initial commit

This commit is contained in:
Desiree Beck
2019-08-01 13:56:04 -04:00
parent c10d9a020a
commit 2cca7af5ae
207 changed files with 3631 additions and 0 deletions
+28
View File
@@ -0,0 +1,28 @@
|||
|--|-----|
|**ID**|**M9007**|
# Discovery #
Behaviors that aim to gain knowledge about the system and internal network.
* **Account Discovery** [T1087](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/account-discover.md)
* **Analysis Tool Discovery** [M0013](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/analysis-tool-discover.md)
* **Application Discovery** [T1418](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/app-discover.md)
* **Application Window Discovery** [T1010](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/app-window-discover.md)
* **Device Type Discovery** [T1419](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/device-type-discover.md)
* **File and Directory Discovery** [T1083](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/file-and-directory-discover.md)
* **Local Network Configuration Discovery** [T1422](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/local-network-configuration-discover.md)
* **Network Sniffing** [T1040](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/network-sniff.md)
* **Network Service Scanning** [T1046](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/network-service-scan.md)
* **Peripheral Device Discovery** [T1120](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/peripheral-device-discover.md)
* **Process Discovery** [T1057](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/process-discover.md)
* **Query Registry** [T1012](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/query-registry.md)
* **Remote System Discovery** [T1018](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/remote-sys-discover.md)
* **Security Software Discovery** [T1063](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/security-sw-discover.md)
* **SMTP Connection Discovery** [M0014](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/smtp-connect-discover.md)
* **System Information Discovery** [T1082](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/system-info-discover.md)
* **System Network Configuration Discovery** [T1016](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/system-network-config-discover.md)
* **System Network Connections Discovery** [T1049](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/system-network-conn-discover.md)
* **System Owner/User Discovery** [T1033](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/system-owner-discover.md)
* **System Service Discovery** [T1007](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/system-service-discover.md)
* **System Time Discovery** [T1124](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/system-time-discover.md)
+12
View File
@@ -0,0 +1,12 @@
|||
|---------|------------------------|
|**ID**|**T1087**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[Account Discovery](https://attack.mitre.org/techniques/T1087)|
Account Discovery
=================
Malware may try to get names of local system or domain accounts.
See ATT&CK: [**Account Discovery**](https://attack.mitre.org/techniques/T1087).
+29
View File
@@ -0,0 +1,29 @@
|||
|---------|------------------------|
|**ID**|**M0013**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|None|
Analysis Tool Discovery
=======================
Malware can employ various means to detect whether analysis tools are present or running on the system on which it is executing.
Methods
-------
* **Process detection**: Malware can scan for the process name associated with common analysis tools:
* Debuggers: OllyDBG / ImmunityDebugger / WinDbg / IDA Pro
* SysInternals Suite Tools (Process Explorer / Process Monitor / Regmon / Filemon, TCPView, Autoruns)
* PCAP Utilities: Wireshark / Dumpcap
* Process Utilities: ProcessHacker / SysAnalyzer / HookExplorer / SysInspector
* PE Utilities: ImportREC / PETools / LordPE
* Sandboxes: Joe Sandbox, etc.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
References
----------
+12
View File
@@ -0,0 +1,12 @@
|||
|---------|------------------------|
|**ID**|**T1418**|
|**Objective(s)**| [Defense Evasion](https://github.com/MAECProject/malware-behaviors/tree/master/defense-evasion), [Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[Application Discovery](https://attack.mitre.org/techniques/T1418)|
Application Discovery
=====================
Malware may try to identify all applications installed on the device.
See ATT&CK: [**Application Discovery**](https://attack.mitre.org/techniques/T1418).
+12
View File
@@ -0,0 +1,12 @@
|||
|---------|------------------------|
|**ID**|**T1010**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[Application Window Discovery](https://attack.mitre.org/techniques/T1010)|
Application Window Discovery
============================
Malware may try to get a list of open application windows.
See ATT&CK: [**Application Window Discovery**](https://attack.mitre.org/techniques/T1010).
+12
View File
@@ -0,0 +1,12 @@
|||
|---------|------------------------|
|**ID**|**T1419**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[Device Type Discovery](https://attack.mitre.org/techniques/T1419)|
Device Type Discovery
=====================
Android malware may get device type information through the android.os.Build class.
See ATT&CK: [**Device Type Discovery**](https://attack.mitre.org/techniques/T1419).
+12
View File
@@ -0,0 +1,12 @@
|||
|---------|------------------------|
|**ID**|**T1083**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[File and Directory Discovery](https://attack.mitre.org/techniques/T1083)|
File and Directory Discovery
============================
Malware may enumerate files and/or directories.
See ATT&CK: [**File and Directory Discovery**](https://attack.mitre.org/techniques/T1083).
@@ -0,0 +1,12 @@
|||
|---------|------------------------|
|**ID**|**T1422**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[Local Network Configuration Discovery](https://attack.mitre.org/techniques/T1422)|
Local Network Configuration Discovery
=====================================
Android malware may try to get details of on-board network interfaces through the java.net.NetworkInterface class.
See ATT&CK: [**Local Network Configuration Discovery**](https://attack.mitre.org/techniques/T1422).
+12
View File
@@ -0,0 +1,12 @@
|||
|---------|------------------------|
|**ID**|**T1046**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[Network Service Scanning](https://attack.mitre.org/techniques/T1046)|
Network Service Scanning
========================
Malware may try to a listing of services running on remotes hosts.
See ATT&CK: [**Network Service Scanning**](https://attack.mitre.org/techniques/T1046).
+11
View File
@@ -0,0 +1,11 @@
|||
|---------|------------------------|
|**ID**|**T1040**|
|**Objective(s)**|[Collection](https://github.com/MAECProject/malware-behaviors/tree/master/credential-access), [Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[Network Sniffing](https://attack.mitre.org/techniques/T1040/)|
Network Sniffing
================
Malware captures information sent over a wired or wireless connection.
**See ATT&CK:** [**Network Sniffing**](https://attack.mitre.org/techniques/T1040/).
+12
View File
@@ -0,0 +1,12 @@
|||
|---------|------------------------|
|**ID**|**T1120**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[Peripheral Device Discovery](https://attack.mitre.org/techniques/T1120)|
Peripheral Device Discovery
===========================
Malware may try to get information about peripheral devices.
See ATT&CK: [**Peripheral Device Discovery**](https://attack.mitre.org/techniques/T1120).
+12
View File
@@ -0,0 +1,12 @@
|||
|---------|------------------------|
|**ID**|**T1057**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[Process Discovery](https://attack.mitre.org/techniques/T1057)|
Process Discovery
=================
Malware may try to get information about running processes.
See ATT&CK: [**Process Discovery**](https://attack.mitre.org/techniques/T1057).
+12
View File
@@ -0,0 +1,12 @@
|||
|---------|------------------------|
|**ID**|**T1012**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[Query Registry](https://attack.mitre.org/techniques/T1012)|
Query Registry
===============
Malware may gather information from the Windows registry.
See ATT&CK: [**Query Registry**](https://attack.mitre.org/techniques/T1012).
+12
View File
@@ -0,0 +1,12 @@
|||
|---------|------------------------|
|**ID**|**T1018**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[Remote System Discovery](https://attack.mitre.org/techniques/T1018)|
Remote System Discovery
=======================
Malware may try to get a list of network-accessible systems (by IP address or hostname).
See ATT&CK: [**Remote System Discovery**](https://attack.mitre.org/techniques/T1018).
+12
View File
@@ -0,0 +1,12 @@
|||
|---------|------------------------|
|**ID**|**T1063**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[Security Software Discovery](https://attack.mitre.org/techniques/T1063)|
Security Software Discovery
===========================
Malware may try to a listing of security software or defensive tools installed on the system.
See ATT&CK: [**Security Software Discovery**](https://attack.mitre.org/techniques/T1063).
+19
View File
@@ -0,0 +1,19 @@
|||
|---------|------------------------|
|**ID**|**M0014**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|None|
SMTP Connection Discovery
=========================
Malware may test whether an outgoing SMTP connection can be made from the system on which the malware instance is executing to some SMTP server, by sending a test SMTP transaction.
Malware Examples
----------------
|Name|Date|Description|
|-----------------------------|--------|-----------------------------|
References
----------
+11
View File
@@ -0,0 +1,11 @@
|||
|---------|------------------------|
|**ID**|**T1082**|
|**Objective(s)**| [Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/defense-evasion)|
|**Related ATT&CK Technique(s)**|[System Information Discovery](https://attack.mitre.org/techniques/T1082)
System Information Discovery
============================
Malware may attempt to get detailed information about the system.
See ATT&CK: [**System Information Discovery**](https://attack.mitre.org/techniques/T1082).
@@ -0,0 +1,12 @@
|||
|---------|------------------------|
|**ID**|**T1016**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[System Network Configuration Discovery](https://attack.mitre.org/techniques/T1016)|
System Network Configuration Discovery
======================================
Malware may try to find details about the system's network configuration.
See ATT&CK: [**System Network Configuration Discovery**](https://attack.mitre.org/techniques/T1016).
+12
View File
@@ -0,0 +1,12 @@
|||
|---------|------------------------|
|**ID**|**T1049**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[System Network Connections Discovery](https://attack.mitre.org/techniques/T1049)|
System Network Connections Discovery
====================================
Malware may try to get a listing of network connections to/from the compromised system.
See ATT&CK: [**System Network Connections Discovery**](https://attack.mitre.org/techniques/T1049).
+12
View File
@@ -0,0 +1,12 @@
|||
|---------|------------------------|
|**ID**|**T1033**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[System Owner/User Discovery](https://attack.mitre.org/techniques/T1033)|
System Owner/User Discovery
===========================
Malware may try to identify the users of the system.
See ATT&CK: [**System Owner/User Discovery**](https://attack.mitre.org/techniques/T1033).
+12
View File
@@ -0,0 +1,12 @@
|||
|---------|------------------------|
|**ID**|**T1007**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[System Service Discovery](https://attack.mitre.org/techniques/T1007)|
System Service Discovery
========================
Malware may try to get information about registered services.
See ATT&CK: [**System Service Discovery**](https://attack.mitre.org/techniques/T1007).
+12
View File
@@ -0,0 +1,12 @@
|||
|---------|------------------------|
|**ID**|**T1087**|
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|**Related ATT&CK Technique(s)**|[System Time Discovery](https://attack.mitre.org/techniques/T1124)|
System Time Discovery
=====================
Malware may try to get the system time or time zone for a system.
See ATT&CK: [**System Time Discovery**](https://attack.mitre.org/techniques/T1124).