couple of things in this commit:

- Added TrickBot and Poison-Ivy as Malware Examples to behaviors
- Consistency in the tables (make them bold, add internal reference if available and typos)
This commit is contained in:
Emmanuelle Vargas-Gonzalez
2019-11-08 18:38:27 -05:00
parent 4ca3884b48
commit 0ebd75beb5
57 changed files with 330 additions and 75 deletions
+7 -1
View File
@@ -9,4 +9,10 @@ Account Discovery
=================
Malware may try to get names of local system or domain accounts.
See ATT&CK: [**Account Discovery**](https://attack.mitre.org/techniques/T1087).
See ATT&CK: [**Account Discovery**](https://attack.mitre.org/techniques/T1087).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
+11 -1
View File
@@ -9,4 +9,14 @@ Application Window Discovery
============================
Malware may try to get a list of open application windows.
See ATT&CK: [**Application Window Discovery**](https://attack.mitre.org/techniques/T1010).
See ATT&CK: [**Application Window Discovery**](https://attack.mitre.org/techniques/T1010).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
|[**Poison-Ivy**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
References
----------
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
+7 -1
View File
@@ -9,4 +9,10 @@ Domain Trust Discovery
======================
Malware may attempt to gather information on domain trust relationships that might be used to identify lateral movement opportunities.
See ATT&CK: [**Domain Trust Discovery**](https://attack.mitre.org/techniques/T1482).
See ATT&CK: [**Domain Trust Discovery**](https://attack.mitre.org/techniques/T1482).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
+7 -1
View File
@@ -9,4 +9,10 @@ File and Directory Discovery
============================
Malware may enumerate files and/or directories.
See ATT&CK: [**File and Directory Discovery**](https://attack.mitre.org/techniques/T1083).
See ATT&CK: [**File and Directory Discovery**](https://attack.mitre.org/techniques/T1083).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
+7 -1
View File
@@ -8,4 +8,10 @@ System Information Discovery
============================
Malware may attempt to get detailed information about the system.
See ATT&CK: [**System Information Discovery**](https://attack.mitre.org/techniques/T1082).
See ATT&CK: [**System Information Discovery**](https://attack.mitre.org/techniques/T1082).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
+7 -1
View File
@@ -9,4 +9,10 @@ System Network Configuration Discovery
======================================
Malware may try to find details about the system's network configuration.
See ATT&CK: [**System Network Configuration Discovery**](https://attack.mitre.org/techniques/T1016).
See ATT&CK: [**System Network Configuration Discovery**](https://attack.mitre.org/techniques/T1016).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
+7 -1
View File
@@ -9,4 +9,10 @@ System Service Discovery
========================
Malware may try to get information about registered services.
See ATT&CK: [**System Service Discovery**](https://attack.mitre.org/techniques/T1007).
See ATT&CK: [**System Service Discovery**](https://attack.mitre.org/techniques/T1007).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|