87 Commits

Author SHA1 Message Date
brightmt f88fdabdad Update references (#172)
* Update references_to_mbc.md

Updated references.

* Update references_to_mbc.md

* Update references_to_mbc.md

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2024-12-27 11:15:10 -05:00
brightmt 634e938b37 Added matrix images with alphabetic objectives 2024-10-17 12:49:58 -04:00
Maddie Bright 476b07385d removed old tables 2024-10-17 10:44:52 -04:00
brightmt 0468702b69 Added new matrix images for 3.2 2024-10-17 10:41:15 -04:00
Maddie Bright d180c7bb60 uploaded table drafts 2024-09-27 08:55:53 -04:00
Desiree Beck bd31003a22 Staging (#151)
* Fixing links

* Code samples (#149)

* Update obfuscated-files-or-information.md

Added code sample with some proposed formatting incl. annotations explaining broad behavior patterns

* Update obfuscated-files-or-information.md

Added brief clarification to note

* Update obfuscated-files-or-information.md

Made requested changes to format

* Update system-information-discovery.md

Added code snippet from PoisonIvy RAT

* Update debugger-detection.md

Added code with example of PEB access

* Update system-information-discovery.md

Added new method based on code snippet

* Update registry.md

Added snippet for registry key query

* Update generate-pseudorandom-sequence.md

Added example of Mersenne Twister algorithm

* Update keylogging.md

Add Dark Comet keylogging code sample

* Update dns-communication.md

Added code sample from darkcomet

* Update socket-communication.md

Added DarkComet code snippet

* Update delete-file.md

Provided DarkComet sample

* Update file-and-directory-discovery.md

Added DarkComet snippet

* Update allocate-memory.md

Added DarkComet sample

* Update modulo.md

Added Hupigon snippet

* Update get-file-attributes.md

Added Hupigon sample

* Update application-window-discovery.md

Added Hupigon snippet

* Update create-process.md

Added Hupigon snippet.

* Update conditional-execution.md

Added Hupigon snippet

* Update create-thread.md

Added Hupigon snippet

* Update resume-thread.md

Added Hupigon snippet

* Update command-and-scripting-interpreter.md

Added SmokeLoader sample

* Update change-memory-protection.md

Added SmokeLoader snippet

* Update console.md

Added snippet from SmokeLoader

* Update dynamic-analysis-evasion.md

Added Industroyer sample

* Update interprocess-communication.md

Added CobaltStrike sample

* Update read-file.md

Added Cobalt Strike snippet

* Update writes-file.md

Added cobalt strike snippet

* Update noncryptographic-hash.md

Added emotet snippet

* Update clipboard-modification.md

Added emotet snippet

* Update check-mutex.md

Added emotet sampler

* Update check-mutex.md

Fixed typo

* Update create-mutex.md

Added Emotet snippet

* Update allocate-thread-local-storage.md

Added emotet snippet

* Update registry-run-keys-startup-folder.md

Added emotet snippet

* Update wininet.md

Added EnvyScout snippet

* Update http-communication.md

Added EnvyScout snippet

* Update enumerate-threads.md

Added Envyscout snippet

* Update set-thread-local-storage-value.md

Added Envyscout sample

* Update create-directory.md

Added explosive snippet

* Update delete-directory.md

Added explosive code snippet (note: the malware is called "explosive")

* Update set-file-attributes.md

Added explosive sample

* Update terminate-process.md

Added explosive snippet

* Update terminate-thread.md

Added explosive sample

* Update move-file.md

Added Finfisher snippet

* Update screen-capture.md

Added ECCENTRICBANDWAGON snippet

* Fix links (#150)

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* fix link

* update mod date

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* fix links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* update links

* Update code-discovery.md

* Update taskbar-discovery.md

* Update conditional-execution.md

* Update memory-dump-evasion.md

* Update execution-dependency.md

* Update compromise-data-integrity.md

* Update dns-communication.md

* Update http-communication.md

* Update interprocess-communication.md

* Update socket-communication.md

* Update wininet.md

* Update generate-pseudorandom-sequence.md

* Update modulo.md

* Update noncryptographic-hash.md

* Update create-directory.md

* Update delete-directory.md

* Update delete-file.md

* Update get-file-attributes.md

* Update move-file.md

* Update read-file.md

* Update terminate-thread.md

* Update set-file-attributes.md

* Update writes-file.md

* Update allocate-memory.md

* Update change-memory-protection.md

* Update console.md

* Update registry.md

* Update allocate-thread-local-storage.md

* Update check-mutex.md

* Update terminate-process.md

* Update create-mutex.md

* Update create-process.md

* Update set-thread-local-storage-value.md

* Update resume-thread.md

* Update enumerate-threads.md

* Update create-thread.md

* update for 3.1 release

* update for 3.1 release

* update for 3.1 release

---------

Co-authored-by: ryan <ryanxu@wustl.edu>
Co-authored-by: brightmt <50853930+brightmt@users.noreply.github.com>
2024-05-01 16:09:33 -04:00
Ryan Xu 009ae77217 3.1 Updates (#145)
* E/f updates (#143)

* E/F Update,  Update Install Cert ID

* Small fixes

* Update common objects link (#142)

* Update README.md

* Update 09152023.md

* Update README.md

* Update 12182023.md

* Adding descriptions to micro-behaviors

* Fixing dead links

* V3.1 updates (#144)

* minor fixes for v3.1

* correct id

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2024-02-14 09:27:20 -05:00
Ryan Xu d423b5a5fa Adding CAPE mappings to detection section (#132)
* Making spacing between sections consistent

* Adding cape mappings
2023-12-05 14:19:50 -05:00
Desiree Beck c2df3d4e10 Staging (#126)
* Changing conti name

* Mbc 3 (#125)

* update version number

* update links

* update version number

* update version number

* update version number

* 2.3 to main in matrix

* link fix

* v3 faq update

---------

Co-authored-by: ryan <ryanxu@wustl.edu>

---------

Co-authored-by: ryan <ryanxu@wustl.edu>
2023-10-03 11:36:05 -04:00
Ryan Xu f7d92d59fa Staging (#124)
- Updating capa detection in behaviors
- Newsletter
- Conti malware
- pafish faq
2023-09-20 15:57:32 -04:00
Ryan Xu 7223fa76d6 Aug 23 update (#118) (#119)
* update faq

* update faq

* update corpus doc

* update corpus doc

* update FAQ

* update FAQ

* update FAQ

* update FAQ

* update FAQ

* update what's new

* Cleaning ref links, etc (#115) (#116)

* Cleanup

---------



* Revert "Cleaning ref links, etc (#115) (#116)" (#117)

This reverts commit 57d470ab4c.

* reorder questions

* reorder questions

* reorder questions

* reorder questions

* update faq

* update faq

* update faq

* update faq

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2023-08-23 14:05:31 -04:00
Ryan Xu f3a6002ab4 Adding references page (#88)
* Adding references_to_mbc page

* Adding refs
2023-03-20 09:46:42 -04:00
Ryan Xu 1917b816ca Adding capa analysis to corpus and improved backtrace to behavior pages (#80)
* Adding script files

* Scripting overhaul

* Adding capa analysis from MITRE into corpus

* Adding capa analysis from MITRE into corpus

* Backtracing capa mappings to behavior pages

* Other fixes

* merge dev into staging

* Fixing capa mappings

* merge dev into staging

* fix writes file typo

* merge dev into staging

* Fix method column + cape analysis
2023-02-01 10:28:30 -05:00
Ryan Xu a2c1bb740b Merge branch 'master' into mbc-addfields 2022-11-30 10:07:21 -05:00
ryan 12b8422a5f Completed syntax migration and typo fixes 2022-11-29 09:19:21 -05:00
Malware Utkonos 0cad98fb1f Update navigator links from tag v2.2 to v2.3. Fixes #61 2022-11-19 01:53:22 -05:00
ryan 9c69facf0f Changed Markdown headers to atx-style 2022-11-10 12:02:12 -05:00
ryan 322fb1248d Updating Hashes to SHA256 + typo fixes 2022-09-16 09:44:47 -04:00
Desiree Beck e5b31bdd5b Merge pull request #57 from MBCProject/mbc-newsletter
Mbc newsletter
2022-09-09 15:52:26 -04:00
ryan fa9f508370 faq readme anchor fix 2022-09-08 15:01:30 -04:00
Dez Beck dbf98ecfb7 add newsletters 2022-09-08 12:42:21 -04:00
Dez Beck a1f14b90a8 updated for v2.3 2022-09-07 19:33:26 -04:00
ryan 9d2dc7d065 ATT&CK + MBC reference consistent formatting 2022-08-22 10:59:49 -04:00
ryan cd7b66d5b9 Adding PR feedback 2022-08-09 14:34:00 -04:00
ryan c544962577 Merge remote-tracking branch 'origin/master' into corpus 2022-08-09 14:14:11 -04:00
Dez Beck 95b1f2e854 mbc table and faq update 2022-08-09 14:11:10 -04:00
ryan e07e00f4d4 Enhanced malware corpus & update file names to match behaviors 2022-08-02 10:32:52 -04:00
Emmanuelle Vargas-Gonzalez ed5892d24b update text for v2.2 2022-02-05 19:58:09 -05:00
Emmanuelle Vargas-Gonzalez 2facfec1a5 update svg files for v2.2 2022-02-05 19:32:12 -05:00
Emmanuelle Vargas-Gonzalez 115d7f39d7 update svg graphics 2021-04-15 18:32:39 -04:00
Emmanuelle Vargas-Gonzalez 248207bd4b minor link issue in SVG 2021-02-10 14:41:55 -05:00
Emmanuelle Vargas-Gonzalez 14e747fc1f minor link issue in SVG 2021-02-10 10:15:35 -05:00
Emmanuelle Vargas-Gonzalez 052ad8283c update SVGs for MBC v2.1 2021-02-10 02:18:37 -05:00
Desiree Beck 859544e548 update text for v2.1 2021-02-09 13:42:54 -05:00
Desiree Beck a29e07bee2 update faq 2021-01-04 15:36:01 -05:00
Desiree Beck f60855e3b0 update faq 2021-01-04 15:30:45 -05:00
Emmanuelle Vargas-Gonzalez 9a177f67b5 add content for new MBC Matrix 2020-11-12 17:09:19 -05:00
malwarefrank ade5b26988 fix small typos in FAQ 2020-08-22 22:37:26 -04:00
Emmanuelle Vargas-Gonzalez b7197c785d make all internal references relative 2020-08-21 17:49:32 -04:00
Emmanuelle Vargas-Gonzalez c0a7760da9 Remove MBC-beta mention from FAQ 2020-08-20 16:08:50 -04:00
Emmanuelle Vargas-Gonzalez 74d816deb1 update mbc-beta hyperlinks to mbc-markdown equivalents 2020-08-14 14:54:01 -04:00
Emmanuelle Vargas-Gonzalez 2207d845ae move and replace MBCProject/mbc-markdown with contents from MBCProject/mbc-beta 2020-08-14 14:37:45 -04:00
Desiree Beck 3559ac6c87 typos 2020-06-28 13:58:28 -04:00
Desiree Beck 93367ba757 update text 2020-05-30 13:09:58 -04:00
Desiree Beck b751693952 update faq 2020-05-23 14:07:03 -04:00
Desiree Beck 16d6fb8683 update faq 2020-05-23 13:48:21 -04:00
Desiree Beck 4820c04475 update faq 2020-05-23 13:43:22 -04:00
Desiree Beck b04a1fda23 update faq 2020-05-23 13:39:00 -04:00
Desiree Beck 5cbe88a51e update faq 2020-05-23 13:34:08 -04:00
Desiree Beck 1d925d7cdd update faq 2020-05-23 13:33:31 -04:00