mirror of
https://github.com/MBCProject/mbc-markdown
synced 2026-06-08 11:36:36 +00:00
084ba830d3
* Update self-deletion.md Added CAPA rule "self delete using alternate data streams" (https://github.com/mandiant/capa-rules/blob/v7.1.0/anti-analysis/anti-forensic/self-deletion/self-delete-using-alternate-data-streams.yml) * Update obfuscated-files-or-information.md added new CAPA rule "encrypt data using RC4 via SystemFunction033" https://github.com/mandiant/capa-rules/blob/v7.1.0/data-manipulation/encryption/rc4/encrypt-data-using-rc4-via-systemfunction033.yml * Update disk-wipe.md Added capa rule "https://github.com/mandiant/capa-rules/blob/v7.1.0/impact/wipe-disk/delete-drive-layout-via-ioctl.yml" https://github.com/mandiant/capa-rules/blob/v7.1.0/impact/wipe-disk/delete-drive-layout-via-ioctl.yml * Update system-information-discovery.md Added new CAPA rule "get disk information via IOCTL" https://github.com/mandiant/capa-rules/blob/v7.1.0/nursery/get-disk-information-via-ioctl.yml * Update system-information-discovery.md Added new CAPA rule "get volume information via IOCTL" https://github.com/mandiant/capa-rules/blob/v7.1.0/nursery/get-volume-information-via-ioctl.yml * Update dns-communication.md Removed duplication in APIs in "Resolve DNS" CAPA rule * Update socket-communication.md Updated APIs for "create raw socket" CAPA rule * Update socket-communication.md Updated APIs on CAPA rule "get socket status" * Update socket-communication.md Updated CAPA rule "initialize Winsock library" * Update socket-communication.md Updated API listing on CAPA rule "receive data on socket" * Update socket-communication.md Updated API listing for "send data on socket" CAPA rule * Update socket-communication.md Update APIs for CAPA rule "set socket configuration" * Update socket-communication.md Updated CAPA rule "connect tcp socket" to add APIs * Update socket-communication.md Added APIs to CAPA rule "create tcp socket" * Update socket-communication.md Added APIs to "create UDP socket" CAPA rule * Update encrypt-data.md Added new APIs to "encrypt data using DPAPI" CAPA rule * Update install-driver.md Added APIs to CAPA rule "install driver" * Update set-file-attributes.md Added APIs to CAPA rule "change file permissions on Linux" * Update writes-file.md Updated APIs for CAPA rule "write file on linux" * Update system-information-discovery.md Removed API from CAPA rule "get disk size" to align with published CAPA rule in v. 7.1 * Update create-process.md Added API to "create process on linux" CAPA rule * Update hijack-execution-flow.md Added API calls to CAPA rule "execute shellcode via Windows callback function" * Update self-deletion.md Changed link to master * Update obfuscated-files-or-information.md Changed rule link to release to point to master * Update system-information-discovery.md Removed nursery rules * Update disk-wipe.md Updated link to master branch * Update socket-communication.md Checked for correct socket listings under the APIs
1.0 KiB
1.0 KiB
| ID | C0037 |
| Objective(s) | Hardware |
| Related ATT&CK Techniques | None |
| Version | 2.0 |
| Created | 4 December 2020 |
| Last Modified | 13 September 2023 |
Install Driver
Malware installs a driver or minifilter.
Methods
| Name | ID | Description |
|---|---|---|
| Minifilter | C0037.001 | Malware registers a minifilter. |
Detection
| Tool: capa | Mapping | APIs |
|---|---|---|
| install driver | Install Driver (C0037) | ntdll.NtLoadDriver, ZwLoadDriver, NtSetSystemInformation ZwSetSystemInformation |
| register minifilter driver | Install Driver::Minifilter (C0037.001) | FltRegisterFilter |