application → Script Interpreter → Network Activity
වගේ unusual process chain එකක් ඇතිවුණොත් investigation එකකට signal එකක් වෙන්න පුළුවන්.
හැබැයි:
⚠️ “මේ process එක මේ process එකෙන් spawn වුණා = 100% malware”
කියලා කියන්නත් බැහැ.
Context එක අනිවාර්යයි.
---
2️⃣ Command-Line Monitoring | 1 |
| 19 | بدون متن... | 1 |
| 20 | • Command-line arguments
• User account
• Timestamp
• Network destination
• File activity
• Process ancestry
වැනි data useful.
Tool එකට වඩා tool එක භාවිතා කළ ආකාරය වැදගත්.
3️⃣ EDR / Behavioral Detection
Modern EDR solutions සාමාන්යයෙන් single indicator එකකට පමණක් depend නොවී, multiple behavioral signals correlate කිරීමට උත්සාහ කරනවා.
උදාහරණයක්:
Unknown Office document → unusual child process → script interpreter → external connection → suspicious file activity
වගේ chain එකක් තිබුණොත් risk එක වැඩි වෙන්න පුළුවන්.
🔐 DEFENSE SIDE එකෙන් කරන්න පුළුවන් දේවල්
✅ Least Privilege
Users ලාට අවශ්ය තරමට පමණක් permissions දෙන්න.
✅ Application Control
Environment එකට ගැළපෙන application-control policies භාවිතා කරන්න.
Windows environments වල:
AppLocker / WDAC
වැනි technologies consider කළ හැකියි.
✅ PowerShell Logging
විශේෂයෙන් enterprise Windows environments වල appropriate PowerShell logging සහ centralized monitoring වැදගත්.
✅ Centralized Logging
Endpoint logs වෙන වෙනම devices වල තියාගෙන ඉන්නවාට වඩා centralized collection + correlation මගින් suspicious patterns හඳුනාගැනීම පහසු වෙනවා.
✅ Network Monitoring
Process එකක් external destination එකකට සම්බන්ධ වෙන්නේ ඇයි.?
Destination එක trusted ද.?
Connection එක user/device behavior එකට match වෙනවද.?
මේවාත් බලන්න ඕනේ.
✅ User & Process Baselines
“Normal” behavior එක දන්නේ නැත්නම් “abnormal” behavior එක හඳුනාගන්න අමාරුයි.
🧠 අවසාන පාඩම
Cybersecurity වල තියෙන ලොකු misconception එකක් තමයි:
“Antivirus scan එක clean නම් machine එක safe.”
ඒක සම්පූර්ණ සත්යයක් නෙවෙයි.
Modern security එකේ වැදගත් ප්රශ්නය:
❌ “මේ file එක malware ද.?”
විතරක් නෙවෙයි.
ඒ වෙනුවට:
✅ “මේ activity එක සිදුවෙන්නේ ඇයි.?”
✅ “කවුද ඒක execute කළේ.?”
✅ “මොන process එකෙන්ද spawn වුණේ.?”
✅ “මොන arguments ද භාවිතා කළේ.?”
✅ “මොන network destination එකකටද සම්බන්ධ වුණේ.?”
✅ “මේ behavior එක මේ machine එකට normal ද.?”
කියන ප්රශ්නත් අහන්න ඕනේ.
🔥 Living off the Land එකේ භයානකම point එක මෙන්න:
හැම suspicious activity එකක්ම suspicious-looking file එකකින් එන්නේ නැහැ.
සමහර වෙලාවට attacker කෙනෙක්ට අවශ්ය tools දැනටමත් system එක ඇතුළේ තියෙන්න පුළුවන්.
ඒ නිසා modern cybersecurity එකේ:
“What is this file.?”
විතරක් නොව,
“What is this system doing, and why.?”
කියන ප්රශ්නයත් අතිශයින් වැදගත්.
🛡️ Security is not just about detecting malware.
It is about understanding behavior. | 1 |
