[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.jp/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/ja/)  
Menu

* [セキュリティ コンサルティング](https://www.paloaltonetworks.com/unit42)
* [**現在、攻撃を受けていますか?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  Japanese
* [English](https://unit42.paloaltonetworks.com/vice-society-ransomware-powershell/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/vice-society-ransomware-powershell/)
* [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research")
* [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/ "脅威リサーチ")
* [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/ "マルウェア")  
  [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)

# Vice Societyによる現地調達型攻撃: PowerShellを使った被害者データの漏出手法

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 7 分で読めます  
Related Products  
[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/ja/product-category/cortex-xdr-ja/ "Cortex XDR")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/ja/product-category/unit-42-incident-response-ja/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  著者:
  
  * [Ryan Chapman](https://unit42.paloaltonetworks.com/ja/author/ryan-chapman/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  公開日:2023年4月13日

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  カテゴリー
  
  * [マルウェア](https://unit42.paloaltonetworks.com/ja/category/malware-ja/)
  * [脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  タグ:
  
  * [PowerShell Scripts](https://unit42.paloaltonetworks.com/ja/tag/powershell-scripts-ja/)
  * [Vice Society](https://unit42.paloaltonetworks.com/ja/tag/vice-society-ja/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/ja/vice-society-ransomware-powershell/?pdf=download&lg=ja&_wpnonce=48697d1bdd "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/ja/vice-society-ransomware-powershell/?pdf=print&lg=ja&_wpnonce=48697d1bdd "Click here to print")

共有![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Vice%20Societyによる現地調達型攻撃:%20PowerShellを使った被害者データの漏出手法&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fvice-society-ransomware-powershell%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fvice-society-ransomware-powershell%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fvice-society-ransomware-powershell%2F&title=Vice%20Societyによる現地調達型攻撃:%20PowerShellを使った被害者データの漏出手法 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fvice-society-ransomware-powershell%2F&text=Vice%20Societyによる現地調達型攻撃:%20PowerShellを使った被害者データの漏出手法 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fvice-society-ransomware-powershell%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Vice%20Societyによる現地調達型攻撃:%20PowerShellを使った被害者データの漏出手法%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fja%2Fvice-society-ransomware-powershell%2F "Share in Mastodon")

## 概要

Unit 42チームは、最近行ったインシデント対応のなかで、[Vice Societyランサムウェア攻撃グループ](https://unit42.paloaltonetworks.jp/vice-society-targets-education-sector/)による被害者ネットワークからのデータ漏出を特定しました。このさい同グループは、カスタム作成した[Microsoft PowerShell](https://learn.microsoft.com/ja-jp/powershell/) (PS)スクリプトを使っていました。本稿はこのカスタム スクリプトを分解して各関数の機能を解説し、データ漏出手法を明らかにします。

ランサムウェア攻撃グループはさまざまな手口で被害者のネットワークからデータを窃取します。外部からFileZilla、WinSCP、rcloneなどのツールを持ち込むグループもあれば、いわゆる「[LOLBAS方式(living off the land binaries and scripts: 被害環境に元からあるバイナリーやスクリプトを使う現地調達型の攻撃手法)](https://lolbas-project.github.io/)」を使うグループもあります。たとえばPowerShell (PS)スクリプトやリモート デスクトップ プロトコル(RDP)経由のコピー/ペースト、Microsoft Win32 API (例: Wininet.dllの呼び出し)などがLOLBAS方式の例です。ここでは、PowerShellスクリプトでランサムウェア攻撃のデータ漏出ステージを自動化した場合どのようなものになるかを検証していきます。

パロアルトネットワークスのお客様は、次の方法で、これ以下で説明するスクリプトに対する保護と緩和を受けています。

* 本稿末に記載したXQLクエリーはCortex XDRによる同スクリプトの追跡に役立ちます。
* Unit 42のインシデント レスポンス チームによる個別対応もご提供しています。

さらに、本稿の末尾に記載した[YARAルール](#post-127684-_4d01s3mpq9v1)でこのスクリプトを検出できます。

| **関連するUnit 42のトピック** | [**Vice Society**](https://unit42.paloaltonetworks.jp/tag/vice-society-ja/), **[Ransomware](https://unit42.paloaltonetworks.jp/category/ransomware-ja/)** |
|----------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------|

## 概要

LOLBASのような現地調達型のデータ漏出手法を使うと外部からツールを持ち込む必要がなくなます。したがって、これらのツールがセキュリティ ソフトウェアやアナリストなどに検出フラグを立てられることも避けられますし、通常のオペレーションに紛れ込んでシステムを侵害できます。

たとえば一般的なWindows環境ではPowerShellスクリプトがよく使われていますので脅威アクターが目立たずに行動したいときにはこれが頼れる味方になります。

2023年の初め、Unit 42のインシデント レスポンス チームは、被害者ネットワークからのデータ漏出にw1.ps1というスクリプトを使うVice Societyランサムウェア攻撃グループを発見しました。この事例で私たちはWindowsイベント ログ(WEL)からスクリプトを復元しました。具体的には、Microsoft-Windows-PowerShell/Operationalというログ内の[Event ID 4104: Script Block Logging](https://learn.microsoft.com/ja-jp/powershell/module/microsoft.powershell.core/about/about_logging_windows)というイベントからスクリプトを復元しました。

すべてのスクリプト ブロックを記録するにはWindowsで[スクリプト ブロック ログの有効化](https://learn.microsoft.com/ja-jp/powershell/module/microsoft.powershell.core/about/about_logging_windows?view=powershell-7.3#enabling-script-block-logging)をしておく必要があります。ただし、Microsoftは「悪意がある」と判断されるイベントについては、文書化されていないバックエンド側のしくみを使って、デフォルトでログを記録しています。このため、スクリプト ブロック ログが完全に有効化されていない環境でも、イベントID 4104のイベントが分析に役立つことがあります。

Unit 42のリサーチャーは、以下のスクリプトがpowershellコマンドを使って実行されていたことを確認しました。

powershell.exe -ExecutionPolicy Bypass -file \\\\\[redacted\_ip\]\\s$\\w1.ps1

|---|------------------------------------------------------------------------------|
| 1 | powershell.exe -ExecutionPolicy Bypass -file \\\\\[redacted\_ip\]\\s$\\w1.ps1 |

このスクリプトの呼び出しでは、URNパス(上記で\[redacted\_ip\]で示した部分)内のローカル ドメイン コントローラー(DC)のIPアドレスが使われ、DC上のs$という管理共有が指定されています。なお、このスクリプトは被害者環境のDCの1つを介して展開されるので、標的のコンピューターに対して脅威アクターがこの時点では直接的なアクセスを確保していない可能性がある点に留意してください。つまり被害者ネットワーク内のエンドポイントはすべて、同スクリプトの標的となる可能性があります。powershellの実行ファイルには、[実行ポリシーの制限](https://learn.microsoft.com/ja-jp/powershell/module/microsoft.powershell.security/set-executionpolicy)を回避するため、-ExecutionPolicyパラメーターとポリシー値「Bypass」が付与されます。

このスクリプトは引数を必要としません。*どのファイルをネットワークからコピーするかはスクリプト自身に任されています* 。興味深いことに、このスクリプトはどのデータを漏出させるかを自動的に*選択*できるようになっています。

## スクリプトの分析

このスクリプトは最初に定数的に利用される2つの変数、$idと$tokenを定義します。これらは被害者の識別に使われます。今回確認したスクリプトでは、これらの値はそれぞれ「TEST」と「TEST\_1」という値にハードコードされていました。

\[string\]$id = "TEST"; \[string\]$token = "TEST\_1"

|-----|-----------------------------------------------------|
| 1 2 | \[string\]$id = "TEST"; \[string\]$token = "TEST\_1" |

論理上、これらの変数にもっと具体的な値を設定すれば、実際の被害者の特定に使えるはずなので、これが本当にテスト段階だったのか、うっかりテスト状態のままになっているのかはわかっていません。

このスクリプトは次に、コード ベース内で実務を担う関数を複数定義します。表1にこのスクリプトの関数の概要を示します。ここでは関数の定義の順ではなく呼び出し順で記載しています。

|-----------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **関数**                      | **説明**                                                                                                                                                                                                                                                                                                                              |
| Work( $disk )               | マウントされたボリュームごとに呼び出される。ハードコードされたディレクトリー名リストにもとづいて特定のディレクトリーを除外し、漏出候補のディレクトリーを絞り込む。  Show()関数を呼び出し、除外リストに一致しなかったディレクトリーのディレクトリー名をすべて渡す。                                                                                                                                                                                         |
| Show( $name )               | Work()関数からディレクトリー名を受け取る。5つのディレクトリーを1単位としてグループに分割し、このディレクトリー グループをCreateJobLocal()関数に渡し、さらに処理をすすめる。                                                                                                                                                                                                                                  |
| CreateJobLocal( $folders )  | ディレクトリー グループ(5つのディレクトリーを1単位とするグループに分かれていることが多い)を受け取り、PowerShellのスクリプト ブロックを作成し、作成したスクリプト ブロックを[Start-Jobコマンドレット](https://learn.microsoft.com/ja-jp/powershell/module/microsoft.powershell.core/start-job)経由でジョブとして実行する。  提供されたディレクトリー名に対し、キーワードを使って、処理対象に含めるかそれとも除外するかという選択処理を行う。これによりfill()という外部への漏出を行う関数にどのディレクトリーを渡すかを決める。 |
| fill( \[string\]$filename ) | CreateJobLocal()関数によって呼び出される。この関数は、脅威アクターのWebサーバーに対するHTTP POSTリクエストを経由して実際にデータを漏出させる。                                                                                                                                                                                                                                               |

*表1. スクリプトの関数の概要*

図1は関数間の処理フローの概要で、スクリプトがどのように動作するのかを理解しやすくするものです。
[![画像1はw1.ps1スクリプトの処理フロー図です。フローはスクリプト ファイルから始まって、HTTP POSTイベントによる脅威アクターへのファイルのアップロードで終わります。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-1-ja-2.png)](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-1-ja-2.png) 図1. w1.ps1スクリプトの処理フロー

### 開始部

このスクリプトはまず、[Windows Management Instrumentation(WMI)](https://learn.microsoft.com/ja-jp/windows/win32/wmisdk/wmi-start-page)経由でシステム上にマウントされているドライブを特定します。次に、定義された関数を呼び出します。簡単なフィルタリングを指定して[get-wmiobject win32\_volume](<https://learn.microsoft.com/en-us/previous-versions/windows/desktop/legacy/aa394515(v=vs.85)>)を呼び出し、$drivesという名前の配列を作成します。この配列には、コンピューターにマウントされているドライブのリストが格納されます。この後、見つかった各ドライブのパスを個別にWork()関数に渡します。図2に関連するコード スニペットを示します。
![画像2はスクリプトのスクリーンショットです。1で示しているのはForEach-Objectの行、2で示しているのがWork()関数の始まる行です。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-2.png) 図2. スクリプト開始部のコード。マウントされている各ボリュームを特定して処理する

この開始部のコードは以下を行っています。

1. $drivesという名前の配列を作成し、コンピューター上にマウントされているボリュームのリストをこの配列に格納する。
   1. win32\_volumeのDriveTypeのenumは「  
      Local Disk (ローカル ディスク)」を意味する。詳しくは[MicrosoftのWin32\_Volume Classのドキュメント](<https://learn.microsoft.com/en-us/previous-versions/windows/desktop/legacy/aa394515(v=vs.85)>)を参照のこと。
2. コンピューター上で特定されたドライブ($drive)を繰り返し処理し、特定された各ドライブ パスをWork()関数に渡す。

図3は1台のドライブしかマウントされていない平均的なWindowsホストでこのコードがどのように動くかを示した例です。
![画像3はコードのスクリーンショットです。変数$driveと配列$drivesを赤枠で強調しています。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-3.png) 図3. ドライブが1台マウントされているコンピューターの$drives配列と$drive変数の値の例

特定された各ドライブ名に対し、この開始部はWork()関数を呼び出してドライブ上のディレクトリーを処理します。

### Work()関数

Work()関数は呼び出しのつどディレクトリーの検索と処理に使うドライブ パスを ($diskとして) 受け取ります。図4はWork()関数の開始部分です。
![画像4はWork()関数の開始部分を表示した何行ものコードのスクリーンショットです。ここでは配列$folders、変数$store、Show()関数の3行がそれぞれ1、2、3の番号つきで強調されています。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-4.png) 図4. Work()関数の開始部分

上のコードは以下を行っています。

1. $foldersという配列と$jobsという配列を作成する。
2. $storeというTupleを作成し、さきほど作成した2つの配列を格納する。
3. Show()関数を定義する。

図5はShow()関数のすぐ下にあるWork()関数のコードの残りの部分です。
![画像5はWork()関数の終了部分を示す何行ものコードのスクリーンショットです。ハイライトは3つあります。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-5.png) 図5. Work()関数の残りの部分

上のコードは以下を行っています。

4. Get-ChildItemコマンドレットに処理中のボリューム文字列を渡す。システム関連ファイルやアプリケーション関連ファイルの処理を避けるため、対象外にする31個のディレクトリー パスをフィルタリングする。その後それぞれのルートのディレクトリー名をShow()関数に渡して処理を継続する。
   * 除外するルート ディレクトリーの一覧は「[付録](#post-127684-_46pitawsbgtt)」の「[包含・除外リスト](#post-127684-_46pitawsbgtt)」セクションを参照のこと。
5. Show()関数にルート ディレクトリーのディレクトリーを渡してから、Work()関数はルート ディレクトリー内のサブディレクトリーを再帰的に検索する。先のフィルタリング同様、除外リストに一致しないサブディレクトリーがShow()関数に送られて処理される。
   * 除外するサブディレクトリーの一覧は「[付録](#post-127684-_46pitawsbgtt)」の「[包含・除外リスト](#post-127684-_46pitawsbgtt)」セクションを参照のこと。
6. Show()関数は[PowerShellジョブ](https://learn.microsoft.com/ja-jp/powershell/module/microsoft.powershell.core/about/about_jobs)を作成してデータを漏出できるようにする。この関数はディレクトリーを5つ含むグループを1単位として処理を行う。このコード部分はグループ化されたフォルダーのあまりを確実に処理するためのフェイル セーフとして機能する。
   * たとえば合計212個のディレクトリーが特定された場合はこのコードの部分であまりの2つのディレクトリー処理を保証する。

### Show()関数

Show()関数はディレクトリー名を受け取って処理します。図6はShow()関数の概要を示したものです。
![画像6は、Show()関数の概要を示す何行ものコードのスクリーンショットです。ifで始まる行とwhileで始まる行の2箇所が強調されています。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-6.png) 図6. Show()関数の概要

上のコードは以下を行っています。

1. 提供されたディレクトリー名を集めてディレクトリー名が5つ含まれるグループを作る。ディレクトリー名が5つ集まったらそれをCreateJobLocal()関数に渡してPowerShellジョブを作成させ、そのディレクトリー グループからデータの漏出を行う。
2. このスクリプトは、1回の処理では5つのディレクトリーを含むグループを最大10ジョブまでしか処理しないというレート制限を設けている。10個以上のジョブが実行されている場合このスクリプトは5秒間スリープして実行中のジョブ数を再確認する。
   * \*\*注:\*\*全体的なスクリプト設計ではプロレベルのコーディングが行われていることがわかる。このスクリプトはコンピューター リソースに影響しないような工夫がしてある。正確な理由は作者にしかわからないが、この手法は一般的なコーディングのベストプラクティスにそったもの。

### CreateJobLocal()関数

CreateJobLocal()関数は、データ漏出用のマルチプロセッシング キューを設定します。図7はCreateJobLocal()関数の開始部分です。
![画像7はCreateJobLocal()関数の概要を示す何行ものコードのスクリーンショットです。ifで始まる行とwhileで始まる行の2箇所が強調されています。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-7.png) 図7 CreateJobLocal()関数の概要

上のコードは以下を行っています。

1. 作成するジョブの名前を擬似乱数を使って生成する。ジョブ名はアルファベット5文字(小文字、大文字を含む)で構成される。
   * たとえば、あるデバッグ セッション中、このスクリプトはiZUIb、dlHxF、VCHYu、FyrCb、GVILAという5つのジョブ名を生成した。
2. PowerShellジョブを1つセットアップする。スクリプトのこの時点で作成されるこのジョブは、のちにスクリプト ブロックとなるコード構造を持つ。

CreateJobLocal()内のこの時点でfill()関数が定義されます(後述)が、ここでは先にCreateJobLocal()関数の残りを続けて説明します。図8はコードの続きの部分です。
![画像8は、CreateJobLocal()関数の残りを示す何行ものコードのスクリーンショットです。foreach、$include/$excludes、ifの部分を3、4、5で強調しています。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-8.png) 図8. CreateJobLocal()関数の残りのコード

以下は、上のCreateJobLocal()のコードベースについての説明です。

3. 漏出対象ファイルのための$fileListという配列を作成する。次に、現在のグループ内のディレクトリーをループ処理する。前述のとおり、通常はディレクトリーを5つ含むグループ単位でディレクトリーを処理する。
4. 包含用に$include、除外用に$excludesという名前の配列をセットアップする。
   * これらの配列の値一覧は「[付録](#post-127684-_46pitawsbgtt)」の「[包含・除外リスト](#post-127684-_46pitawsbgtt)」セクションを参照のこと。
5. 与えられたディレクトリー グループ内のディレクトリーをループし、$include配列にハードコードされた値にもとづいて、正規表現を使い、漏出対象に含めるフォルダーを絞り込む。

この関数はさらにここで$excludesを使って漏出対象から除外するファイルを絞り込みます。
![画像9は、CreateJobLocal()関数の残りを示す、何行ものコードのスクリーンショットです。if節内の$filesの処理と、else節内の$filesの処理、そしてforeachのセクションが6、7、8で強調されています。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-9.png) 図9. CreateJobLocal()関数の残りの部分

以下はCreateJobLocal()のコードベースの残りの部分の説明です。

6. **あるディレクトリーが$lincludeの包含リストと一致した場合、そのディレクトリー内にあり、$excludesの除外リストに記載された拡張子を持たず、10KBより大きく、拡張子がついているファイルをすべて見つける。**
   * \*\*注:\*\*検証でサイズが10KB以下のファイルとファイル拡張子のないファイルの両方が除外されることを確認した。
7. 正規表現で$includeの包含リストに合致しなかったディレクトリーであっても、そのディレクトリー内のファイルを漏出対象に含めるべきかどうかをチェックする。
   * これは、対象ファイルが包含リストに一致するかどうかを確認する2度目のチャンスを与えているものと見られる。これは、上記ステップ5では正規表現でマッチを行う-Likeで比較を行っているが、ここではGet-ChildItemコマンドレットに-Includeパラメーターを指定して比較を行っているため。
8. 漏出対象として特定されたファイルをループし、fill()関数を呼び出して、各ファイルを漏出させる。

図10は、マルウェア解析用仮想マシン(VM)で実行したさい、このスクリプトが選択した5つのフォルダーを含む最初のグループを示しています。これらの値はスクリプトを実行するコンピューターによって変わるので、ここでは単に、この検証環境だとここからスクリプトがデータの検索を始めた、ということです。
![画像10はスクリプトが漏出対象に選んだフォルダーを示すスクリーンショットです。下の紺色のウィンドウ上で、Cドライブのパスを赤枠でハイライトしています。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-10.png) 図10. スクリプトの実行例。漏出候補に選ばれた最初の5つのディレクトリー

### fill()関数

fill()関数が実際にデータを漏出させます。この関数はファイル漏出先URLを作成する役割を担っていて、System.Net.Webclientオブジェクトと、このオブジェクトの.UploadFileメソッドを使い、HTTP POSTイベント経由で実際の漏出を行います。図11にfill()関数を示します。
![画像11は、fill()関数の概要を示す何行ものコードのスクリーンショットです。スクリプトの動作の順番を2から6の赤い数字で強調表示してあります。](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/04/word-image-127651-11.png) 図11 fill()関数の概要

上のコードは以下を行っています。

1. 全スクリプトの冒頭2行で定義されている変数$idと$token(fill()関数にこれらの定義が含まれていないことに注意)が各ファイル アップロードURL内で使われる。
2. このスクリプトから得られるもっとも重要なIoC(侵害指標)2つを含む$prefixの値を構築する。
   * IPアドレス
     1. ファイルのアップロード先となる脅威アクターのインフラ/サーバーのIPアドレス。
   * ネットワークポート番号
     1. このポート番号は80、443、または[通常はエフェメラル ポートの範囲とされる](https://ja.wikipedia.org/wiki/%E3%82%A8%E3%83%95%E3%82%A7%E3%83%A1%E3%83%A9%E3%83%AB%E3%83%9D%E3%83%BC%E3%83%88)カスタム ポート番号の可能性がある。

\*\*注:\*\*本稿の執筆においてはこのIoC情報を意図的に一部削除してあります。

3. HTTPベースのデータ漏出実行に使うWebClientオブジェクトのインスタンスを作成する。
4. アップロード対象ファイルの完全ファイル パスとなる$fullPath変数を組み立てる。
   * \*\*注:\*\*各HTTP POSTイベントにはファイルの完全パスが含まれることを意味するため、ここは重要。この完全パスと送信元ホストのIPアドレスの両方が取得できれば、事後、漏出したファイルのリストを作成できる。
5. $prefix、$token、$id、$fullPathの各変数を組み合わせて、ファイル アップロード用の完全URLとなる$uriを組み立てる。
6. [WebClient.UploadFile()](https://learn.microsoft.com/ja-jp/dotnet/api/system.net.webclient.uploadfile)メソッドを呼び出し、ファイルをアップロードする。
   * \*\*注:\*\*これによりHTTP POSTイベントが作成される。

### HTTPアクティビティの例

このスクリプトのPOSTリクエストが脅威アクターのWebサーバー上でどのように見えるかを確認するため、ローカルのVM上にサーバーをセットアップし、マルウェア解析用マシンにこのVMをゲートウェイとして使用するように指示してスクリプトを実行しました。以下は、検証環境で実行したさいにこのスクリプトが作成した3つのPOSTリクエストの例です。

192\.168.42.100 - - \[17/Feb/2023:02:46:00 -0000\] "POST /upload?token=TEST\_1\&id=TEST\&fullPath=%2fUsers%2fUnit42%2fDesktop%2fdont\_exfil\_me.eml HTTP/1.1" 200 166 "-" "-" 192.168.42.100 - - \[17/Feb/2023:02:46:00 -0000\] "POST /upload?token=TEST\_1\&id=TEST\&fullPath=%2fUsers%2fUnit42%2fDesktop%2fi\_mean\_please\_dont\_exfil\_me.eml HTTP/1.1" 200 166 "-" "-" 192.168.42.100 - - \[17/Feb/2023:02:46:00 -0000\] "POST /upload?token=TEST\_1\&id=TEST\&fullPath=%2fUsers%2fUnit42%2fDesktop%2fme\_either.docx HTTP/1.1" 200 166 "-" "-"

|-------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 | 192.168.42.100 - - \[17/Feb/2023:02:46:00 -0000\] "POST /upload?token=TEST\_1\&id=TEST\&fullPath=%2fUsers%2fUnit42%2fDesktop%2fdont\_exfil\_me.eml HTTP/1.1" 200 166 "-" "-" 192.168.42.100 - - \[17/Feb/2023:02:46:00 -0000\] "POST /upload?token=TEST\_1\&id=TEST\&fullPath=%2fUsers%2fUnit42%2fDesktop%2fi\_mean\_please\_dont\_exfil\_me.eml HTTP/1.1" 200 166 "-" "-" 192.168.42.100 - - \[17/Feb/2023:02:46:00 -0000\] "POST /upload?token=TEST\_1\&id=TEST\&fullPath=%2fUsers%2fUnit42%2fDesktop%2fme\_either.docx HTTP/1.1" 200 166 "-" "-" |

上記でいう192.168.42\[.\]100のIPアドレスが今回私たちが使用した検証用クライアントVMのIPアドレスです。現実のシナリオだとVice SocietyのWebサーバーはこの部分に被害者のEgress用IPアドレスを表示することになります。

以上より、このスクリプトが開始するHTTPアクティビティに関し、重要事項をいくつか集められました。

1. POSTのパラメーターのfullpathには、ファイル送信元のドライブ レターが含まれて*いない*。
2. このスクリプトはWebサーバーにUser-Agent文字列を提供しない。

[Zeek](https://zeek.org/about/)などのネットワーク セキュリティ監視(NSM)・侵入検知システム(IDS)がある場合や、パケット キャプチャー システムが稼働している環境であれば、社内から社外へ向かうPOSTリクエストを確認できることがあります。こうした社内から社外へのログを確認すればリクエスト長がバイト単位でわかるので、総バイト数に対する送信バイト数に注目することにより、どの版のファイルが漏出したかを特定するのに役立つかもしれません。

## 結論

Vice SocietyのこのPowerShellスクリプトはシンプルなデータ漏出ツールで、マルチプロセッシングやキューイングを使って、システム リソースの消費をおさえています。このスクリプトは、$includeのリストに合致するディレクトリーに存在し、サイズが10KBを超え、拡張子をもつファイルだけを対象としています。この説明に当てはまらないデータは漏出させません。

Windows環境におけるPowerShellスクリプトの性質上、この手の脅威を完全に防止するのは容易ではありませんが、検出と脅威ハントに関するヒントを「[検出と脅威ハント](#post-127684-_tfjt1juueu3)」のセクションに記載しますので、この中でもとくにYARAルールを活用して、自社環境内の脅威の有無の識別にベストを尽くしていただければと思います。ランサムウェア攻撃グループに皆さんのデータを自動で漏出させないようご注意ください。

パロアルトネットワークスのお客様は、次の方法で、これ以下で説明するスクリプトに対する保護と緩和を受けています。

* 本稿末に記載したXQLクエリーはCortex XDRによる同スクリプトの追跡に役立ちます。
* Unit 42のインシデント レスポンス チームによる個別対応もご提供しています。

侵害の懸念があり弊社にインシデントレスポンスに関するご相談をなさりたい場合は、[こちらのフォーム](https://start.paloaltonetworks.jp/contact-unit42.html)からご連絡いただくか、infojapan@paloaltonetworks.comまでメールにてご連絡いただくか、下記の電話番号までお問い合わせください(ご相談は弊社製品のお客様には限定されません)。

* 北米フリーダイヤル: 866.486.4842 (866.4.UNIT42)
* 欧州: +31.20.299.3130
* アジア太平洋: +65.6983.8730
* 日本: +81.50.1790.0200

## 検出と脅威ハント

* 本稿で紹介するYARAルールをお使いのセキュリティ システムに導入します。
* [PowerShellでPowerShellモジュールとスクリプト ブロック ログを有効にします。](https://www.rootusers.com/enable-and-configure-module-script-block-and-transcription-logging-in-windows-powershell/)
  * Windowsイベント ログからEvent ID 400、600、800、4103、4104を確認します。
  * Event IDが4104のイベントのなかでスクリプトの関数名を検索します。
    * Work( $disk )
    * Show( $name )
    * CreateJobLocal( $folders )
    * fill( \[string\]$filename )
* powershell.exe -ExecutionPolicy Bypass -file \\\\\[internal\_ip\_address\]\\s$\\w1.ps1を含むコマンドラインを監視します。
* 不明なリモートHTTPサーバーに対してエンドポイントから/uploadを実行しているHTTP POSTイベントを探します。
* 外部IPアドレス宛のHTTPアクティビティを確認できる場合はそれを調べます。
* ネットワーク トラフィックのスパイクを検出します。
  * ネットワーク トラフィックのベースラインを計測済みであれば、そのベースラインから極端に逸脱しているホストやホスト グループがないかをそのベースラインから判断します。
  * HTTP POSTのサイズにもとづいてアラートを発報できるSIEMやSOARなどのログ アグリゲーション ユーティリティがある場合は、ある特定のサイト(とくにある特定のIPアドレス)に対するPOSTイベント数が基準を上回っている時点がどこかにないかを調べます。また、POSTイベントのリクエスト サイズが所定の閾値を超えた場合にアラートを発報させることも検討します。たとえば、POSTイベントのファイル サイズが10MBを超える場合はアラートを出す、などです。これを行うにはチューニングと自社環境における通常トラフィックがどのようなものかという洞察が必要です。
  * 予期しないアカウントからのネットワーク トラフィック急増がないかどうか調べます。たとえば自社のドメイン管理者アカウント、Enterprise管理者アカウント、一般的サービス アカウントは、サイズの大きなPOSTリクエストを行うことが想定されているでしょうか。そうした場合にアラートを発報できるでしょうか。

## IoC

私たちはこのスクリプトをEvent ID 4104のWindowイベント ログから復元したため、ディスク上に存在していたかもしれない元ファイルのハッシュは入手できていません。そのかわりにスクリプトのファイル名とスクリプトから復元した内容を記載しておきます。

**注:** IPアドレスやポート番号は公開*しない* ことにしました。リクエストがあった場合でもこれらのIoCを提供することは*ありません*。

### ファイル名

* w1.ps1

## YARAルール

このスクリプトの識別用に次のYARAルールが作成されました。本稿公開日現在で、過去1年間の間に、[VirusTotal IntelligenceのRetro Huntシステム](https://support.virustotal.com/hc/en-us/articles/360001293377-Retrohunt)において、このスクリプトには1件しか誤検出がありません。このルールは、被害者のID情報を設定する2行のコードと、HTTP経由でデータを漏出するために使うURI組み立て用の文字列連結メソッドを探します。

rule vice\_society\_ps\_exfil\_script { meta: author = "RyanChapman - Unit42 - PaloAltoNetworks" date = "2023-02-10" description = "Detects Vice Society's 'w1.ps1' Data Exfiltration PowerShell script. Often run via 'powershell.exe -ExecutionPolicy Bypass -file \\\\\[ip\_address\]\\s$\\w1.ps1'." strings: $victim\_id = /\\\[string\\\]\\$id = \\".{0,1000}\\"/ $victim\_token = /\\\[string\\\]\\$token = \\"{0,1000}\\"/ $uri\_prefix = /\\$prefix = \\'https?:\\/\\/{0,300}:\\d{0,6}\\/upload\\'/ nocase ascii wide $uri\_builder = "$uri = \\"$( $prefix )?token=$( $token )\&id=$( $id )\&fullPath=$( $fullPath )\\"" nocase ascii wide condition: (any of ($uri\*)) or (2 of ($victim\*)) }

|----------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 | rule vice\_society\_ps\_exfil\_script { meta: author = "RyanChapman - Unit42 - PaloAltoNetworks" date = "2023-02-10" description = "Detects Vice Society's 'w1.ps1' Data Exfiltration PowerShell script. Often run via 'powershell.exe -ExecutionPolicy Bypass -file \\\\\[ip\_address\]\\s$\\w1.ps1'." strings: $victim\_id = /\\\[string\\\]\\$id = \\".{0,1000}\\"/ $victim\_token = /\\\[string\\\]\\$token = \\"{0,1000}\\"/ $uri\_prefix = /\\$prefix = \\'https?:\\/\\/{0,300}:\\d{0,6}\\/upload\\'/ nocase ascii wide $uri\_builder = "$uri = \\"$( $prefix )?token=$( $token )\&id=$( $id )\&fullPath=$( $fullPath )\\"" nocase ascii wide condition: (any of ($uri\*)) or (2 of ($victim\*)) } |

## Unit 42 マネージド スレット ハンティング チームによるクエリ

config case\_sensitive = false | preset = xdr\_process // Detect powershell command line that contains //\<ip\_address\>/s$/.\*.ps1 | filter action\_process\_image\_name = "powershell.exe" and action\_process\_image\_command\_line ~= "\\\\\\\\((25\[0-5\]|(2\[0-4\]|1\\d|\[1-9\]|)\\d)\\.?\\b){4}\\\\s\[$\]\\\\.\*\[.\]ps1" | fields agent\_hostname, actor\_effective\_username, action\_process\_image\_name, action\_process\_image\_command\_line | alter detected\_ip\_address = arrayindex(regextract(action\_process\_image\_command\_line, "\\b\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\b"), 0) | filter incidr(detected\_ip\_address, "10.0.0.0/8") = true or incidr(detected\_ip\_address, "192.168.0.0/16") = true or incidr(detected\_ip\_address, "172.16.0.0/12") = true

|-------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 | config case\_sensitive = false | preset = xdr\_process // Detect powershell command line that contains //\<ip\_address\>/s$/.\*.ps1 | filter action\_process\_image\_name = "powershell.exe" and action\_process\_image\_command\_line ~= "\\\\\\\\((25\[0-5\]|(2\[0-4\]|1\\d|\[1-9\]|)\\d)\\.?\\b){4}\\\\s\[$\]\\\\.\*\[.\]ps1" | fields agent\_hostname, actor\_effective\_username, action\_process\_image\_name, action\_process\_image\_command\_line | alter detected\_ip\_address = arrayindex(regextract(action\_process\_image\_command\_line, "\\b\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\.\\d{1,3}\\b"), 0) | filter incidr(detected\_ip\_address, "10.0.0.0/8") = true or incidr(detected\_ip\_address, "192.168.0.0/16") = true or incidr(detected\_ip\_address, "172.16.0.0/12") = true |

## 追加リソース

* [教育セクターを狙う持続的脅威Vice Societyのプロファイリング](https://unit42.paloaltonetworks.jp/vice-society-targets-education-sector) -- パロアルトネットワークス Unit 42
* [2022 Unit 42 ランサムウェア脅威レポートからの注目ポイント: 依然として主要な脅威](https://unit42.paloaltonetworks.jp/2022-ransomware-threat-report-highlights) -- パロアルトネットワークス Unit 42
* [2022 Unit 42 ランサムウェア脅威レポート](https://start.paloaltonetworks.jp/unit-42-ransomware-threat-report.html) -- パロアルトネットワークス Unit 42

## 付録: 包含・除外リスト

### Work()関数での除外

( $_.FullName -notlike "\*old\*" ) ( $_.FullName -notlike "\*Backup\*" ) ( $_.FullName -notlike "\*Delete\*" ) ( $_.FullName -notlike "\*Snap\*" ) ( $_.FullName -notlike "\*Backup\*" ) ( $_.FullName -notlike "\*System\*" ) ( $_.FullName -notlike "\*Windows\*" ) ( $_.FullName -notlike "\*}\*" ) ( $_.FullName -notlike "\*{\*" ) ( $_.FusllName -notlike "\*Symantec\*" ) \<-- "FullName"にスペルミスあり ( $_.FullName -notlike "\*Chrome\*" ) ( $_.FullName -notlike "\*Mozilla\*" ) ( $_.FullName -notlike "\*ESET\*" ) ( $_.FullName -notlike "\*Package Cache\*" ) ( $_.FullName -notlike "\*VMWare\*" ) ( $_.FullName -notlike "\*Microsoft\*" ) ( $_.FullName -notlike "\*Sophos\*" ) ( $_.FullName -notlike "\*System Volume Information\*" ) ( $_.FullName -notlike "\*PerfLogs\*" ) ( $_.FullName -notlike "\*Recovery\*" ) ( $_.FullName -notlike "\*Boot\*" ) ( $_.FullName -notlike "\*Program Files\*" ) ( $_.FullName -notlike "\*ProgramData\*" ) ( $_.FullName -notlike "\*msys64\*" ) ( $_.FullName -notlike "\*apache-ant\*" ) ( $_.FullName -notlike "\*libarchive\*" ) ( $_.FullName -notlike "\*MinGW\*" ) ( $_.FullName -notlike "\*Ruby\*" ) ( $_.FullName -notlike "\*mysql-connector\*" ) ( $_.FullName -notlike "\*svm-map\*" ) ( $\_.FullName -notlike "\*TDM-GCC\*" )

|-------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 | ( $_.FullName -notlike "\*old\*" ) ( $_.FullName -notlike "\*Backup\*" ) ( $_.FullName -notlike "\*Delete\*" ) ( $_.FullName -notlike "\*Snap\*" ) ( $_.FullName -notlike "\*Backup\*" ) ( $_.FullName -notlike "\*System\*" ) ( $_.FullName -notlike "\*Windows\*" ) ( $_.FullName -notlike "\*}\*" ) ( $_.FullName -notlike "\*{\*" ) ( $_.FusllName -notlike "\*Symantec\*" ) \<-- "FullName"にスペルミスあり ( $_.FullName -notlike "\*Chrome\*" ) ( $_.FullName -notlike "\*Mozilla\*" ) ( $_.FullName -notlike "\*ESET\*" ) ( $_.FullName -notlike "\*Package Cache\*" ) ( $_.FullName -notlike "\*VMWare\*" ) ( $_.FullName -notlike "\*Microsoft\*" ) ( $_.FullName -notlike "\*Sophos\*" ) ( $_.FullName -notlike "\*System Volume Information\*" ) ( $_.FullName -notlike "\*PerfLogs\*" ) ( $_.FullName -notlike "\*Recovery\*" ) ( $_.FullName -notlike "\*Boot\*" ) ( $_.FullName -notlike "\*Program Files\*" ) ( $_.FullName -notlike "\*ProgramData\*" ) ( $_.FullName -notlike "\*msys64\*" ) ( $_.FullName -notlike "\*apache-ant\*" ) ( $_.FullName -notlike "\*libarchive\*" ) ( $_.FullName -notlike "\*MinGW\*" ) ( $_.FullName -notlike "\*Ruby\*" ) ( $_.FullName -notlike "\*mysql-connector\*" ) ( $_.FullName -notlike "\*svm-map\*" ) ( $\_.FullName -notlike "\*TDM-GCC\*" ) |

( $_.FullName -notlike "\*Windows\*" ) ( $_.FullName -notlike "\*inetpub\*" ) ( $_.FullName -notlike "\*pris\_temp\*" ) ( $_.FullName -notlike "\*Request\*" ) ( $_.FullName -notlike "\*ESET\*" ) ( $_.FullName -notlike "\*Package Cache\*" ) ( $_.FullName -notlike "\*VMWare\*" ) ( $_.FullName -notlike "\*VMMShare\*" ) ( $_.FullName -notlike "\*Logs\*" ) ( $_.FullName -notlike "\*System Volume Information\*" ) ( $_.FullName -notlike "\*WindowsAzure\*" ) ( $_.FullName -notlike "\*Packages\*" ) ( $_.FullName -notlike "\*Boot\*" ) ( $_.FullName -notlike "\*Program Files\*" ) ( $_.FullName -notlike "\*ProgramData\*" ) ( $_.FullName -notlike "\*.cargo\*" ) ( $\_.FullName -notlike "\*.gradle\*" )

|-------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 | ( $_.FullName -notlike "\*Windows\*" ) ( $_.FullName -notlike "\*inetpub\*" ) ( $_.FullName -notlike "\*pris\_temp\*" ) ( $_.FullName -notlike "\*Request\*" ) ( $_.FullName -notlike "\*ESET\*" ) ( $_.FullName -notlike "\*Package Cache\*" ) ( $_.FullName -notlike "\*VMWare\*" ) ( $_.FullName -notlike "\*VMMShare\*" ) ( $_.FullName -notlike "\*Logs\*" ) ( $_.FullName -notlike "\*System Volume Information\*" ) ( $_.FullName -notlike "\*WindowsAzure\*" ) ( $_.FullName -notlike "\*Packages\*" ) ( $_.FullName -notlike "\*Boot\*" ) ( $_.FullName -notlike "\*Program Files\*" ) ( $_.FullName -notlike "\*ProgramData\*" ) ( $_.FullName -notlike "\*.cargo\*" ) ( $\_.FullName -notlike "\*.gradle\*" ) |

### CreateLocalJob()関数での包含

\[array\]$include = @( "\*941\*", "\*1040\*", "\*1099\*", "\*8822\*", "\*9465\*", "\*401\*K\*", "\*401K\*", "\*4506\*T\*", "\*4506T\*", "\*Abkommen\*", "\*ABRH\*", "\*Abtretung\*", "\*abwickeln\*", "\*ACA\*1095\*", "\*Accordi\*", "\*Aceito\*", "\*Acordemen\*", "\*Acordos\*", "\*Acuerde\*", "\*Acuerdo\*", "\*Addres\*", "\*Adres\*", "\*Affectation\*", "\*agreem\*", "\*Agreemen\*Disclosur\*", "\*agreement\*", "\*Alamat\*", "\*Allocation\*", "\*angreifen\*", "\*Angriff\*", "\*Anmeldeformationen\*", "\*Anmeldeinformationen\*", "\*Anmeldenunter\*", "\*Anmeldung\*", "\*Anschrift\*", "\*Anspruch\*", "\*Ansspruch\*", "\*Anweisung\*", "\*AnweisungBank\*", "\*anxious\*", "\*Análise\*", "\*Apotheke\*", "\*ARH\*", "\*Asignación\*", "\*Asignatura\*", "\*Assegnazione\*", "\*Assignation\*", "\*Assignment\*", "\*Atribuição\*", "\*attorn\*", "\*Audit\*", "\*Auditnaadrese\*", "\*Aufführen\*", "\*Aufgabe\*", "\*Aufschühren\*", "\*Auftrag\*", "\*auftrunken\*", "\*Auftrunkinen\*", "\*Auswertung\*", "\*Avaliação\*", "\*Avaliações\*", "\*Avtal\*", "\*balanc\*", "\*bank\*", "\*Bargeld\*", "\*Belästigung\*", "\*Benef\*", "\*benefits\*", "\*Bericht\*", "\*Beschäftigung\*", "\*Betrug\*", "\*Bewertung\*", "\*bezahlen\*", "\*billing\*", "\*bio\*", "\*biometric\*", "\*borrow\*", "\*Brett\*", "\*Brok\*", "\*Buchstabe\*", "\*budget\*", "\*bully\*", "\*Bund\*", "\*bureau\*", "\*Büro\*", "\*capital\*", "\*card\*", "\*card\*SS\*", "\*cash\*", "\*CDA\*", "\*Cessão\*", "\*cestovnípas\*", "\*check\*", "\*checking\*", "\*claim\*", "\*clandestine\*", "\*Committe\*", "\*compilation\*", "\*comprom\*", "\*compromate\*", "\*compromise\*", "\*concealed\*", "\*Concordam\*", "\*Concordo\*", "\*Concordância\*", "\*Conf\*", "\*confid\*", "\*Confidential\*Disclosure\*", "\*Conflict\*", "\*contact\*", "\*contr\*", "\*convict\*", "\*Court\*", "\*CPF\*", "\*crandestin\*", "\*Cred\*", "\*Credential\*", "\*CRH\*", "\*Crim\*", "\*Crime\*", "\*CSE\*", "\*DACA\*", "\*DDRH\*", "\*dead\*", "\*Dean\*", "\*death\*", "\*Demog\*", "\*Demütigung\*", "\*Department\*", "\*Designação\*", "\*Detail\*", "\*Die\*", "\*Diebstahl\*", "\*Dirección\*", "\*Direktor\*", "\*Disburs\*", "\*Disbursement\*", "\*Disclosure\*Agreement\*", "\*Disclosure\*Confidential\*", "\*discriminate\*", "\*Dohody\*", "\*DRH\*", "\*Déclaration\*", "\*EIN\*", "\*Email\*", "\*E-Mail\*", "\*emplo\*", "\*Endereço\*", "\*Enrol\*", "\*enroll\*", "\*Enterin\*", "\*entrusted\*", "\*Erklärung\*", "\*Ermittlung\*", "\*Ertrittlung\*", "\*Evaluasi\*", "\*Evaluation\*", "\*Evaluierung\*", "\*Ewaluacja\*", "\*Excerpted\*", "\*FATCA\*", "\*federal\*", "\*Finan\*", "\*Finanzen\*", "\*Fiscalización\*", "\*Forbidden\*", "\*Form\*", "\*fraud\*", "\*Free\*", "\*Freeman\*", "\*Frei\*", "\*FSA\*", "\*föderal\*", "\*Geduldig\*", "\*Gefühllos\*", "\*Gehaltsabechung\*", "\*geheim\*", "\*Geheimnis\*", "\*GESetzlich\*", "\*Gewalt\*", "\*Gleichgewicht\*", "\*gov\*", "\*government\*", "\*grantor\*", "\*haras\*", "\*Haushalt\*", "\*hidden\*", "\*hir\*", "\*Hirf\*", "\*Hodnocení\*", "\*HR\*", "\*HRDD\*", "\*Human\*", "\*I\*765\*", "\*i\*9\*", "\*i9\*", "\*identi\*", "\*illegal\*", "\*important\*", "\*Incarico\*", "\*Incident\*", "\*Income\*", "\*Indirizzo\*", "\*individual\*", "\*Info\*", "\*Information\*", "\*informationprivileged\*", "\*Innen\*", "\*insider\*", "\*Insurance\*", "\*Internal\*", "\*Intima\*", "\*investigation\*", "\*invoicing\*", "\*IRS\*", "\*isola\*", "\*ITIN\*", "\*K\*1\*", "\*k\*12\*", "\*K1\*", "\*Karte\*", "\*Kasse\*", "\*Kesepakatan\*", "\*kill\*", "\*klassifiziert\*", "\*kompromet\*", "\*Kontakt\*", "\*Kontoauszug\*", "\*Kontrola\*", "\*Kritik\*", "\*kritisch\*", "\*Kuppel\*", "\*Legal\*", "\*lender\*", "\*letter\*", "\*List\*", "\*loan\*", "\*Login\*", "\*Lohn\*", "\*Lohn-und\*", "\*m\*274\*", "\*mail\*", "\*Mechan\*", "\*Med\*", "\*Menschlich\*", "\*misdemeanor\*", "\*Missbrauch\*", "\*Missão\*", "\*Molecula\*", "\*Morada\*", "\*Moradas\*", "\*MwSt\*", "\*National\*Health\*", "\*NDA\*", "\*Nds\*", "\*NHS\*", "\*nicht\*", "\*notsorted\*", "\*Numb\*", "\*Numero\*", "\*obligat\*", "\*Ocena\*", "\*Offenbarung\*", "\*office\*", "\*order\*", "\*Osoite\*", "\*Osoitteet\*", "\*Partn\*", "\*pas\*", "\*passport\*", "\*passwd\*", "\*password\*", "\*patient\*", "\*PATIENT\*", "\*Pause\*", "\*pay\*", "\*payment\*", "\*payroll\*", "\*Pemeriksaan\*", "\*penalty\*", "\*Pendel\*", "\*pendeln\*", "\*Penugasan\*", "\*Perjanjian\*", "\*Pers\*", "\*person\*", "\*Personnel\*", "\*Pharm\*", "\*Phon\*", "\*Phone\*", "\*Phys\*", "\*porno\*", "\*Porozumienie\*", "\*principal\*", "\*priv\*", "\*priva\*", "\*privit\*", "\*promissor\*", "\*Przydział\*", "\*Przypisanie\*", "\*Prüfbericht\*", "\*Prüfung\*", "\*pwd\*", "\*Přidělení\*", "\*Rechnungsprüfung\*", "\*Rechtliches\*", "\*rechtswidrig\*", "\*Recruitment\*", "\*Recursos\*Humanos\*", "\*RecursosHumanos\*", "\*Regierung\*", "\*Reisepass\*", "\*Rekrutierung\*", "\*report\*", "\*Resour\*", "\*restrict\*", "\*resurses\*human\*", "\*Revenue\*", "\*Revision\*", "\*RHO\*", "\*routing\*", "\*RRHH\*", "\*salar\*", "\*Salary\*", "\*Samen\*", "\*Sanit\*", "\*Sanitäter\*", "\*saving\*", "\*savings\*", "\*scan\*", "\*scannen\*", "\*scans\*", "\*SCHNELL\*", "\*sec\*", "\*secret\*", "\*security\*", "\*seed\*", "\*Seller\*", "\*Seltsamkeit\*", "\*sex\*", "\*Sicherheit\*", "\*Signed\*", "\*Smlouvy\*", "\*Solicitations\*", "\*Sopimukset\*", "\*Souhlas\*", "\*Soz\*", "\*sparen\*", "\*spüren\*", "\*SQL\*", "\*SS\*4\*", "\*SS\*card\*", "\*SSA\*", "\*SSN\*", "\*Stab\*", "\*STAC\*", "\*Staf\*", "\*state\*", "\*Statement\*", "\*Statement\*Bank\*", "\*Stechen\*", "\*Stehlen\*", "\*Stelkeit\*", "\*Stellungnahme\*", "\*Stellungsnahme\*", "\*Steuerzahler\*", "\*studen\*", "\*superintendent\*", "\*Susitarimai\*", "\*Susitarimas\*", "\*Sutartis\*", "\*Sutartys\*", "\*SWIFT\*", "\*SÜNDE\*", "\*Tare\*", "\*tax\*", "\*Taxpayer\*", "\*Telef\*", "\*Terror\*", "\*TIN\*", "\*Tod\*", "\*tot\*", "\*Transact\*", "\*Trennen\*", "\*trust\*", "\*Tugas\*", "\*Tätigen\*", "\*Umowa\*", "\*unclas\*", "\*unclassified\*", "\*Untersuchung\*", "\*Unterweichnet\*", "\*Unterzeichnet\*", "\*Uppdrag\*", "\*USCIS\*", "\*Valutazione\*", "\*Vend\*", "\*violence\*", "\*Vorfall\*", "\*Vyhodnocení\*", "\*Vér\*", "\*W\*2\*", "\*w\*4\*", "\*W\*7\*", "\*W\*8\*BEN\*", "\*w\*9\*", "\*W2\*", "\*w4\*", "\*W7\*", "\*W8BEN\*", "\*w9\*", "\*Wage\*", "\*Wenker\*", "\*wicht\*", "\*wied\*", "\*with\*", "\*withdr\*", "\*Zadanie\*", "\*Zadání\*", "\*Zahlen\*", "\*Zahlung\*", "\*Zellbiologies\*", "\*Zlecenie\*", "\*Zuordnung\*", "\*Zusammenstellung\*", "\*zustimmen\*", "\*zuversichtlich\*", "\*Zuweisung\*", "\*Zählung\*", "\*équilibre\*", "\*Évaluation\*", "\*Überprüfung\*", "\*Úkol\*" );

|---|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 | \[array\]$include = @( "\*941\*", "\*1040\*", "\*1099\*", "\*8822\*", "\*9465\*", "\*401\*K\*", "\*401K\*", "\*4506\*T\*", "\*4506T\*", "\*Abkommen\*", "\*ABRH\*", "\*Abtretung\*", "\*abwickeln\*", "\*ACA\*1095\*", "\*Accordi\*", "\*Aceito\*", "\*Acordemen\*", "\*Acordos\*", "\*Acuerde\*", "\*Acuerdo\*", "\*Addres\*", "\*Adres\*", "\*Affectation\*", "\*agreem\*", "\*Agreemen\*Disclosur\*", "\*agreement\*", "\*Alamat\*", "\*Allocation\*", "\*angreifen\*", "\*Angriff\*", "\*Anmeldeformationen\*", "\*Anmeldeinformationen\*", "\*Anmeldenunter\*", "\*Anmeldung\*", "\*Anschrift\*", "\*Anspruch\*", "\*Ansspruch\*", "\*Anweisung\*", "\*AnweisungBank\*", "\*anxious\*", "\*Análise\*", "\*Apotheke\*", "\*ARH\*", "\*Asignación\*", "\*Asignatura\*", "\*Assegnazione\*", "\*Assignation\*", "\*Assignment\*", "\*Atribuição\*", "\*attorn\*", "\*Audit\*", "\*Auditnaadrese\*", "\*Aufführen\*", "\*Aufgabe\*", "\*Aufschühren\*", "\*Auftrag\*", "\*auftrunken\*", "\*Auftrunkinen\*", "\*Auswertung\*", "\*Avaliação\*", "\*Avaliações\*", "\*Avtal\*", "\*balanc\*", "\*bank\*", "\*Bargeld\*", "\*Belästigung\*", "\*Benef\*", "\*benefits\*", "\*Bericht\*", "\*Beschäftigung\*", "\*Betrug\*", "\*Bewertung\*", "\*bezahlen\*", "\*billing\*", "\*bio\*", "\*biometric\*", "\*borrow\*", "\*Brett\*", "\*Brok\*", "\*Buchstabe\*", "\*budget\*", "\*bully\*", "\*Bund\*", "\*bureau\*", "\*Büro\*", "\*capital\*", "\*card\*", "\*card\*SS\*", "\*cash\*", "\*CDA\*", "\*Cessão\*", "\*cestovnípas\*", "\*check\*", "\*checking\*", "\*claim\*", "\*clandestine\*", "\*Committe\*", "\*compilation\*", "\*comprom\*", "\*compromate\*", "\*compromise\*", "\*concealed\*", "\*Concordam\*", "\*Concordo\*", "\*Concordância\*", "\*Conf\*", "\*confid\*", "\*Confidential\*Disclosure\*", "\*Conflict\*", "\*contact\*", "\*contr\*", "\*convict\*", "\*Court\*", "\*CPF\*", "\*crandestin\*", "\*Cred\*", "\*Credential\*", "\*CRH\*", "\*Crim\*", "\*Crime\*", "\*CSE\*", "\*DACA\*", "\*DDRH\*", "\*dead\*", "\*Dean\*", "\*death\*", "\*Demog\*", "\*Demütigung\*", "\*Department\*", "\*Designação\*", "\*Detail\*", "\*Die\*", "\*Diebstahl\*", "\*Dirección\*", "\*Direktor\*", "\*Disburs\*", "\*Disbursement\*", "\*Disclosure\*Agreement\*", "\*Disclosure\*Confidential\*", "\*discriminate\*", "\*Dohody\*", "\*DRH\*", "\*Déclaration\*", "\*EIN\*", "\*Email\*", "\*E-Mail\*", "\*emplo\*", "\*Endereço\*", "\*Enrol\*", "\*enroll\*", "\*Enterin\*", "\*entrusted\*", "\*Erklärung\*", "\*Ermittlung\*", "\*Ertrittlung\*", "\*Evaluasi\*", "\*Evaluation\*", "\*Evaluierung\*", "\*Ewaluacja\*", "\*Excerpted\*", "\*FATCA\*", "\*federal\*", "\*Finan\*", "\*Finanzen\*", "\*Fiscalización\*", "\*Forbidden\*", "\*Form\*", "\*fraud\*", "\*Free\*", "\*Freeman\*", "\*Frei\*", "\*FSA\*", "\*föderal\*", "\*Geduldig\*", "\*Gefühllos\*", "\*Gehaltsabechung\*", "\*geheim\*", "\*Geheimnis\*", "\*GESetzlich\*", "\*Gewalt\*", "\*Gleichgewicht\*", "\*gov\*", "\*government\*", "\*grantor\*", "\*haras\*", "\*Haushalt\*", "\*hidden\*", "\*hir\*", "\*Hirf\*", "\*Hodnocení\*", "\*HR\*", "\*HRDD\*", "\*Human\*", "\*I\*765\*", "\*i\*9\*", "\*i9\*", "\*identi\*", "\*illegal\*", "\*important\*", "\*Incarico\*", "\*Incident\*", "\*Income\*", "\*Indirizzo\*", "\*individual\*", "\*Info\*", "\*Information\*", "\*informationprivileged\*", "\*Innen\*", "\*insider\*", "\*Insurance\*", "\*Internal\*", "\*Intima\*", "\*investigation\*", "\*invoicing\*", "\*IRS\*", "\*isola\*", "\*ITIN\*", "\*K\*1\*", "\*k\*12\*", "\*K1\*", "\*Karte\*", "\*Kasse\*", "\*Kesepakatan\*", "\*kill\*", "\*klassifiziert\*", "\*kompromet\*", "\*Kontakt\*", "\*Kontoauszug\*", "\*Kontrola\*", "\*Kritik\*", "\*kritisch\*", "\*Kuppel\*", "\*Legal\*", "\*lender\*", "\*letter\*", "\*List\*", "\*loan\*", "\*Login\*", "\*Lohn\*", "\*Lohn-und\*", "\*m\*274\*", "\*mail\*", "\*Mechan\*", "\*Med\*", "\*Menschlich\*", "\*misdemeanor\*", "\*Missbrauch\*", "\*Missão\*", "\*Molecula\*", "\*Morada\*", "\*Moradas\*", "\*MwSt\*", "\*National\*Health\*", "\*NDA\*", "\*Nds\*", "\*NHS\*", "\*nicht\*", "\*notsorted\*", "\*Numb\*", "\*Numero\*", "\*obligat\*", "\*Ocena\*", "\*Offenbarung\*", "\*office\*", "\*order\*", "\*Osoite\*", "\*Osoitteet\*", "\*Partn\*", "\*pas\*", "\*passport\*", "\*passwd\*", "\*password\*", "\*patient\*", "\*PATIENT\*", "\*Pause\*", "\*pay\*", "\*payment\*", "\*payroll\*", "\*Pemeriksaan\*", "\*penalty\*", "\*Pendel\*", "\*pendeln\*", "\*Penugasan\*", "\*Perjanjian\*", "\*Pers\*", "\*person\*", "\*Personnel\*", "\*Pharm\*", "\*Phon\*", "\*Phone\*", "\*Phys\*", "\*porno\*", "\*Porozumienie\*", "\*principal\*", "\*priv\*", "\*priva\*", "\*privit\*", "\*promissor\*", "\*Przydział\*", "\*Przypisanie\*", "\*Prüfbericht\*", "\*Prüfung\*", "\*pwd\*", "\*Přidělení\*", "\*Rechnungsprüfung\*", "\*Rechtliches\*", "\*rechtswidrig\*", "\*Recruitment\*", "\*Recursos\*Humanos\*", "\*RecursosHumanos\*", "\*Regierung\*", "\*Reisepass\*", "\*Rekrutierung\*", "\*report\*", "\*Resour\*", "\*restrict\*", "\*resurses\*human\*", "\*Revenue\*", "\*Revision\*", "\*RHO\*", "\*routing\*", "\*RRHH\*", "\*salar\*", "\*Salary\*", "\*Samen\*", "\*Sanit\*", "\*Sanitäter\*", "\*saving\*", "\*savings\*", "\*scan\*", "\*scannen\*", "\*scans\*", "\*SCHNELL\*", "\*sec\*", "\*secret\*", "\*security\*", "\*seed\*", "\*Seller\*", "\*Seltsamkeit\*", "\*sex\*", "\*Sicherheit\*", "\*Signed\*", "\*Smlouvy\*", "\*Solicitations\*", "\*Sopimukset\*", "\*Souhlas\*", "\*Soz\*", "\*sparen\*", "\*spüren\*", "\*SQL\*", "\*SS\*4\*", "\*SS\*card\*", "\*SSA\*", "\*SSN\*", "\*Stab\*", "\*STAC\*", "\*Staf\*", "\*state\*", "\*Statement\*", "\*Statement\*Bank\*", "\*Stechen\*", "\*Stehlen\*", "\*Stelkeit\*", "\*Stellungnahme\*", "\*Stellungsnahme\*", "\*Steuerzahler\*", "\*studen\*", "\*superintendent\*", "\*Susitarimai\*", "\*Susitarimas\*", "\*Sutartis\*", "\*Sutartys\*", "\*SWIFT\*", "\*SÜNDE\*", "\*Tare\*", "\*tax\*", "\*Taxpayer\*", "\*Telef\*", "\*Terror\*", "\*TIN\*", "\*Tod\*", "\*tot\*", "\*Transact\*", "\*Trennen\*", "\*trust\*", "\*Tugas\*", "\*Tätigen\*", "\*Umowa\*", "\*unclas\*", "\*unclassified\*", "\*Untersuchung\*", "\*Unterweichnet\*", "\*Unterzeichnet\*", "\*Uppdrag\*", "\*USCIS\*", "\*Valutazione\*", "\*Vend\*", "\*violence\*", "\*Vorfall\*", "\*Vyhodnocení\*", "\*Vér\*", "\*W\*2\*", "\*w\*4\*", "\*W\*7\*", "\*W\*8\*BEN\*", "\*w\*9\*", "\*W2\*", "\*w4\*", "\*W7\*", "\*W8BEN\*", "\*w9\*", "\*Wage\*", "\*Wenker\*", "\*wicht\*", "\*wied\*", "\*with\*", "\*withdr\*", "\*Zadanie\*", "\*Zadání\*", "\*Zahlen\*", "\*Zahlung\*", "\*Zellbiologies\*", "\*Zlecenie\*", "\*Zuordnung\*", "\*Zusammenstellung\*", "\*zustimmen\*", "\*zuversichtlich\*", "\*Zuweisung\*", "\*Zählung\*", "\*équilibre\*", "\*Évaluation\*", "\*Überprüfung\*", "\*Úkol\*" ); |

### CreateLocalJob()関数での除外

\[array\]$excludes = @( "\*.xaml", "\*.evt", "\*.VDI", "\*.bac", "\*.dtd", "\*.bkf", "\*.bkp", "\*.pfl", "\*.axd", "\*.x32", "\*.wmf", "\*.cr2", "\*.vsdx", "\*.ap\_", "\*.nib", "\*.IDX", "\*.node", "\*.cpi", "\*.c", "\*.resources", "\*.properties", "\*.gz", "\*.pp", "\*.gm", "\*.hro", "\*.info", "\*.sqlite", "\*.cdpresource", "\*.bat", "\*.jsonlz4", "\*.soc", "\*.bundled", "\*.m4a", "\*.modd", "\*.cfm", "\*.thmx", "\*.dotm", "\*.glox", "\*.osxp", "\*acrodata", "\*.lua", "\*.nse", "\*.qm", "\*.tpl", "\*.contact", "\*.vcf", "\*.potx", "\*.md5", "\*.cat", "\*.csproj", "\*.nupkg", "\*cache", "\*temp", "\*.rdp", "\*.leveldb", "\*.sch", "\*AppData/Roaming\*", "\*.blog", "\*.pbk", "\*download", "\*\_metadata", "\*.sys", "\*.efi", "\*.vbs", "\*.ps1", "\*.jfm", "\*.mui", "\*.psd1", "\*.psd", "\*.cdxml", "\*.ps1xml", "\*.wer", "\*.ass", "\*.ed1", "\*.obj", "\*.emf", "\*.apk", "\*.oab", "\*.accdb", "\*.mov", "\*.eps", "\*.NEF", "\*.mp3", "\*.idml\*", "\*.pkf", "\*.wav", "\*.aiff", "\*.au", "\*.avi", "\*.bmp", "\*.cvs", "\*.dbf", "\*.security", "\*.fp5", "\*.msc", "\*.pdb", "\*.inf", "\*.diz", "\*.asc", "\*.mst", "\*.chg", "\*.su", "\*.cab", "\*.pfx", "\*.log", "\*.dif", "\*.fm3", "\*.hqx", "\*.xaml", "\*.evt", "\*.mdb", "\*.mid", "\*.midi", "\*.ppt", "\*.pptx", "\*.psp", "\*.qxd", "\*.ra", "\*.sit", "\*.tar", "\*.wk3", "\*.ai", ".\*recicle\*", "\*.mp4", "\*.indd", "\*.tiff", "\*.tif", "\*.etl", "\*ProgramData\*", "\*Program Files\*", "\*Boot\*", "\*Recovery\*", "\*System Volume Information\*", "\*Sophos\*", "\*Microsoft\*", "\*VMWare\*", "\*Package Cache\*", "\*ESET\*", "\*Mozilla\*", "\*Symantec\*", "\*{\*", "\*}\*", "\*Windows\*", "\*.kit\*", "\*.htm\*", "\*.jsp", "\*.txt", "\*.py", "\*.pyc", "\*.dll", "\*.exe", "\*.js", "\*.css", "\*.evtx", "\*.rb", "\*.jar", "\*.dat", "\*.ini", "\*.xrm-ms", "\*.xml", "\*.swf", "\*.gif", "\*.url", "\*.lnk", "\*.cs", "\*.json", "\*.bak", "\*.md", "\*.manifest", "\*.man", "\*.template", "\*.xsd", "\*.aspx", "\*.h", "\*.Pid", "\*.frm", "\*.msi", "\*.pls", "\*.checksum", "\*.cdf-ms", "\*.cmd", "\*. rpt", "\*.php", "\*.svc", "\*.java", "\*.class", "\*.trn", "\*.ipa", "\*.procedure", "\*.vb", "\*.cshtml", "\*.config", "\*.chm", "\*.msp", "\*.msm", "\*.ascx", "\*.application", "\*.cls", "\*.deploy", "\*.DIC", "\*.rll", "\*.so", "\*.table", "\*.tmp", "\*.suo", "\*.vsix", "\*.wsdl", "\*.tt", "\*.cch", "\*.chw", "\*.epub", "\*.form", "\*.jss", "\*.jsm", "\*.ico", "\*.function", "\*.hlp", "\*.ldf", "\*.map", "\*.mof", "\*.msg", "\*.fmx", "\*.MSB", "\*.db", "\*.rep", "\*.plb", "\*.res", "\*.ctl", "\*.WRI", "\*.cnt", "\*.pll", "\*.ccb", "\*.lst", "\*.resx", "\*.NLB", "\*.ttf" );

|---|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 | \[array\]$excludes = @( "\*.xaml", "\*.evt", "\*.VDI", "\*.bac", "\*.dtd", "\*.bkf", "\*.bkp", "\*.pfl", "\*.axd", "\*.x32", "\*.wmf", "\*.cr2", "\*.vsdx", "\*.ap\_", "\*.nib", "\*.IDX", "\*.node", "\*.cpi", "\*.c", "\*.resources", "\*.properties", "\*.gz", "\*.pp", "\*.gm", "\*.hro", "\*.info", "\*.sqlite", "\*.cdpresource", "\*.bat", "\*.jsonlz4", "\*.soc", "\*.bundled", "\*.m4a", "\*.modd", "\*.cfm", "\*.thmx", "\*.dotm", "\*.glox", "\*.osxp", "\*acrodata", "\*.lua", "\*.nse", "\*.qm", "\*.tpl", "\*.contact", "\*.vcf", "\*.potx", "\*.md5", "\*.cat", "\*.csproj", "\*.nupkg", "\*cache", "\*temp", "\*.rdp", "\*.leveldb", "\*.sch", "\*AppData/Roaming\*", "\*.blog", "\*.pbk", "\*download", "\*\_metadata", "\*.sys", "\*.efi", "\*.vbs", "\*.ps1", "\*.jfm", "\*.mui", "\*.psd1", "\*.psd", "\*.cdxml", "\*.ps1xml", "\*.wer", "\*.ass", "\*.ed1", "\*.obj", "\*.emf", "\*.apk", "\*.oab", "\*.accdb", "\*.mov", "\*.eps", "\*.NEF", "\*.mp3", "\*.idml\*", "\*.pkf", "\*.wav", "\*.aiff", "\*.au", "\*.avi", "\*.bmp", "\*.cvs", "\*.dbf", "\*.security", "\*.fp5", "\*.msc", "\*.pdb", "\*.inf", "\*.diz", "\*.asc", "\*.mst", "\*.chg", "\*.su", "\*.cab", "\*.pfx", "\*.log", "\*.dif", "\*.fm3", "\*.hqx", "\*.xaml", "\*.evt", "\*.mdb", "\*.mid", "\*.midi", "\*.ppt", "\*.pptx", "\*.psp", "\*.qxd", "\*.ra", "\*.sit", "\*.tar", "\*.wk3", "\*.ai", ".\*recicle\*", "\*.mp4", "\*.indd", "\*.tiff", "\*.tif", "\*.etl", "\*ProgramData\*", "\*Program Files\*", "\*Boot\*", "\*Recovery\*", "\*System Volume Information\*", "\*Sophos\*", "\*Microsoft\*", "\*VMWare\*", "\*Package Cache\*", "\*ESET\*", "\*Mozilla\*", "\*Symantec\*", "\*{\*", "\*}\*", "\*Windows\*", "\*.kit\*", "\*.htm\*", "\*.jsp", "\*.txt", "\*.py", "\*.pyc", "\*.dll", "\*.exe", "\*.js", "\*.css", "\*.evtx", "\*.rb", "\*.jar", "\*.dat", "\*.ini", "\*.xrm-ms", "\*.xml", "\*.swf", "\*.gif", "\*.url", "\*.lnk", "\*.cs", "\*.json", "\*.bak", "\*.md", "\*.manifest", "\*.man", "\*.template", "\*.xsd", "\*.aspx", "\*.h", "\*.Pid", "\*.frm", "\*.msi", "\*.pls", "\*.checksum", "\*.cdf-ms", "\*.cmd", "\*. rpt", "\*.php", "\*.svc", "\*.java", "\*.class", "\*.trn", "\*.ipa", "\*.procedure", "\*.vb", "\*.cshtml", "\*.config", "\*.chm", "\*.msp", "\*.msm", "\*.ascx", "\*.application", "\*.cls", "\*.deploy", "\*.DIC", "\*.rll", "\*.so", "\*.table", "\*.tmp", "\*.suo", "\*.vsix", "\*.wsdl", "\*.tt", "\*.cch", "\*.chw", "\*.epub", "\*.form", "\*.jss", "\*.jsm", "\*.ico", "\*.function", "\*.hlp", "\*.ldf", "\*.map", "\*.mof", "\*.msg", "\*.fmx", "\*.MSB", "\*.db", "\*.rep", "\*.plb", "\*.res", "\*.ctl", "\*.WRI", "\*.cnt", "\*.pll", "\*.ccb", "\*.lst", "\*.resx", "\*.NLB", "\*.ttf" ); |

トップに戻る

### タグ

* [PowerShell Scripts](https://unit42.paloaltonetworks.com/ja/tag/powershell-scripts-ja/ "PowerShell Scripts")
* [Vice Society](https://unit42.paloaltonetworks.com/ja/tag/vice-society-ja/ "Vice Society")  
  [Threat Research Center](https://unit42.paloaltonetworks.com/ja/ "Threat Research") [次ページ:ポルトガル語話者を狙う暗号通貨窃取マルウェアCryptoClippy](https://unit42.paloaltonetworks.com/ja/crypto-clipper-targets-portuguese-speakers/ "ポルトガル語話者を狙う暗号通貨窃取マルウェアCryptoClippy")

### 目次

* 

### 関連記事

* [ランサムウェア振り返り: 2024 年上半期](https://unit42.paloaltonetworks.com/ja/unit-42-ransomware-leak-site-data-analysis/ "article - table of contents")
* [2024 年 ランサムウェア振り返り: Unit 42 によるリーク サイト分析](https://unit42.paloaltonetworks.com/ja/unit-42-ransomware-leak-site-data-analysis-all-2023/ "article - table of contents")
* [教育セクターを狙う持続的脅威Vice Societyのプロファイリング](https://unit42.paloaltonetworks.com/ja/vice-society-targets-education-sector/ "article - table of contents")

## 関連項目 マルウェア リソース

![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年8月6日 [#### ChainDropの脅威の概要:自己増殖型npmワームの内部](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/ja/tag/blockchain-ja/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/ja/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/ja/tag/claude-code/ "Claude code")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/chaindrop-npm-worm-analysis/ "ChainDropの脅威の概要:自己増殖型npmワームの内部")  
  ![Pictorial representation of the npm packages supply chain attack. Screen displaying code with a prominent alert symbol and the words 'VIRUS DETECTED' highlighted in red.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/05_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年6月2日 [#### npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/ja/tag/credential-harvesting-ja/ "Credential Harvesting")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Npm packages](https://unit42.paloaltonetworks.com/ja/tag/npm-packages/ "npm packages")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/monitoring-npm-supply-chain-attacks/ "npmの脅威の状況: アタックサーフェスと緩和策(6月2日更新)")  
  ![Pictorial representation of Screening Serpens. An illustrated blue snake is highlighted by a red circle against a night sky. The constellation serpens.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/Serpens-Iran-A-1920x900-2-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)脅威アクター グループ](https://unit42.paloaltonetworks.com/ja/category/threat-actor-groups-ja/) 2026年5月22日 [#### イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/ja/tag/advanced-persistent-threat-ja/ "Advanced Persistent Threat")

* [AppDomainManager](https://unit42.paloaltonetworks.com/ja/tag/appdomainmanager/ "AppDomainManager")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/tracking-iran-apt-screening-serpens/ "イランAPT Screening Serpensによる2026年スパイ キャンペーンの追跡")  
  ![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月17日 [#### 脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/ja/tag/apk-ja/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/ja/tag/ddos-attacks-ja/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/ja/tag/genai-ja/ "GenAI")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/iranian-cyberattacks-2026/ "脅威情報: 2026年イランに関するサイバー リスクの激化(4月17日更新)")  
  ![Pictorial representation of the supply chain attack compromising Axios. A giant eye made of glowing binary code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/02_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年4月1日 [#### 脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/)

* [API attacks](https://unit42.paloaltonetworks.com/ja/tag/api-attacks-ja/ "API attacks")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")

* [Powershell](https://unit42.paloaltonetworks.com/ja/tag/powershell-ja/ "Powershell")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/axios-supply-chain-attack/ "脅威概要:Axiosサプライ チェーン攻撃で広範に及ぶ影響")  
  ![Pictorial representation of TeamPCP. Glowing code on a screen where several word such as Crime, Hackers, and Security are highlighted in a contrasting color.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/03_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年3月31日 [#### プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/)

* [CVE-2025-55182](https://unit42.paloaltonetworks.com/ja/tag/cve-2025-55182-ja/ "CVE-2025-55182")

* [GitHub](https://unit42.paloaltonetworks.com/ja/tag/github-ja/ "GitHub")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/teampcp-supply-chain-attacks/ "プロテクターを武器として利用する:セキュリティ インフラにおけるTeamPCPの多段階サプライ チェーン攻撃")  
  ![Pictorial representation of phishing campaign. A blurred image focusing on a person typing on a laptop with lines of code visible on the screen, illuminated in blue and red lights, suggestive of intense coding or cyber activities.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/06_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年3月24日 [#### 脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/)

* [Email scam](https://unit42.paloaltonetworks.com/ja/tag/email-scam/ "email scam")

* [Lure](https://unit42.paloaltonetworks.com/ja/tag/lure/ "lure")

* [Phishing](https://unit42.paloaltonetworks.com/ja/tag/phishing-ja/ "phishing")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/phishing-attackers-pose-as-panw-recruiters/ "脅威情報: パロアルトネットワークスの人材獲得チームになりすました採用スキーム")  
  ![Pictorial representation of Notepad++ supply chain compromise. A digital rendering of Earth from space, focusing on North and South America. The continents are illuminated in blue, with red lines and dots indicating data connections across various locations. Dark background highlights the vibrant network representation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/11_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)主なサイバー脅威](https://unit42.paloaltonetworks.com/ja/category/top-cyberthreats-ja/) 2026年2月11日 [#### 国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/)

* [Backdoor](https://unit42.paloaltonetworks.com/ja/tag/backdoor-ja/ "backdoor")

* [Cobalt Strike](https://unit42.paloaltonetworks.com/ja/tag/cobalt-strike-ja/ "Cobalt Strike")

* [DLL Sideloading](https://unit42.paloaltonetworks.com/ja/tag/dll-sideloading-ja/ "DLL Sideloading")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/notepad-infrastructure-compromise/ "国家支援型の脅威アクターがNotepad++のサプライチェーンを悪用")  
  ![Pictorial representation of runtime assembly attacks. Digital artwork of a glowing, futuristic shield disintegrating into small particles, set against a dark blue, bokeh-effect background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月22日 [#### ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/)

* [API](https://unit42.paloaltonetworks.com/ja/tag/api-ja/ "API")

* [Google](https://unit42.paloaltonetworks.com/ja/tag/google-ja/ "Google")

* [JavaScript](https://unit42.paloaltonetworks.com/ja/tag/javascript-ja/ "JavaScript")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/real-time-malicious-javascript-through-llms/ "ランタイムアセンブリ攻撃の新たなフロンティア：LLMを活用したフィッシング用JavaScriptのリアルタイム生成")  
  ![Pictorial representation of SLOW#TEMPEST campaign. Digital artwork depicting a malware alert symbol on a computer screen, with background of blurred programming code in blue and red colors.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/07_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)脅威リサーチ](https://unit42.paloaltonetworks.com/ja/category/threat-research-ja/) 2026年1月2日 [#### Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer](https://unit42.paloaltonetworks.com/ja/vvs-stealer/)

* [Discord](https://unit42.paloaltonetworks.com/ja/tag/discord/ "Discord")

* [Infostealer](https://unit42.paloaltonetworks.com/ja/tag/infostealer-ja/ "Infostealer")

* [Python](https://unit42.paloaltonetworks.com/ja/tag/python-ja/ "Python")  
  [今すぐ読む ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ja/vvs-stealer/ "Pyarmorを利用して難読化と検知回避を行うVVS Discord Stealer")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/Unit-42_get-updates-banner.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Unit 42 からの最新情報を取得

## 進化する脅威の状況を常に先取り

メール アドレス

本フォームを送信することにより、[利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)に同意し、[プライバシー ポリシー](https://www.paloaltonetworks.jp/legal-notices/privacy)を承認したことになります。

本サイトは reCAPTCHA で保護されており、Googleの[プライバシー ポリシー](https://policies.google.com/privacy) と[サービス利用規約](https://policies.google.com/terms)が適用されます。

Invalid captcha!
サブスクライブ ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} 製品とサービス

* [AI利用ネットワーク セキュリティ プラットフォーム](https://www.paloaltonetworks.jp/network-security)

* [AIのセキュア バイ デザイン](https://www.paloaltonetworks.jp/precision-ai-security/secure-ai-by-design)

* [Prisma AIRS](https://www.paloaltonetworks.jp/prisma/prisma-ai-runtime-security)

* [AI Access Security](https://www.paloaltonetworks.jp/sase/ai-access-security)

* [クラウド提供型セキュリティ サービス](https://www.paloaltonetworks.jp/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.jp/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.jp/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.jp/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.jp/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/enterprise-iot-security)

* [Medical IoT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/medical-iot-security)

* [Industrial OT Security](https://www.paloaltonetworks.jp/content/pan/ja_JP/network-security/industrial-ot-security)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [次世代ファイアウォール](https://www.paloaltonetworks.jp/network-security/next-generation-firewall)

* [ハードウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/hardware-firewall-innovations)

* [ソフトウェア ファイアウォール](https://www.paloaltonetworks.jp/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.jp/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.jp/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.jp/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.jp/network-security/panorama)

* [セキュア アクセス サービス エッジ](https://www.paloaltonetworks.jp/sase)

* [Prisma SASE](https://www.paloaltonetworks.jp/sase)

* [App Acceleration](https://www.paloaltonetworks.jp/sase/app-acceleration)

* [自律型デジタルエクスペリエンス管理](https://www.paloaltonetworks.jp/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.jp/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.jp/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.jp/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.jp/sase/sd-wan)

* [リモート ブラウザ分離](https://www.paloaltonetworks.jp/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.jp/sase/saas-security)

* [AI駆動型セキュリティ運用プラットフォーム](https://www.paloaltonetworks.jp/cortex)

* [Cloud Security](https://www.paloaltonetworks.jp/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.jp/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.jp/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.jp/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.jp/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.jp/prisma/cloud)

* [AI駆動型SOC](https://www.paloaltonetworks.jp/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.jp/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.jp/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.jp/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.jp/cortex/cortex-xpanse)

* [Unit 42マネージド ディテクション\&レスポンス](https://www.paloaltonetworks.jp/cortex/managed-detection-and-response)

* [マネージドXSIAM](https://www.paloaltonetworks.jp/cortex/managed-xsiam)

* [次世代のアイデンティティ セキュリティ](https://www.paloaltonetworks.jp/idira)

* [特権アクセス管理](https://www.paloaltonetworks.jp/idira/human/privileged-access-management)

* [アイデンティティ管理とアクセス管理](https://www.paloaltonetworks.jp/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.jp/idira/human/endpoint-privilege-manager)

* [アイデンティティ ガバナンス](https://www.paloaltonetworks.jp/idira/human/identity-governance)

* [従業員パスワード管理](https://www.paloaltonetworks.jp/idira/human/workforce-password-management)

* [エージェンティック アイデンティティ](https://www.paloaltonetworks.jp/idira/agentic)

* [シークレット管理](https://www.paloaltonetworks.jp/idira/machine/secrets-management)

* [統合型シークレット ガバナンス](https://www.paloaltonetworks.jp/idira/machine/unified-secrets-governance)

* [アプリケーションの認証情報配信](https://www.paloaltonetworks.jp/idira/machine/application-credentials-delivery)

* [ベンダーの特権アクセス](https://www.paloaltonetworks.jp/idira/human/vendor-privileged-access)

* [脅威インテリジェンス\&インシデント レスポンス サービス](https://www.paloaltonetworks.jp/unit42)

* [予防評価](https://www.paloaltonetworks.jp/unit42/assess)

* [インシデント レスポンス](https://www.paloaltonetworks.jp/unit42/respond)

* [セキュリティ戦略を変革](https://www.paloaltonetworks.jp/unit42/transform)

* [脅威インテリジェンスについて](https://www.paloaltonetworks.jp/unit42/threat-intelligence-partners)  
  会社名

* [パロアルトネットワークスについて](https://www.paloaltonetworks.jp/about-us)

* [採用情報](https://jobs.paloaltonetworks.com/en/)

* [お問合せ](https://www.paloaltonetworks.jp/company/contact-sales)

* [企業責任](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [お客様向け](https://www.paloaltonetworks.jp/customers)

* [IR](https://investors.paloaltonetworks.com/)

* [拠点](https://www.paloaltonetworks.com/about-us/locations)

* [ニュースルーム](https://www.paloaltonetworks.jp/company/newsroom)  
  人気のあるリンク

* [ブログ](https://www.paloaltonetworks.com/blog/?lang=ja)

* [コミュニティ](https://www.paloaltonetworks.com/communities)

* [コンテンツライブラリ](https://www.paloaltonetworks.jp/resources)

* [Cyberpedia](https://www.paloaltonetworks.jp/cyberpedia)

* [イベントセンター](https://events.paloaltonetworks.com/)

* [電子メール設定の管理](https://start.paloaltonetworks.com/preference-center)

* [製品A〜Z](https://www.paloaltonetworks.jp/products/products-a-z)

* [製品認証](https://www.paloaltonetworks.com/legal-notices/trust-center/compliance)

* [脆弱性の報告](https://www.paloaltonetworks.com/security-disclosure)

* [サイトマップ](https://www.paloaltonetworks.jp/sitemap)

* [テクニカル ドキュメント](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.jp/)

* [個人情報の販売および共有禁止](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [プライバシー](https://www.paloaltonetworks.jp/legal-notices/privacy)

* [トラスト センター](https://www.paloaltonetworks.jp/legal-notices/trust-center)

* [利用規約](https://www.paloaltonetworks.jp/legal-notices/terms-of-use)

* [ドキュメント](https://www.paloaltonetworks.jp/legal-notices)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![](https://www.paloaltonetworks.jp/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![](https://www.paloaltonetworks.jp/content/dam/pan/en_US/images/icons/podcast.svg)](https://unit42.paloaltonetworks.com/unit-42-threat-vector-podcast/)
* JP  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
