mirror of
https://github.com/MBCProject/mbc-markdown
synced 2026-06-08 11:36:36 +00:00
initial commit
This commit is contained in:
@@ -0,0 +1,28 @@
|
||||
|||
|
||||
|--|-----|
|
||||
|**ID**|**M9007**|
|
||||
|
||||
# Discovery #
|
||||
Behaviors that aim to gain knowledge about the system and internal network.
|
||||
|
||||
* **Account Discovery** [T1087](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/account-discover.md)
|
||||
* **Analysis Tool Discovery** [M0013](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/analysis-tool-discover.md)
|
||||
* **Application Discovery** [T1418](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/app-discover.md)
|
||||
* **Application Window Discovery** [T1010](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/app-window-discover.md)
|
||||
* **Device Type Discovery** [T1419](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/device-type-discover.md)
|
||||
* **File and Directory Discovery** [T1083](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/file-and-directory-discover.md)
|
||||
* **Local Network Configuration Discovery** [T1422](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/local-network-configuration-discover.md)
|
||||
* **Network Sniffing** [T1040](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/network-sniff.md)
|
||||
* **Network Service Scanning** [T1046](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/network-service-scan.md)
|
||||
* **Peripheral Device Discovery** [T1120](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/peripheral-device-discover.md)
|
||||
* **Process Discovery** [T1057](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/process-discover.md)
|
||||
* **Query Registry** [T1012](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/query-registry.md)
|
||||
* **Remote System Discovery** [T1018](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/remote-sys-discover.md)
|
||||
* **Security Software Discovery** [T1063](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/security-sw-discover.md)
|
||||
* **SMTP Connection Discovery** [M0014](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/smtp-connect-discover.md)
|
||||
* **System Information Discovery** [T1082](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/system-info-discover.md)
|
||||
* **System Network Configuration Discovery** [T1016](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/system-network-config-discover.md)
|
||||
* **System Network Connections Discovery** [T1049](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/system-network-conn-discover.md)
|
||||
* **System Owner/User Discovery** [T1033](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/system-owner-discover.md)
|
||||
* **System Service Discovery** [T1007](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/system-service-discover.md)
|
||||
* **System Time Discovery** [T1124](https://github.com/MAECProject/malware-behaviors/blob/master/discovery/system-time-discover.md)
|
||||
@@ -0,0 +1,12 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1087**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[Account Discovery](https://attack.mitre.org/techniques/T1087)|
|
||||
|
||||
|
||||
Account Discovery
|
||||
=================
|
||||
Malware may try to get names of local system or domain accounts.
|
||||
|
||||
See ATT&CK: [**Account Discovery**](https://attack.mitre.org/techniques/T1087).
|
||||
@@ -0,0 +1,29 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0013**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|None|
|
||||
|
||||
|
||||
Analysis Tool Discovery
|
||||
=======================
|
||||
Malware can employ various means to detect whether analysis tools are present or running on the system on which it is executing.
|
||||
|
||||
Methods
|
||||
-------
|
||||
* **Process detection**: Malware can scan for the process name associated with common analysis tools:
|
||||
* Debuggers: OllyDBG / ImmunityDebugger / WinDbg / IDA Pro
|
||||
* SysInternals Suite Tools (Process Explorer / Process Monitor / Regmon / Filemon, TCPView, Autoruns)
|
||||
* PCAP Utilities: Wireshark / Dumpcap
|
||||
* Process Utilities: ProcessHacker / SysAnalyzer / HookExplorer / SysInspector
|
||||
* PE Utilities: ImportREC / PETools / LordPE
|
||||
* Sandboxes: Joe Sandbox, etc.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|--------|-----------------------------|
|
||||
|
||||
|
||||
References
|
||||
----------
|
||||
@@ -0,0 +1,12 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1418**|
|
||||
|**Objective(s)**| [Defense Evasion](https://github.com/MAECProject/malware-behaviors/tree/master/defense-evasion), [Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[Application Discovery](https://attack.mitre.org/techniques/T1418)|
|
||||
|
||||
|
||||
Application Discovery
|
||||
=====================
|
||||
Malware may try to identify all applications installed on the device.
|
||||
|
||||
See ATT&CK: [**Application Discovery**](https://attack.mitre.org/techniques/T1418).
|
||||
@@ -0,0 +1,12 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1010**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[Application Window Discovery](https://attack.mitre.org/techniques/T1010)|
|
||||
|
||||
|
||||
Application Window Discovery
|
||||
============================
|
||||
Malware may try to get a list of open application windows.
|
||||
|
||||
See ATT&CK: [**Application Window Discovery**](https://attack.mitre.org/techniques/T1010).
|
||||
@@ -0,0 +1,12 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1419**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[Device Type Discovery](https://attack.mitre.org/techniques/T1419)|
|
||||
|
||||
|
||||
Device Type Discovery
|
||||
=====================
|
||||
Android malware may get device type information through the android.os.Build class.
|
||||
|
||||
See ATT&CK: [**Device Type Discovery**](https://attack.mitre.org/techniques/T1419).
|
||||
@@ -0,0 +1,12 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1083**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[File and Directory Discovery](https://attack.mitre.org/techniques/T1083)|
|
||||
|
||||
|
||||
File and Directory Discovery
|
||||
============================
|
||||
Malware may enumerate files and/or directories.
|
||||
|
||||
See ATT&CK: [**File and Directory Discovery**](https://attack.mitre.org/techniques/T1083).
|
||||
@@ -0,0 +1,12 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1422**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[Local Network Configuration Discovery](https://attack.mitre.org/techniques/T1422)|
|
||||
|
||||
|
||||
Local Network Configuration Discovery
|
||||
=====================================
|
||||
Android malware may try to get details of on-board network interfaces through the java.net.NetworkInterface class.
|
||||
|
||||
See ATT&CK: [**Local Network Configuration Discovery**](https://attack.mitre.org/techniques/T1422).
|
||||
@@ -0,0 +1,12 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1046**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[Network Service Scanning](https://attack.mitre.org/techniques/T1046)|
|
||||
|
||||
|
||||
Network Service Scanning
|
||||
========================
|
||||
Malware may try to a listing of services running on remotes hosts.
|
||||
|
||||
See ATT&CK: [**Network Service Scanning**](https://attack.mitre.org/techniques/T1046).
|
||||
@@ -0,0 +1,11 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1040**|
|
||||
|**Objective(s)**|[Collection](https://github.com/MAECProject/malware-behaviors/tree/master/credential-access), [Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[Network Sniffing](https://attack.mitre.org/techniques/T1040/)|
|
||||
|
||||
Network Sniffing
|
||||
================
|
||||
Malware captures information sent over a wired or wireless connection.
|
||||
|
||||
**See ATT&CK:** [**Network Sniffing**](https://attack.mitre.org/techniques/T1040/).
|
||||
@@ -0,0 +1,12 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1120**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[Peripheral Device Discovery](https://attack.mitre.org/techniques/T1120)|
|
||||
|
||||
|
||||
Peripheral Device Discovery
|
||||
===========================
|
||||
Malware may try to get information about peripheral devices.
|
||||
|
||||
See ATT&CK: [**Peripheral Device Discovery**](https://attack.mitre.org/techniques/T1120).
|
||||
@@ -0,0 +1,12 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1057**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[Process Discovery](https://attack.mitre.org/techniques/T1057)|
|
||||
|
||||
|
||||
Process Discovery
|
||||
=================
|
||||
Malware may try to get information about running processes.
|
||||
|
||||
See ATT&CK: [**Process Discovery**](https://attack.mitre.org/techniques/T1057).
|
||||
@@ -0,0 +1,12 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1012**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[Query Registry](https://attack.mitre.org/techniques/T1012)|
|
||||
|
||||
|
||||
Query Registry
|
||||
===============
|
||||
Malware may gather information from the Windows registry.
|
||||
|
||||
See ATT&CK: [**Query Registry**](https://attack.mitre.org/techniques/T1012).
|
||||
@@ -0,0 +1,12 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1018**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[Remote System Discovery](https://attack.mitre.org/techniques/T1018)|
|
||||
|
||||
|
||||
Remote System Discovery
|
||||
=======================
|
||||
Malware may try to get a list of network-accessible systems (by IP address or hostname).
|
||||
|
||||
See ATT&CK: [**Remote System Discovery**](https://attack.mitre.org/techniques/T1018).
|
||||
@@ -0,0 +1,12 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1063**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[Security Software Discovery](https://attack.mitre.org/techniques/T1063)|
|
||||
|
||||
|
||||
Security Software Discovery
|
||||
===========================
|
||||
Malware may try to a listing of security software or defensive tools installed on the system.
|
||||
|
||||
See ATT&CK: [**Security Software Discovery**](https://attack.mitre.org/techniques/T1063).
|
||||
@@ -0,0 +1,19 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**M0014**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|None|
|
||||
|
||||
|
||||
SMTP Connection Discovery
|
||||
=========================
|
||||
Malware may test whether an outgoing SMTP connection can be made from the system on which the malware instance is executing to some SMTP server, by sending a test SMTP transaction.
|
||||
|
||||
Malware Examples
|
||||
----------------
|
||||
|Name|Date|Description|
|
||||
|-----------------------------|--------|-----------------------------|
|
||||
|
||||
|
||||
References
|
||||
----------
|
||||
@@ -0,0 +1,11 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1082**|
|
||||
|**Objective(s)**| [Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/defense-evasion)|
|
||||
|**Related ATT&CK Technique(s)**|[System Information Discovery](https://attack.mitre.org/techniques/T1082)
|
||||
|
||||
System Information Discovery
|
||||
============================
|
||||
Malware may attempt to get detailed information about the system.
|
||||
|
||||
See ATT&CK: [**System Information Discovery**](https://attack.mitre.org/techniques/T1082).
|
||||
@@ -0,0 +1,12 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1016**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[System Network Configuration Discovery](https://attack.mitre.org/techniques/T1016)|
|
||||
|
||||
|
||||
System Network Configuration Discovery
|
||||
======================================
|
||||
Malware may try to find details about the system's network configuration.
|
||||
|
||||
See ATT&CK: [**System Network Configuration Discovery**](https://attack.mitre.org/techniques/T1016).
|
||||
@@ -0,0 +1,12 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1049**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[System Network Connections Discovery](https://attack.mitre.org/techniques/T1049)|
|
||||
|
||||
|
||||
System Network Connections Discovery
|
||||
====================================
|
||||
Malware may try to get a listing of network connections to/from the compromised system.
|
||||
|
||||
See ATT&CK: [**System Network Connections Discovery**](https://attack.mitre.org/techniques/T1049).
|
||||
@@ -0,0 +1,12 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1033**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[System Owner/User Discovery](https://attack.mitre.org/techniques/T1033)|
|
||||
|
||||
|
||||
System Owner/User Discovery
|
||||
===========================
|
||||
Malware may try to identify the users of the system.
|
||||
|
||||
See ATT&CK: [**System Owner/User Discovery**](https://attack.mitre.org/techniques/T1033).
|
||||
@@ -0,0 +1,12 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1007**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[System Service Discovery](https://attack.mitre.org/techniques/T1007)|
|
||||
|
||||
|
||||
System Service Discovery
|
||||
========================
|
||||
Malware may try to get information about registered services.
|
||||
|
||||
See ATT&CK: [**System Service Discovery**](https://attack.mitre.org/techniques/T1007).
|
||||
@@ -0,0 +1,12 @@
|
||||
|||
|
||||
|---------|------------------------|
|
||||
|**ID**|**T1087**|
|
||||
|**Objective(s)**|[Discovery](https://github.com/MAECProject/malware-behaviors/tree/master/discovery)|
|
||||
|**Related ATT&CK Technique(s)**|[System Time Discovery](https://attack.mitre.org/techniques/T1124)|
|
||||
|
||||
|
||||
System Time Discovery
|
||||
=====================
|
||||
Malware may try to get the system time or time zone for a system.
|
||||
|
||||
See ATT&CK: [**System Time Discovery**](https://attack.mitre.org/techniques/T1124).
|
||||
Reference in New Issue
Block a user