update corpus overview text

This commit is contained in:
Dez Beck
2022-08-12 18:52:39 -04:00
parent ff57a87f7f
commit a5a31f2f63
+6 -2
View File
@@ -1,7 +1,11 @@
# Example Malware #
The following malware are used as examples on MBC behavior pages.
The MBC corpus comprises the malware below. On each malware page, malware behaviors are mapped to ATT&CK techniques and MBC behaviors. The results are separated into three categories: "ATT&CK Techniques," "Enhanced ATT&CK Techniques," and "MBC Behaviors."
If malware appears on ATT&CK's software list, ATT&CK is referenced. Behaviors (techniques) listed on an ATT&CK page may be included in an MBC Behavior table, but the user should reference ATT&CK for details (MBC does not duplicate ATT&CK content). Behaviors not included on an ATT&CK page will include details of use.
**ATT&CK Techniques** - If a malware example <u>is not</u> included in ATT&CK's software collection, then all ATT&CK techniques to which malware behaviors map are listed. If a malware example <u>is</u> included in ATT&CK's software collection, then the corresponding software page is referenced under "ATT&CK Techniques" (mappings *not* captured in ATT&CK are still listed).
**Enhanced ATT&CK Techniques** - Any ATT&CK techniques that would be listed under "ATT&CK Techniques" but have been enhanced in MBC are listed in this section instead.
**MBC Behaviors** - Lists all MBC behaviors to which malware behaviors map.
* **Bagle** [X0001](../xample-malware/bagle.md)
* **Black Energy** [X0002](../xample-malware/blackenergy.md)