Desiree Beck
|
bd31003a22
|
Staging (#151)
* Fixing links
* Code samples (#149)
* Update obfuscated-files-or-information.md
Added code sample with some proposed formatting incl. annotations explaining broad behavior patterns
* Update obfuscated-files-or-information.md
Added brief clarification to note
* Update obfuscated-files-or-information.md
Made requested changes to format
* Update system-information-discovery.md
Added code snippet from PoisonIvy RAT
* Update debugger-detection.md
Added code with example of PEB access
* Update system-information-discovery.md
Added new method based on code snippet
* Update registry.md
Added snippet for registry key query
* Update generate-pseudorandom-sequence.md
Added example of Mersenne Twister algorithm
* Update keylogging.md
Add Dark Comet keylogging code sample
* Update dns-communication.md
Added code sample from darkcomet
* Update socket-communication.md
Added DarkComet code snippet
* Update delete-file.md
Provided DarkComet sample
* Update file-and-directory-discovery.md
Added DarkComet snippet
* Update allocate-memory.md
Added DarkComet sample
* Update modulo.md
Added Hupigon snippet
* Update get-file-attributes.md
Added Hupigon sample
* Update application-window-discovery.md
Added Hupigon snippet
* Update create-process.md
Added Hupigon snippet.
* Update conditional-execution.md
Added Hupigon snippet
* Update create-thread.md
Added Hupigon snippet
* Update resume-thread.md
Added Hupigon snippet
* Update command-and-scripting-interpreter.md
Added SmokeLoader sample
* Update change-memory-protection.md
Added SmokeLoader snippet
* Update console.md
Added snippet from SmokeLoader
* Update dynamic-analysis-evasion.md
Added Industroyer sample
* Update interprocess-communication.md
Added CobaltStrike sample
* Update read-file.md
Added Cobalt Strike snippet
* Update writes-file.md
Added cobalt strike snippet
* Update noncryptographic-hash.md
Added emotet snippet
* Update clipboard-modification.md
Added emotet snippet
* Update check-mutex.md
Added emotet sampler
* Update check-mutex.md
Fixed typo
* Update create-mutex.md
Added Emotet snippet
* Update allocate-thread-local-storage.md
Added emotet snippet
* Update registry-run-keys-startup-folder.md
Added emotet snippet
* Update wininet.md
Added EnvyScout snippet
* Update http-communication.md
Added EnvyScout snippet
* Update enumerate-threads.md
Added Envyscout snippet
* Update set-thread-local-storage-value.md
Added Envyscout sample
* Update create-directory.md
Added explosive snippet
* Update delete-directory.md
Added explosive code snippet (note: the malware is called "explosive")
* Update set-file-attributes.md
Added explosive sample
* Update terminate-process.md
Added explosive snippet
* Update terminate-thread.md
Added explosive sample
* Update move-file.md
Added Finfisher snippet
* Update screen-capture.md
Added ECCENTRICBANDWAGON snippet
* Fix links (#150)
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* update mod date
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* Update code-discovery.md
* Update taskbar-discovery.md
* Update conditional-execution.md
* Update memory-dump-evasion.md
* Update execution-dependency.md
* Update compromise-data-integrity.md
* Update dns-communication.md
* Update http-communication.md
* Update interprocess-communication.md
* Update socket-communication.md
* Update wininet.md
* Update generate-pseudorandom-sequence.md
* Update modulo.md
* Update noncryptographic-hash.md
* Update create-directory.md
* Update delete-directory.md
* Update delete-file.md
* Update get-file-attributes.md
* Update move-file.md
* Update read-file.md
* Update terminate-thread.md
* Update set-file-attributes.md
* Update writes-file.md
* Update allocate-memory.md
* Update change-memory-protection.md
* Update console.md
* Update registry.md
* Update allocate-thread-local-storage.md
* Update check-mutex.md
* Update terminate-process.md
* Update create-mutex.md
* Update create-process.md
* Update set-thread-local-storage-value.md
* Update resume-thread.md
* Update enumerate-threads.md
* Update create-thread.md
* update for 3.1 release
* update for 3.1 release
* update for 3.1 release
---------
Co-authored-by: ryan <ryanxu@wustl.edu>
Co-authored-by: brightmt <50853930+brightmt@users.noreply.github.com>
|
2024-05-01 16:09:33 -04:00 |
|
ryan
|
ad05fb07ba
|
Updating version and last modified
|
2024-01-02 12:58:56 -05:00 |
|
Ryan Xu
|
d423b5a5fa
|
Adding CAPE mappings to detection section (#132)
* Making spacing between sections consistent
* Adding cape mappings
|
2023-12-05 14:19:50 -05:00 |
|
Ryan Xu
|
f7d92d59fa
|
Staging (#124)
- Updating capa detection in behaviors
- Newsletter
- Conti malware
- pafish faq
|
2023-09-20 15:57:32 -04:00 |
|
Ryan Xu
|
275c8feec3
|
New Malware Examples + Editing References (#105)
* New malware examples (#103)
* fix typos
* add new Use in Malware entries to behaviors
* new corpus entries
* remove extraneous ref
* restore original IDs
* fix typos
* Update registry.md (#101)
Update C0036.001 per "Registry micro-behavior" Discussion.
* Update registry.md (#102)
Update C0036.001 per "Registry micro-behavior" Discussion.
* correct modified date
* fix PR comments on formatting
* Editing references (#104)
---------
Co-authored-by: Desiree Beck <dbeck@mitre.org>
|
2023-06-12 11:10:47 -04:00 |
|
ryan
|
236f706f30
|
Changed Markdown headers to atx-style pt2
|
2022-11-10 13:28:52 -05:00 |
|
ryan
|
9c69facf0f
|
Changed Markdown headers to atx-style
|
2022-11-10 12:02:12 -05:00 |
|
ryan
|
779142fb8f
|
Added new header fields
|
2022-10-31 15:49:13 -04:00 |
|
ryan
|
9d2dc7d065
|
ATT&CK + MBC reference consistent formatting
|
2022-08-22 10:59:49 -04:00 |
|
ryan
|
d9e84725bf
|
HTML tables inside Markdown
|
2022-08-18 15:15:00 -04:00 |
|
ryan
|
e07e00f4d4
|
Enhanced malware corpus & update file names to match behaviors
|
2022-08-02 10:32:52 -04:00 |
|