diff --git a/anti-behavioral-analysis/README.md b/anti-behavioral-analysis/README.md index 10527aa..fd6e560 100644 --- a/anti-behavioral-analysis/README.md +++ b/anti-behavioral-analysis/README.md @@ -14,7 +14,6 @@ Behaviors that prevent, obstruct, or evade behavioral analysis of malware--for e * **Emulator Detection** [B0004](../anti-behavioral-analysis/detect-emulator.md) * **Emulator Evasion** [B0005](../anti-behavioral-analysis/evade-emulator.md) * **Executable Code Virtualization** [B0008](../anti-static-analysis/exe-code-virtualize.md) -* **Hooking** [F0003](../credential-access/hooking.md) * **Memory Dump Evasion** [B0006](../anti-behavioral-analysis/evade-memory-dump.md) * **Sandbox Detection** [B0007](../anti-behavioral-analysis/detect-sandbox.md) * **Software Packing** [F0001](../anti-static-analysis/software-packing.md) diff --git a/collection/README.md b/collection/README.md index 964f8f5..bb3ee2b 100644 --- a/collection/README.md +++ b/collection/README.md @@ -4,10 +4,9 @@ # Collection # -Behaviors that identify and gather information, such as sensitive files, from a target network prior to exfiltration. This objective includes locations on a system or network where the malware may look for information to exfiltrate. +Behaviors that enable malware to identify and gather information, such as sensitive files, from a machine or network. Sources often targeted include drives, browsers, audio/video, and email. Often the malware's next objective is to exfiltrate the information gathered. * **Cryptocurrency** [B0028](../collection/cryptocurrency.md) -* **Hooking** [F0003](../credential-access/hooking.md) * **Input Capture** [E1056](../collection/input-capture.md) * **Keylogging** [F0002](../collection/keylogging.md) * **Screen Capture** [E1113](../collection/screen-capture.md) diff --git a/command-and-control/README.md b/command-and-control/README.md index 7673351..e5976b9 100644 --- a/command-and-control/README.md +++ b/command-and-control/README.md @@ -4,7 +4,7 @@ # Command and Control -Behaviors malware may use to communicate with systems under its control within a target network. There are many ways malware can establish command and control with various levels of covertness, depending on system configuration and network topology. Behaviors may relate to C2 servers or a bot that is part of a botnet. As "server" and "client" are confusing terminology in this context, we use the terms **controller** and **implant**. The controller is the software running on adversary-controlled infrastructure and used to send commands to the implant. The implant is the software running on victim-controlled infrastructure that receives commands from the adversary, executes those commands on the victim, and optionally sends the results back to the adversary. +Behaviors that enable malware to communicate with systems such as C2 servers or bots. Malware can establish command and control with various levels of covertness, depending on system configuration and network topology. * **Command and Control Communication** [B0030](../command-and-control/command-control-comm.md) * **Domain Name Generation** [B0031](../command-and-control/domain-name-generate.md) diff --git a/command-and-control/command-control-comm.md b/command-and-control/command-control-comm.md index db5a77a..9a7ffd7 100644 --- a/command-and-control/command-control-comm.md +++ b/command-and-control/command-control-comm.md @@ -11,6 +11,8 @@ All command and control malware use implant/controller communication. The method Command and Control Communication relates to *autonomous* communications, not explicit, on-demand commands that malware provides to an adversary (such commands should be captured with [Remote Commands](../execution/remote-commands.md) under the Execution objective). +As "server" and "client" are confusing terminology, we use the terms "controller" and "implant". The controller is the software running on adversary-controlled infrastructure and used to send commands to the implant. The implant is the software running on victim-controlled infrastructure that receives commands from the adversary, executes those commands on the victim, and optionally sends the results back to the adversary. + Methods ------- |Name|ID|Description| diff --git a/defense-evasion/README.md b/defense-evasion/README.md index b966546..12b46e0 100644 --- a/defense-evasion/README.md +++ b/defense-evasion/README.md @@ -4,7 +4,7 @@ # Defense Evasion # -Behaviors that evade detection or avoid other defenses. +Behaviors that enable malware to evade detection. * **Alternative Installation Location** [B0027](../defense-evasion/alter-install-location.md) * **Bootkit** [F0013](../defense-evasion/boot-sector-mod.md) @@ -16,7 +16,6 @@ Behaviors that evade detection or avoid other defenses. * **Hide Artifacts** [E1564](../defense-evasion/hide-artifacts.md) * **Hidden Files and Directories** [F0005](../defense-evasion/hidden-files.md) * **Hijack Execution Flow** [F0015](../defense-evasion/hijack-execution-flow.md) -* **Hooking** [F0003](../credential-access/hooking.md) * **Indicator Blocking** [F0006](../defense-evasion/indicator-blocking.md) * **Install Insecure or Malicious Configuration** [E1478](../defense-evasion/config-mod.md) * **Modify Registry** [E1112](../defense-evasion/modify-reg.md) diff --git a/discovery/README.md b/discovery/README.md index f86bb44..e10b86c 100644 --- a/discovery/README.md +++ b/discovery/README.md @@ -4,7 +4,7 @@ # Discovery # -Behaviors that aim to gain knowledge about the system and internal network. +Behaviors that enable malware to gain knowledge about the system and network. * **Analysis Tool Discovery** [B0013](../discovery/analysis-tool-discover.md) * **Application Window Discovery** [E1010](../discovery/app-window-discover.md) diff --git a/execution/README.md b/execution/README.md index de48f13..d08fbf4 100644 --- a/execution/README.md +++ b/execution/README.md @@ -3,7 +3,7 @@ |**ID**|**OB0009**| # Execution # -Behaviors that execute code on a system to achieve a variety of goals. +Behaviors that enable malware to execute code on a system to achieve a variety of goals. * **Command and Scripting Interpreter** [E1059](../execution/command-line.md) * **Conditional Execution** [B0025](../execution/conditional-execute.md) diff --git a/exfiltration/README.md b/exfiltration/README.md index 8efca23..e11edca 100644 --- a/exfiltration/README.md +++ b/exfiltration/README.md @@ -4,7 +4,7 @@ # Exfiltration # -Behaviors that steal data from the system on which it executes. This includes stored data (e.g., files) as well as data input into applications (e.g., web browser). +Behaviors that enable malware to steal data from a system. This includes stored data, such as files, as well as data input into applications, such as web browsers. * **Automated Exfiltration** [E1020](../exfiltration/auto-exfiltrate.md) * **Archive Collected Data** [E1560](../exfiltration/data-encrypted.md) diff --git a/impact/README.md b/impact/README.md index 41da76c..995e442 100644 --- a/impact/README.md +++ b/impact/README.md @@ -4,7 +4,7 @@ # Impact # -Behaviors that enable malware to achieve its mission of manipulating, interrupting, or destroying systems and/or data. +Behaviors that enable malware to manipulate, interrupt, or destroy systems and data. * **Clipboard Modification** [E1510](../impact/clipboard-mod.md) * **Component Firmware** [F0009](../persistence/component-firmware.md) diff --git a/lateral-movement/README.md b/lateral-movement/README.md index a200987..00c9e48 100644 --- a/lateral-movement/README.md +++ b/lateral-movement/README.md @@ -4,7 +4,7 @@ # Lateral Movement -Behaviors that enable propagation through a compromised system or infected files. The malware may move actively (e.g., gain access to a machine directly) or passively (e.g., send malicious email). +Behaviors that enable malware to propagate or otherwise move through an environment. Lateral movement may be active, happening via direct machine access, or may be passive (for example, done via malicious email). * **Malicious Network Driver** [B0026](../persistence/malicious-network-drv.md) * **Remote File Copy** [E1105](../command-and-control/remote-file-copy.md) diff --git a/persistence/README.md b/persistence/README.md index 2f3e06f..bb554fd 100644 --- a/persistence/README.md +++ b/persistence/README.md @@ -4,14 +4,13 @@ # Persistence # -Malware aims to remain on a system regardless of system events. +Behaviors that enable malware to remain on a system regardless of system events, such as reboots. * **Bootkit** [F0013](../defense-evasion/boot-sector-mod.md) * **Component Firmware** [F0009](../persistence/component-firmware.md) * **Hide Artifacts** [E1564](../defense-evasion/hide-artifacts.md) * **Hidden Files and Directories** [F0005](../defense-evasion/hidden-files.md) * **Hijack Execution Flow** [E1574](../defense-evasion/hijack-execution-flow.md) -* **Hooking** [F0003](../credential-access/hooking.md) * **Install Insecure or Malicious Configuration** [E1478](../defense-evasion/config-mod.md) * **Kernel Modules and Extensions** [F0010](../persistence/kernel-modules-ext.md) * **Malicious Network Driver** [B0026](../persistence/malicious-network-drv.md) diff --git a/privilege-escalation/README.md b/privilege-escalation/README.md index 491342f..52d10bf 100644 --- a/privilege-escalation/README.md +++ b/privilege-escalation/README.md @@ -4,10 +4,9 @@ # Privilege Escalation # -Behaviors that aim to obtain a higher level of permission. +Behaviors that enable malware to obtain higher level permissions. These behaviors often overlap with Persistence behaviors. * **Hijack Execution Flow** [E1574](../defense-evasion/hijack-execution-flow.md) -* **Hooking** [F0003](../credential-access/hooking.md) * **Kernel Modules and Extensions** [F0010](../persistence/kernel-modules-ext.md) * **Modify Existing Service** [F0011](../persistence/modify-service.md) * **Process Injection** [E1055](../defense-evasion/process-inject.md)