update corpus overview text

This commit is contained in:
Dez Beck
2022-08-12 18:58:55 -04:00
parent a5a31f2f63
commit 5e3a5cedf7
+3 -1
View File
@@ -1,7 +1,9 @@
# Example Malware #
The MBC corpus comprises the malware below. On each malware page, malware behaviors are mapped to ATT&CK techniques and MBC behaviors. The results are separated into three categories: "ATT&CK Techniques," "Enhanced ATT&CK Techniques," and "MBC Behaviors."
**ATT&CK Techniques** - If a malware example <u>is not</u> included in ATT&CK's software collection, then all ATT&CK techniques to which malware behaviors map are listed. If a malware example <u>is</u> included in ATT&CK's software collection, then the corresponding software page is referenced under "ATT&CK Techniques" (mappings *not* captured in ATT&CK are still listed).
**ATT&CK Techniques** - If a malware example *is not* included in ATT&CK's software collection, then all ATT&CK techniques to which malware behaviors map are listed. For an example, please see [Kovter X0009](../xample-malware/kovter.md).
If a malware example *is* included in ATT&CK's software collection, then the corresponding software page is referenced under "ATT&CK Techniques" (mappings *not* captured in ATT&CK are still listed). For an example, please see [Poison-Ivy X0014](../xample-malware/poison-ivy.md).
**Enhanced ATT&CK Techniques** - Any ATT&CK techniques that would be listed under "ATT&CK Techniques" but have been enhanced in MBC are listed in this section instead.