move and replace MBCProject/mbc-markdown with contents from MBCProject/mbc-beta

This commit is contained in:
Emmanuelle Vargas-Gonzalez
2020-08-14 14:37:45 -04:00
parent 3559ac6c87
commit 2207d845ae
283 changed files with 1764 additions and 2839 deletions
+5 -25
View File
@@ -1,31 +1,11 @@
|||
|--|-----|
|**ID**|**M9007**|
|**ID**|**OB0007**|
# Discovery #
Behaviors that aim to gain knowledge about the system and internal network.
* **Account Discovery** [T1087](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/account-discover.md)
* **Analysis Tool Discovery** [M0013](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/analysis-tool-discover.md)
* **Application Window Discovery** [T1010](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/app-window-discover.md)
* **Device Type Discovery** [T1419](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/device-type-discover.md)
* **File and Directory Discovery** [T1083](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/file-and-directory-discover.md)
* **Domain Trust Discovery** [T1482](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/domain-trust-discover.md)
* **Local Network Configuration Discovery** [T1422](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/local-network-configuration-discover.md)
* **Network Sniffing** [T1040](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/network-sniff.md)
* **Network Service Scanning** [T1046](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/network-service-scan.md)
* **Network Share Discovery** [T1135](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/network-share-discover.md)
* **Peripheral Device Discovery** [T1120](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/peripheral-device-discover.md)
* **Process Discovery** [T1057](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/process-discover.md)
* **Query Registry** [T1012](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/query-registry.md)
* **Remote System Discovery** [T1018](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/remote-sys-discover.md)
* **Security Software Discovery** [T1063](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/security-sw-discover.md)
* **Self Discovery** [M0038](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/self-discover.md)
* **SMTP Connection Discovery** [M0014](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/smtp-connect-discover.md)
* **Software Discovery** [T1518](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/sw-discover.md)
* **System Information Discovery** [E1082](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/system-info-discover.md)
* **System Network Configuration Discovery** [T1016](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/system-network-config-discover.md)
* **System Network Connections Discovery** [T1049](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/system-network-conn-discover.md)
* **System Owner/User Discovery** [T1033](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/system-owner-discover.md)
* **System Service Discovery** [T1007](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/system-service-discover.md)
* **System Time Discovery** [T1124](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/system-time-discover.md)
* **Analysis Tool Discovery** [B0013](https://github.com/MBCProject/mbc-beta/blob/master/discovery/analysis-tool-discover.md)
* **Self Discovery** [B0038](https://github.com/MBCProject/mbc-beta/blob/master/discovery/self-discover.md)
* **SMTP Connection Discovery** [B0014](https://github.com/MBCProject/mbc-beta/blob/master/discovery/smtp-connect-discover.md)
* **System Information Discovery** [E1082](https://github.com/MBCProject/mbc-beta/blob/master/discovery/system-info-discover.md)
-18
View File
@@ -1,18 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1087**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[Account Discovery](https://attack.mitre.org/techniques/T1087)|
Account Discovery
=================
Malware may try to get names of local system or domain accounts.
See ATT&CK: [**Account Discovery**](https://attack.mitre.org/techniques/T1087).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
+19 -16
View File
@@ -1,29 +1,32 @@
|||
|---------|------------------------|
|**ID**|**M0013**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**ID**|**B0013**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-beta/tree/master/discovery)|
|**Related ATT&CK Technique**|None|
Analysis Tool Discovery
=======================
Malware can employ various means to detect whether analysis tools are present or running on the system on which it is executing. Note that analysis tools are used to *analyze* malware whereas security software (see [Security Software Discovery](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/security-sw-discover.md)) aims to *detect/mitigate* malware on a system or network.
Malware can employ various means to detect whether analysis tools are present or running on the system on which it is executing. Note that analysis tools are used to *analyze* malware whereas security software (see [Software Discovery: Security Software Discovery](https://attack.mitre.org/techniques/T1518/001/)) aims to *detect/mitigate* malware on a system or network.
This behavior corresponds to simple, general discovery of analysis tools. Behaviors to find specific analysis tools (e.g., debuggers or disassemblers) are defined under the [Anti-Behavioral Analysis](https://github.com/MBCProject/mbc-beta/tree/master/anti-behavioral-analysis) objective.
Methods
-------
* **Process detection**: Malware can scan for the process name associated with common analysis tools:
* Debuggers: OllyDBG / ImmunityDebugger / WinDbg / IDA Pro
* SysInternals Suite Tools (Process Explorer / Process Monitor / Regmon / Filemon, TCPView, Autoruns)
* PCAP Utilities: Wireshark / Dumpcap
* Process Utilities: ProcessHacker / SysAnalyzer / HookExplorer / SysInspector
* PE Utilities: ImportREC / PETools / LordPE
* Sandboxes: Joe Sandbox, etc.
Malware Examples
----------------
|Name|Date|Description|
|ID|Name|Description|
|-----------------------------|--------|-----------------------------|
|B0013.001|**Process detection**|Malware can scan for the process name associated with common analysis tools.|
| | | | |
|----------|-----------------------------|--------|-----------------------------|
| |B0013.002|*Debuggers*|OllyDBG / ImmunityDebugger / WinDbg / IDA Pro|
| |B0013.003|*SysInternals Suite Tools*|Process Explorer / Process Monitor / Regmon / Filemon, TCPView, Autoruns|
| |B0013.004|*PCAP Utilities*|Wireshark / Dumpcap|
| |B0013.005|*Process Utilities*|ProcessHacker / SysAnalyzer / HookExplorer / SysInspector|
| |B0013.006|*PE Utilities*|ImportREC / PETools / LordPE|
| |B0013.007|*Sandboxes*|Joe Sandbox, etc.|
References
----------
| | | |
|-----------------------------|--------|-----------------------------|
|B0013.008|**Known File Location**|Malware may detect an analysis tool by the presence of a file in a known location.|
|B0013.009|**Known Window**|Malware may detect an analysis tool via the presence of a known window.|
-22
View File
@@ -1,22 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1010**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[Application Window Discovery](https://attack.mitre.org/techniques/T1010)|
Application Window Discovery
============================
Malware may try to get a list of open application windows.
See ATT&CK: [**Application Window Discovery**](https://attack.mitre.org/techniques/T1010).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
|[**Poison-Ivy**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/poison-ivy.md)|2005|After the Poison-Ivy server is running on the target machine, the attacker can use a Windows GUI client to control the target computer. [[1]](#1)|
References
----------
<a name="1">[1]</a> https://www.cyber.nj.gov/threat-profiles/trojan-variants/poison-ivy
-12
View File
@@ -1,12 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1419**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[Device Type Discovery](https://attack.mitre.org/techniques/T1419)|
Device Type Discovery
=====================
Android malware may get device type information through the android.os.Build class.
See ATT&CK: [**Device Type Discovery**](https://attack.mitre.org/techniques/T1419).
-18
View File
@@ -1,18 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1482**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[Domain Trust Discovery](https://attack.mitre.org/techniques/T1482)|
Domain Trust Discovery
======================
Malware may attempt to gather information on domain trust relationships that might be used to identify lateral movement opportunities.
See ATT&CK: [**Domain Trust Discovery**](https://attack.mitre.org/techniques/T1482).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
-18
View File
@@ -1,18 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1083**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[File and Directory Discovery](https://attack.mitre.org/techniques/T1083)|
File and Directory Discovery
============================
Malware may enumerate files and/or directories.
See ATT&CK: [**File and Directory Discovery**](https://attack.mitre.org/techniques/T1083).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
@@ -1,12 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1422**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[Local Network Configuration Discovery](https://attack.mitre.org/techniques/T1422)|
Local Network Configuration Discovery
=====================================
Android malware may try to get details of on-board network interfaces through the java.net.NetworkInterface class.
See ATT&CK: [**Local Network Configuration Discovery**](https://attack.mitre.org/techniques/T1422).
-12
View File
@@ -1,12 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1046**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[Network Service Scanning](https://attack.mitre.org/techniques/T1046)|
Network Service Scanning
========================
Malware may try to a listing of services running on remotes hosts.
See ATT&CK: [**Network Service Scanning**](https://attack.mitre.org/techniques/T1046).
-12
View File
@@ -1,12 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1135**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[Network Share Discovery](https://attack.mitre.org/techniques/T1135)|
Network Share Discovery
=======================
Malware may discover and/or scan shared network drives.
See ATT&CK: [**Network Share Discovery**](https://attack.mitre.org/techniques/T1135).
-11
View File
@@ -1,11 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1040**|
|**Objective(s)**|[Collection](https://github.com/MBCProject/mbc-markdown/tree/master/credential-access), [Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[Network Sniffing](https://attack.mitre.org/techniques/T1040/)|
Network Sniffing
================
Malware captures information sent over a wired or wireless connection.
**See ATT&CK:** [**Network Sniffing**](https://attack.mitre.org/techniques/T1040/).
-12
View File
@@ -1,12 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1120**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[Peripheral Device Discovery](https://attack.mitre.org/techniques/T1120)|
Peripheral Device Discovery
===========================
Malware may try to get information about peripheral devices.
See ATT&CK: [**Peripheral Device Discovery**](https://attack.mitre.org/techniques/T1120).
-12
View File
@@ -1,12 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1057**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[Process Discovery](https://attack.mitre.org/techniques/T1057)|
Process Discovery
=================
Malware may try to get information about running processes.
See ATT&CK: [**Process Discovery**](https://attack.mitre.org/techniques/T1057).
-12
View File
@@ -1,12 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1012**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[Query Registry](https://attack.mitre.org/techniques/T1012)|
Query Registry
===============
Malware may gather information from the Windows registry.
See ATT&CK: [**Query Registry**](https://attack.mitre.org/techniques/T1012).
-12
View File
@@ -1,12 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1018**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[Remote System Discovery](https://attack.mitre.org/techniques/T1018)|
Remote System Discovery
=======================
Malware may try to get a list of network-accessible systems (by IP address or hostname).
See ATT&CK: [**Remote System Discovery**](https://attack.mitre.org/techniques/T1018).
-12
View File
@@ -1,12 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1063**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[Security Software Discovery](https://attack.mitre.org/techniques/T1063)|
Security Software Discovery
===========================
Malware may try to get a listing of security software or defensive tools installed on the system. Note that security software aims to *detect/mitigate* malware on a system whereas analysis tools (see [Analysis Tool Discovery](https://github.com/MBCProject/mbc-markdown/blob/master/discovery/analysis-tool-discover.md)) are used to *analyze* malware.
See ATT&CK: [**Security Software Discovery**](https://attack.mitre.org/techniques/T1063).
+2 -2
View File
@@ -1,7 +1,7 @@
|||
|---------|------------------------|
|**ID**|**M0038**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**ID**|**B0038**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-beta/tree/master/discovery)|
|**Related ATT&CK Technique**|None|
+2 -10
View File
@@ -1,7 +1,7 @@
|||
|---------|------------------------|
|**ID**|**M0014**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**ID**|**B0014**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-beta/tree/master/discovery)|
|**Related ATT&CK Technique**|None|
@@ -9,11 +9,3 @@ SMTP Connection Discovery
=========================
Malware may test whether an outgoing SMTP connection can be made from the system on which the malware instance is executing to some SMTP server, by sending a test SMTP transaction.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
References
----------
-12
View File
@@ -1,12 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1518**|
|**Objective(s)**| [Defense Evasion](https://github.com/MBCProject/mbc-markdown/tree/master/defense-evasion), [Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[Software Discovery](https://attack.mitre.org/techniques/T1518), [Application Discovery](https://attack.mitre.org/techniques/T1418)|
Software Discovery
==================
Malware may try to identify all software and applications installed on the device.
See ATT&CK: [**Software Discovery**](https://attack.mitre.org/techniques/T1518).
+6 -3
View File
@@ -1,7 +1,7 @@
|||
|---------|------------------------|
|**ID**|**E1082**|
|**Objective(s)**| [Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Objective(s)**| [Discovery](https://github.com/MBCProject/mbc-beta/tree/master/discovery)|
|**Related ATT&CK Technique**|[System Information Discovery](https://attack.mitre.org/techniques/T1082)
System Information Discovery
@@ -12,10 +12,13 @@ See ATT&CK: [**System Information Discovery**](https://attack.mitre.org/techniqu
Methods
-------
* **Generate Windows Exception**: malware may trigger an exception as a way of gathering system details.
|ID|Name|Description|
|-----------------------------|--------|-----------------------------|
|E1082.m01|**Generate Windows Exception**|Malware may trigger an exception as a way of gathering system details.|
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|[**TrickBot**](https://github.com/MBCProject/mbc-beta/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
|[**WebCobra**](https://github.com/MBCProject/mbc-beta/blob/master/xample-malware/webcobra.md)|2018|Learns about the system so it can drop compatible miner software.|
@@ -1,18 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1016**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[System Network Configuration Discovery](https://attack.mitre.org/techniques/T1016)|
System Network Configuration Discovery
======================================
Malware may try to find details about the system's network configuration.
See ATT&CK: [**System Network Configuration Discovery**](https://attack.mitre.org/techniques/T1016).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
-12
View File
@@ -1,12 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1049**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[System Network Connections Discovery](https://attack.mitre.org/techniques/T1049)|
System Network Connections Discovery
====================================
Malware may try to get a listing of network connections to/from the compromised system.
See ATT&CK: [**System Network Connections Discovery**](https://attack.mitre.org/techniques/T1049).
-12
View File
@@ -1,12 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1033**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[System Owner/User Discovery](https://attack.mitre.org/techniques/T1033)|
System Owner/User Discovery
===========================
Malware may try to identify the users of the system.
See ATT&CK: [**System Owner/User Discovery**](https://attack.mitre.org/techniques/T1033).
-18
View File
@@ -1,18 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1007**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[System Service Discovery](https://attack.mitre.org/techniques/T1007)|
System Service Discovery
========================
Malware may try to get information about registered services.
See ATT&CK: [**System Service Discovery**](https://attack.mitre.org/techniques/T1007).
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|-----------|-----------------------------|
|[**TrickBot**](https://github.com/MBCProject/mbc-markdown/tree/master/xample-malware/trickbot.md)|2016|Trojan spyware program that has mainly been used for targeting banking sites.|
-12
View File
@@ -1,12 +0,0 @@
|||
|---------|------------------------|
|**ID**|**T1087**|
|**Objective(s)**|[Discovery](https://github.com/MBCProject/mbc-markdown/tree/master/discovery)|
|**Related ATT&CK Technique**|[System Time Discovery](https://attack.mitre.org/techniques/T1124)|
System Time Discovery
=====================
Malware may try to get the system time or time zone for a system.
See ATT&CK: [**System Time Discovery**](https://attack.mitre.org/techniques/T1124).