initial commit

This commit is contained in:
Desiree Beck
2019-08-01 13:56:04 -04:00
parent c10d9a020a
commit 2cca7af5ae
207 changed files with 3631 additions and 0 deletions
+20
View File
@@ -0,0 +1,20 @@
|||
|--|-----|
|**ID**|**M9013**|
# Privilege Escalation #
Behaviors that aim to obtain a higher level of permission.
* **Application Shimming** [T1138](https://github.com/MAECProject/malware-behaviors/blob/master/privilege-escalation/app-shimming.md)
* **Bypass User Account Control** [T1088](https://github.com/MAECProject/malware-behaviors/blob/master/defense-evasion/bypass-user-acct-cntl.md)
* **DLL Search Order Hijacking** [T1038](https://github.com/MAECProject/malware-behaviors/blob/master/privilege-escalation/dll-search-order-hijack.md)
* **Exploitation for Privilege Escalation** [T1068](https://github.com/MAECProject/malware-behaviors/blob/master/privilege-escalation/exploit-priv-escalate.md)
* **File System Permissions Weakness** [T1044](https://github.com/MAECProject/malware-behaviors/blob/master/privilege-escalation/file-system-perm-weakness.md)
* **Hooking** [E1179](https://github.com/MAECProject/malware-behaviors/blob/master/credential-access/hooking.md)
* **Image File Execution Options Injection** [T1183](https://github.com/MAECProject/malware-behaviors/blob/master/defense-evasion/image-file-exe-opt-inj.md)
* **Launch Daemon** [T1160](https://github.com/MAECProject/malware-behaviors/blob/master/privilege-escalation/launch-daemon.md)
* **New Service** [T1050](https://github.com/MAECProject/malware-behaviors/blob/master/persistence/new-service.md)
* **Process Injection** [T1055](https://github.com/MAECProject/malware-behaviors/blob/master/defense-evasion/process-inject.md)
* **Scheduled Task** [T1053](https://github.com/MAECProject/malware-behaviors/blob/master/execution/scheduled-task.md)
* **Setuid and Setgid** [T1166](https://github.com/MAECProject/malware-behaviors/blob/master/privilege-escalation/setuid-setgid.md)
* **Sudo** [T1169](https://github.com/MAECProject/malware-behaviors/blob/master/privilege-escalation/sudo.md)
+11
View File
@@ -0,0 +1,11 @@
|||
|---------|------------------------|
|**ID**|**T1138**|
|**Objective(s)**|[Persistence](https://github.com/MAECProject/malware-behaviors/tree/master/persistence), [Privilege Escalation](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation)|
|**Related ATT&CK Technique(s)**|[Application Shimming](https://attack.mitre.org/techniques/T1138)|
Application Shimming
====================
Malware may use Windows Application Compatibility Infrastructure/Framework (application shim) to elevate privileges or install programs.
**See ATT&CK Technique:** [**Application Shimming**](https://attack.mitre.org/techniques/T1138).
@@ -0,0 +1,11 @@
|||
|---------|------------------------|
|**ID**|**T1038**|
|**Objective(s)**|[Defense Evasion](https://github.com/MAECProject/malware-behaviors/tree/master/defense-evasion), [Persistence](https://github.com/MAECProject/malware-behaviors/tree/master/persistence), [Privilege Escalation](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation)|
|**Related ATT&CK Technique(s)**|[DLL Search Order Hijacking](https://attack.mitre.org/techniques/T1038)|
DLL Search Order Hijacking
==========================
Malware may place a malicious DLL with the same name as a legitimate, but ambiguously specified, DLL in a location that Windows searches before the legitimate DLL (called a binary planting attack).
**See ATT&CK Technique:** [**DLL Search Order Hijacking**](https://attack.mitre.org/techniques/T1038).
@@ -0,0 +1,11 @@
|||
|---------|------------------------|
|**ID**|**T1068**|
|**Objective(s)**|[Privilege Escalation](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation)|
|**Related ATT&CK Technique(s)**|[Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068)|
Exploitation for Privilege Escalation
=====================================
Malware may exploit a software vulnerability to escalate privileges.
**See ATT&CK Technique:** [**Exploitation for Privilege Escalation**](https://attack.mitre.org/techniques/T1068).
@@ -0,0 +1,11 @@
|||
|---------|------------------------|
|**ID**|**T1044**|
|**Objective(s)**|[Persistence](https://github.com/MAECProject/malware-behaviors/tree/master/persistence), [Privilege Escalation](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation)|
|**Related ATT&CK Technique(s)**|[File System Permissions Weakness](https://attack.mitre.org/techniques/T1044)|
File System Permissions Weakness
================================
Malware may exploit a software vulnerability to escalate privileges.
**See ATT&CK Technique:** [**File System Permissions Weakness**](https://attack.mitre.org/techniques/T1044).
+11
View File
@@ -0,0 +1,11 @@
|||
|---------|------------------------|
|**ID**|**T1160**|
|**Objective(s)**|[Persistence](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation), [Privilege Escalation](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation)|
|**Related ATT&CK Technique(s)**|[Launch Daemon](https://attack.mitre.org/techniques/T1160)|
Launch Daemon
=============
Malware may install a new MacOS launch daemon that can be configured to execute at startup.
**See ATT&CK Technique:** [**Launch Daemon**](https://attack.mitre.org/techniques/T1160).
+11
View File
@@ -0,0 +1,11 @@
|||
|---------|------------------------|
|**ID**|**T1166**|
|**Objective(s)**|[Persistence](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation), [Privilege Escalation](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation)|
|**Related ATT&CK Technique(s)**|[Setuid and Setgid](https://attack.mitre.org/techniques/T1166)|
Setuid and Setgid
=================
Malware may take advantage of setuid or setgid bits in Linux or macOS applications to elevate privilege or for persistence.
**See ATT&CK Technique:** [**Setuid and Setgid**](https://attack.mitre.org/techniques/T1166).
+11
View File
@@ -0,0 +1,11 @@
|||
|---------|------------------------|
|**ID**|**T1169**|
|**Objective(s)**|[Privilege Escalation](https://github.com/MAECProject/malware-behaviors/tree/master/privilege-escalation)|
|**Related ATT&CK Technique(s)**|[Sudo](https://attack.mitre.org/techniques/T1169)|
Sudo
====
Malware may take advantage of the sudoers file in Linux or macOS for privilege escalation.
**See ATT&CK Technique:** [**Sudo**](https://attack.mitre.org/techniques/T1169).