Files
brightmt 6933d9e896 Snake (#179)
* Update snake.md

Updated malware behaviors and descriptions.

* Update snake.md

Divided table to split out enhanced techniques

* Update software-packing.md

Added Snake

* Update self-deletion.md

Added Snake

* Update system-information-discovery.md

Added Snake

* Update keylogging.md

Added Snake

* Update screen-capture.md

* Update decode-data.md

Added Snake

* Update decrypt-data.md

Added Snake

* Update copy-file.md

Added Snake

* Update create-file.md

Added Snake

* Update delete-file.md

* Update crypto-library.md

Added Snake

* Update crypto-library.md

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2025-04-03 17:46:24 -04:00
..
2024-02-14 09:27:20 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-21 09:18:21 -05:00
2023-12-20 21:54:25 -05:00
2024-02-14 09:27:20 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2024-08-25 10:09:33 -04:00
2023-12-20 21:54:25 -05:00
2024-05-01 16:09:33 -04:00
2023-12-20 21:54:25 -05:00
2024-08-25 10:09:33 -04:00
2023-12-20 21:54:25 -05:00
2024-08-25 10:09:33 -04:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-21 09:18:21 -05:00
2023-12-20 21:54:25 -05:00
2024-02-14 09:27:20 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2024-02-14 09:27:20 -05:00
2023-12-21 09:18:21 -05:00
2023-12-20 21:54:25 -05:00
2024-02-14 09:27:20 -05:00
2023-12-20 21:54:25 -05:00
2025-04-03 17:46:24 -04:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00
2023-12-20 21:54:25 -05:00

Malware Corpus

The MBC malware corpus comprises a variety of malware where each entry is decomposed into behaviors that are mapped to ATT&CK and MBC. The mappings are based on open source malware analysis reports and are separated into three categories: "ATT&CK Techniques," "Enhanced ATT&CK Techniques," and "MBC Behaviors."

ATT&CK Techniques - If a malware entry is not included in ATT&CK's software collection, then all ATT&CK techniques to which its malware behaviors map are listed. If a malware entry is included in ATT&CK's software collection, then the corresponding software page is referenced under "ATT&CK Techniques" (individual mappings not captured in ATT&CK are still listed). These techniques have T identifiers (e.g., T1012).

Enhanced ATT&CK Techniques - Any ATT&CK techniques that would be listed under "ATT&CK Techniques" but have been enhanced in MBC are listed in this section instead. These techniques have E and F identifiers (e.g., E1560, F0008).

MBC Behaviors - This section lists all MBC behaviors to which an entry's malware behaviors map. These techniques have B and C identifiers (e.g., B0032, C0010).

Notes

  • Each entry is mapped to one or more malware types.

  • Poison-Ivy X0014 and Kovter X0009 are examples of malware samples included and not included in ATT&CK's collection, respectively.

  • The FAQ includes information about the malware used to illustrate the use of MBC in Attack Flow and CACAO.

The List