brightmt
4649d1d522
Merge pull request #178 from MBCProject/match-methods
...
Match methods
2025-04-03 08:13:56 -04:00
brightmt
f3b9e2a714
Merge pull request #177 from MBCProject/visualization
...
Behavior Visualization
2025-04-03 08:11:45 -04:00
Desiree Beck
cb53612423
Update compress-data.md
...
fixed typo
2025-04-02 18:46:23 -04:00
brightmt
2dd31923a2
Update README.md
2025-04-02 09:01:21 -04:00
brightmt
b0e971d43d
Update README.md
2025-04-02 08:55:06 -04:00
brightmt
f8c4eb4cb4
Update README.md
2025-04-02 08:47:19 -04:00
brightmt
a2a42e6c96
Update README.md
2025-04-02 08:43:35 -04:00
brightmt
b5e5331177
Update README.md
2025-03-31 12:13:15 -04:00
Maddie Bright
19ee71f6a2
added files for visualization work
2025-03-31 11:45:38 -04:00
Beck
03af076ad7
refine text
2025-03-29 13:17:53 -04:00
Beck
2739eed073
add visualization info
2025-03-29 12:05:55 -04:00
Beck
6344455b57
add visualization info
2025-03-29 12:03:27 -04:00
brightmt
df40a05878
Update compress-data.md
...
Added aPLib
2025-01-07 09:13:24 -05:00
brightmt
b906fe23f9
Merge pull request #175 from MBCProject/new-methods
...
Two New methods
2025-01-06 11:33:11 -05:00
brightmt
cbc9bb78d4
Create revoked.md ( #173 )
...
* Create revoked.md
Added table for tracking revoked IDs. Unsure of the reason for C0032.004's revocation, although my speculation based on google search is included.
* Update revoked.md
Fixed dates
* Update revoked.md
Added C0013
2025-01-03 13:52:23 -05:00
brightmt
f88fdabdad
Update references ( #172 )
...
* Update references_to_mbc.md
Updated references.
* Update references_to_mbc.md
* Update references_to_mbc.md
---------
Co-authored-by: Desiree Beck <dbeck@mitre.org >
2024-12-27 11:15:10 -05:00
Desiree Beck
e1f422dc8b
Update virtual-machine-detection.md
2024-12-27 11:04:03 -05:00
Desiree Beck
ef18cf849d
Update disassembler-evasion.md
2024-12-27 11:02:32 -05:00
Desiree Beck
04975dae43
Update virtual-machine-detection.md
2024-12-27 11:00:04 -05:00
brightmt
7f3bfe2c7d
Update capa to v8.0.1 ( #174 )
...
* Update disable-or-evade-security-tools.md
Added overwrite DLL .text section to remove hooks rule released in 7.2
* Update socket-communication.md
Added rule "attach BPF to socket on Linux" released in v 7.2
* Update self-deletion.md
Updated for congruence with CAPA 7.2 changes
* Update hijack-execution-flow.md
Updated APIs for "execute shellcode via Windows callback function"
* Update software-packing.md
Added "packed with nmm-protect" from CAPA 7.4
2024-12-26 15:06:07 -05:00
Desiree Beck
0aa720aa31
add December Newsletter ( #171 )
...
* Create 09192024.md
newsletter for MBC v3.2
* Update 09192024.md
* Update README.md
* Update 09192024.md
* Update 09192024.md
* Update 09192024.md
* Rename 09192024.md to 09242024.md
* Rename 09242024.md to 09232024.md
* Update README.md
* Update 09232024.md
* Update and rename 09232024.md to 10212024.md
* Update and rename 10212024.md to 12092024.md
* Update README.md
v3.2
2024-12-09 10:41:09 -05:00
Desiree Beck
0fab38218e
Staging ( #170 )
...
* Update dns-communication.md
* Update dns-communication.md
* Update http-communication.md
* Update icmp-communication.md
* Update interprocess-communication.md
* Update socket-communication.md
* Update wininet.md
* Update encrypt-data.md
* Update encrypt-data.md
* Update encryption-key.md
* Update alter-file-extension.md
* Update create-directory.md
* Update create-file.md
* Update create-file.md
* Update delete-file.md
* Update registry.md
* Update wallpaper.md
* Update create-process.md
* Update check-mutex.md
* Update writes-file.md
* Update create-mutex.md
---------
Co-authored-by: brightmt <50853930+brightmt@users.noreply.github.com >
2024-11-18 15:03:18 -05:00
brightmt
af8c8ea7ff
Merge pull request #166 from MBCProject/add-new-matrix-image
...
uploaded table drafts
2024-10-21 07:37:37 -04:00
brightmt
aa63470894
Merge pull request #167 from MBCProject/update_cape_classes
...
Update cape classes
2024-10-21 07:37:22 -04:00
brightmt
634e938b37
Added matrix images with alphabetic objectives
2024-10-17 12:49:58 -04:00
Maddie Bright
476b07385d
removed old tables
2024-10-17 10:44:52 -04:00
brightmt
0468702b69
Added new matrix images for 3.2
2024-10-17 10:41:15 -04:00
brightmt
03571e42e7
Update modify-registry.md
...
Found and repaired last broken link
2024-10-02 11:48:36 -04:00
brightmt
9cdd933745
Update allocate-thread-local-storage.md
...
Changed allocate TLS detection to new CAPA link
2024-10-02 11:10:24 -04:00
brightmt
7321acd0a1
Update process-injection.md
...
New link for silent process exit
2024-10-02 11:06:59 -04:00
brightmt
b9021def42
Update exploitation-for-client-execution.md
...
Updated link to Windows utilities
2024-10-02 11:01:10 -04:00
brightmt
95ff87565f
Update set-thread-local-storage-value.md
...
Updated link to CAPA rule
2024-10-02 10:52:33 -04:00
brightmt
2ba3797884
Update registry.md
...
Updated neshta signature link
2024-10-02 10:49:09 -04:00
brightmt
8dd14afae3
Update create-mutex.md
...
Updated Zeus P2P link
2024-10-02 10:40:52 -04:00
brightmt
e7a3dae7e6
Update move-file.md
...
Updated CAPE link and CAPE class
2024-10-02 10:28:36 -04:00
brightmt
44a35ab0d8
Update allocate-memory.md
...
Updated CAPE link and class
2024-10-02 10:26:32 -04:00
brightmt
2965436b62
Update allocate-memory.md
...
Fixed bad CAPA link
2024-10-02 10:17:55 -04:00
brightmt
91ec7133ff
Update allocate-memory.md
...
Updated bad CAPA rule link
2024-10-02 10:06:44 -04:00
brightmt
4874fd4b35
Update terminate-process.md
...
Added new link and CAPE class for rule
2024-10-02 10:02:25 -04:00
brightmt
1317809f48
Update decompress-data.md
2024-09-27 12:08:35 -04:00
brightmt
f3fbf1f51b
Update decrypt-data.md
...
Added class to CAPE mapping
2024-09-27 11:58:19 -04:00
Maddie Bright
d180c7bb60
uploaded table drafts
2024-09-27 08:55:53 -04:00
Desiree Beck
70f151ebe4
Update Process micro-objective ( #164 )
...
* Update create-mutex.md
* Update create-mutex.md
* Update README.md
* Update README.md
* Delete micro-behaviors/process/synchronization.md
* Update mbc_summary.md
---------
Co-authored-by: brightmt <50853930+brightmt@users.noreply.github.com >
2024-09-16 13:50:08 -04:00
Desiree Beck
c3033e4061
Staging ( #162 )
...
* update staging (#158 )
* update format/wording
* Capa 7.1 rule updates (#156 )
* Update self-deletion.md
Added CAPA rule "self delete using alternate data streams" (https://github.com/mandiant/capa-rules/blob/v7.1.0/anti-analysis/anti-forensic/self-deletion/self-delete-using-alternate-data-streams.yml )
* Update obfuscated-files-or-information.md
added new CAPA rule "encrypt data using RC4 via SystemFunction033" https://github.com/mandiant/capa-rules/blob/v7.1.0/data-manipulation/encryption/rc4/encrypt-data-using-rc4-via-systemfunction033.yml
* Update disk-wipe.md
Added capa rule "https://github.com/mandiant/capa-rules/blob/v7.1.0/impact/wipe-disk/delete-drive-layout-via-ioctl.yml " https://github.com/mandiant/capa-rules/blob/v7.1.0/impact/wipe-disk/delete-drive-layout-via-ioctl.yml
* Update system-information-discovery.md
Added new CAPA rule "get disk information via IOCTL" https://github.com/mandiant/capa-rules/blob/v7.1.0/nursery/get-disk-information-via-ioctl.yml
* Update system-information-discovery.md
Added new CAPA rule "get volume information via IOCTL" https://github.com/mandiant/capa-rules/blob/v7.1.0/nursery/get-volume-information-via-ioctl.yml
* Update dns-communication.md
Removed duplication in APIs in "Resolve DNS" CAPA rule
* Update socket-communication.md
Updated APIs for "create raw socket" CAPA rule
* Update socket-communication.md
Updated APIs on CAPA rule "get socket status"
* Update socket-communication.md
Updated CAPA rule "initialize Winsock library"
* Update socket-communication.md
Updated API listing on CAPA rule "receive data on socket"
* Update socket-communication.md
Updated API listing for "send data on socket" CAPA rule
* Update socket-communication.md
Update APIs for CAPA rule "set socket configuration"
* Update socket-communication.md
Updated CAPA rule "connect tcp socket" to add APIs
* Update socket-communication.md
Added APIs to CAPA rule "create tcp socket"
* Update socket-communication.md
Added APIs to "create UDP socket" CAPA rule
* Update encrypt-data.md
Added new APIs to "encrypt data using DPAPI" CAPA rule
* Update install-driver.md
Added APIs to CAPA rule "install driver"
* Update set-file-attributes.md
Added APIs to CAPA rule "change file permissions on Linux"
* Update writes-file.md
Updated APIs for CAPA rule "write file on linux"
* Update system-information-discovery.md
Removed API from CAPA rule "get disk size" to align with published CAPA rule in v. 7.1
* Update create-process.md
Added API to "create process on linux" CAPA rule
* Update hijack-execution-flow.md
Added API calls to CAPA rule "execute shellcode via Windows callback function"
* Update self-deletion.md
Changed link to master
* Update obfuscated-files-or-information.md
Changed rule link to release to point to master
* Update system-information-discovery.md
Removed nursery rules
* Update disk-wipe.md
Updated link to master branch
* Update socket-communication.md
Checked for correct socket listings under the APIs
---------
Co-authored-by: brightmt <50853930+brightmt@users.noreply.github.com >
* New method (#159 )
* update format/wording
* Update disassembler-evasion.md
* Update disassembler-evasion.md
* Corpus fix (#160 )
* update format/wording
* fix tables
* Edits
---------
Co-authored-by: ryan <ryanxu@wustl.edu >
* New method (#161 )
* update format/wording
* Update disassembler-evasion.md
* Update disassembler-evasion.md
---------
Co-authored-by: brightmt <50853930+brightmt@users.noreply.github.com >
Co-authored-by: ryan <ryanxu@wustl.edu >
2024-08-25 10:09:33 -04:00
brightmt
084ba830d3
Capa 7.1 rule updates ( #156 )
...
* Update self-deletion.md
Added CAPA rule "self delete using alternate data streams" (https://github.com/mandiant/capa-rules/blob/v7.1.0/anti-analysis/anti-forensic/self-deletion/self-delete-using-alternate-data-streams.yml )
* Update obfuscated-files-or-information.md
added new CAPA rule "encrypt data using RC4 via SystemFunction033" https://github.com/mandiant/capa-rules/blob/v7.1.0/data-manipulation/encryption/rc4/encrypt-data-using-rc4-via-systemfunction033.yml
* Update disk-wipe.md
Added capa rule "https://github.com/mandiant/capa-rules/blob/v7.1.0/impact/wipe-disk/delete-drive-layout-via-ioctl.yml " https://github.com/mandiant/capa-rules/blob/v7.1.0/impact/wipe-disk/delete-drive-layout-via-ioctl.yml
* Update system-information-discovery.md
Added new CAPA rule "get disk information via IOCTL" https://github.com/mandiant/capa-rules/blob/v7.1.0/nursery/get-disk-information-via-ioctl.yml
* Update system-information-discovery.md
Added new CAPA rule "get volume information via IOCTL" https://github.com/mandiant/capa-rules/blob/v7.1.0/nursery/get-volume-information-via-ioctl.yml
* Update dns-communication.md
Removed duplication in APIs in "Resolve DNS" CAPA rule
* Update socket-communication.md
Updated APIs for "create raw socket" CAPA rule
* Update socket-communication.md
Updated APIs on CAPA rule "get socket status"
* Update socket-communication.md
Updated CAPA rule "initialize Winsock library"
* Update socket-communication.md
Updated API listing on CAPA rule "receive data on socket"
* Update socket-communication.md
Updated API listing for "send data on socket" CAPA rule
* Update socket-communication.md
Update APIs for CAPA rule "set socket configuration"
* Update socket-communication.md
Updated CAPA rule "connect tcp socket" to add APIs
* Update socket-communication.md
Added APIs to CAPA rule "create tcp socket"
* Update socket-communication.md
Added APIs to "create UDP socket" CAPA rule
* Update encrypt-data.md
Added new APIs to "encrypt data using DPAPI" CAPA rule
* Update install-driver.md
Added APIs to CAPA rule "install driver"
* Update set-file-attributes.md
Added APIs to CAPA rule "change file permissions on Linux"
* Update writes-file.md
Updated APIs for CAPA rule "write file on linux"
* Update system-information-discovery.md
Removed API from CAPA rule "get disk size" to align with published CAPA rule in v. 7.1
* Update create-process.md
Added API to "create process on linux" CAPA rule
* Update hijack-execution-flow.md
Added API calls to CAPA rule "execute shellcode via Windows callback function"
* Update self-deletion.md
Changed link to master
* Update obfuscated-files-or-information.md
Changed rule link to release to point to master
* Update system-information-discovery.md
Removed nursery rules
* Update disk-wipe.md
Updated link to master branch
* Update socket-communication.md
Checked for correct socket listings under the APIs
2024-08-24 13:19:12 -04:00
Beck
ad8e58255c
update format/wording
2024-07-16 17:31:19 -04:00
Desiree Beck
e1f6657ac0
Update README.md ( #155 )
...
see Issue #152
2024-06-30 16:24:18 -04:00
RazviOverflow
53771d2293
Updated MBC-CAPE signature mappings ( #153 )
...
* Deleted deprecated signatures
* Added new signature
* Updated table to match new CAPE signatures' format
* Added new signature mappings
* Fixed table header
* Deleted unspecified API
* Updated table to match new CAPE signature format. Fixed existing signatures.
* Deleted deprecated signatures
* Added missing class
* Added new signature mappings
* Deleted deprecated signatures
* Updated table to match new CAPE signature format
* Added new signature mappings
* Updated deprecated links
* Updated table to match new CAPE signature format
* Added new signature mapping
* Updated table format, signature, and link
* Fixed existing signatures' url
* Deleted deprecated signatures
* Updated existing signatures
* Added new signature mappings
* Deleted deprecated signature
* Updated table. Added new signature mappings.
* Deleted deprecated signatures
* Updated table to new CAPE signature format
* Added new signature mappings
* Deleted deprecated signatures
* Updated table. Added new signature mappings.
* Deleted deprecated signatures
* Updated table. Added new signature mappings
* Fixed broken url
* Updated table
* Deleted deprecated signatures
* Updated table format. Added new signature mapping.
* Deleted deprecated signatures
* Updated table. Fixed already existing signatures.
* Added new signature mappings
* Updated existing signatures
* Updated table format. Deleted deprecated signatures.
* Updated existing signatures
* Added new signature mappings
* Updated existing signatures
* Updated table and signatures
* Fixed existing signatures
* Deleted deprecated signatures
* Updated table
* Added new signature mappings
* Updated existing signatures
* Updating existing signatures
* Updating existing signatures
* Updating exiting signature
* Deleted deprecated signatures
* Updated existing signatures
* Updated existing signatures
* Added new signature mappings
* Deleted deprecated signature
* Updated table
* Added new signature mapping
* Deleted deprecated signatures
* Added new signature mappings
* Deleted deprecated signatures
* Added new signature mappings
* Updated table and existing signatures
* Deleted deprecated signatures
* Updated table and existing signatures
* Added new signature mappings
* Fixing typos
* Fixing typos II
* Fixing typos III
2024-06-30 15:08:20 -04:00
Desiree Beck
bd31003a22
Staging ( #151 )
...
* Fixing links
* Code samples (#149 )
* Update obfuscated-files-or-information.md
Added code sample with some proposed formatting incl. annotations explaining broad behavior patterns
* Update obfuscated-files-or-information.md
Added brief clarification to note
* Update obfuscated-files-or-information.md
Made requested changes to format
* Update system-information-discovery.md
Added code snippet from PoisonIvy RAT
* Update debugger-detection.md
Added code with example of PEB access
* Update system-information-discovery.md
Added new method based on code snippet
* Update registry.md
Added snippet for registry key query
* Update generate-pseudorandom-sequence.md
Added example of Mersenne Twister algorithm
* Update keylogging.md
Add Dark Comet keylogging code sample
* Update dns-communication.md
Added code sample from darkcomet
* Update socket-communication.md
Added DarkComet code snippet
* Update delete-file.md
Provided DarkComet sample
* Update file-and-directory-discovery.md
Added DarkComet snippet
* Update allocate-memory.md
Added DarkComet sample
* Update modulo.md
Added Hupigon snippet
* Update get-file-attributes.md
Added Hupigon sample
* Update application-window-discovery.md
Added Hupigon snippet
* Update create-process.md
Added Hupigon snippet.
* Update conditional-execution.md
Added Hupigon snippet
* Update create-thread.md
Added Hupigon snippet
* Update resume-thread.md
Added Hupigon snippet
* Update command-and-scripting-interpreter.md
Added SmokeLoader sample
* Update change-memory-protection.md
Added SmokeLoader snippet
* Update console.md
Added snippet from SmokeLoader
* Update dynamic-analysis-evasion.md
Added Industroyer sample
* Update interprocess-communication.md
Added CobaltStrike sample
* Update read-file.md
Added Cobalt Strike snippet
* Update writes-file.md
Added cobalt strike snippet
* Update noncryptographic-hash.md
Added emotet snippet
* Update clipboard-modification.md
Added emotet snippet
* Update check-mutex.md
Added emotet sampler
* Update check-mutex.md
Fixed typo
* Update create-mutex.md
Added Emotet snippet
* Update allocate-thread-local-storage.md
Added emotet snippet
* Update registry-run-keys-startup-folder.md
Added emotet snippet
* Update wininet.md
Added EnvyScout snippet
* Update http-communication.md
Added EnvyScout snippet
* Update enumerate-threads.md
Added Envyscout snippet
* Update set-thread-local-storage-value.md
Added Envyscout sample
* Update create-directory.md
Added explosive snippet
* Update delete-directory.md
Added explosive code snippet (note: the malware is called "explosive")
* Update set-file-attributes.md
Added explosive sample
* Update terminate-process.md
Added explosive snippet
* Update terminate-thread.md
Added explosive sample
* Update move-file.md
Added Finfisher snippet
* Update screen-capture.md
Added ECCENTRICBANDWAGON snippet
* Fix links (#150 )
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* fix link
* update mod date
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* fix links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* update links
* Update code-discovery.md
* Update taskbar-discovery.md
* Update conditional-execution.md
* Update memory-dump-evasion.md
* Update execution-dependency.md
* Update compromise-data-integrity.md
* Update dns-communication.md
* Update http-communication.md
* Update interprocess-communication.md
* Update socket-communication.md
* Update wininet.md
* Update generate-pseudorandom-sequence.md
* Update modulo.md
* Update noncryptographic-hash.md
* Update create-directory.md
* Update delete-directory.md
* Update delete-file.md
* Update get-file-attributes.md
* Update move-file.md
* Update read-file.md
* Update terminate-thread.md
* Update set-file-attributes.md
* Update writes-file.md
* Update allocate-memory.md
* Update change-memory-protection.md
* Update console.md
* Update registry.md
* Update allocate-thread-local-storage.md
* Update check-mutex.md
* Update terminate-process.md
* Update create-mutex.md
* Update create-process.md
* Update set-thread-local-storage-value.md
* Update resume-thread.md
* Update enumerate-threads.md
* Update create-thread.md
* update for 3.1 release
* update for 3.1 release
* update for 3.1 release
---------
Co-authored-by: ryan <ryanxu@wustl.edu >
Co-authored-by: brightmt <50853930+brightmt@users.noreply.github.com >
v3.1
2024-05-01 16:09:33 -04:00
Desiree Beck
42dc41e00b
update for attack v15 ( #148 )
...
* update for attack v15
* update modified date
2024-04-28 14:32:00 -04:00