Files
MBCProject-mbc-markdown/xample-malware
Desiree Beck 4ff8c3a316 Staging (#126)
* Changing conti name

* Mbc 3 (#125)

* update version number

* update links

* update version number

* update version number

* update version number

* 2.3 to main in matrix

* link fix

* v3 faq update

---------

Co-authored-by: ryan <ryanxu@wustl.edu>

---------

Co-authored-by: ryan <ryanxu@wustl.edu>
2023-09-29 20:34:10 -04:00
..
2023-09-20 15:57:32 -04:00
2023-08-17 14:08:55 -04:00
2023-08-17 14:08:55 -04:00
2023-06-29 12:57:34 -04:00
2023-08-17 14:08:55 -04:00
2023-08-17 14:08:55 -04:00
2023-06-29 12:57:34 -04:00
2023-09-29 20:34:10 -04:00
2023-06-29 12:57:34 -04:00
2023-08-17 14:08:55 -04:00
2023-06-29 12:57:34 -04:00
2023-08-17 14:08:55 -04:00
2023-08-17 14:08:55 -04:00
2023-08-17 14:08:55 -04:00
2023-08-17 14:08:55 -04:00
2023-08-17 14:08:55 -04:00
2023-08-17 14:08:55 -04:00
2023-08-17 14:08:55 -04:00
2023-08-17 14:08:55 -04:00
2023-06-29 12:57:34 -04:00
2023-06-29 12:57:34 -04:00
2023-08-17 14:08:55 -04:00
2023-06-29 12:57:34 -04:00
2023-06-29 12:57:34 -04:00
2023-06-29 12:57:34 -04:00
2023-06-29 12:57:34 -04:00
2023-09-20 15:57:32 -04:00
2023-06-29 12:57:34 -04:00
2023-06-29 12:57:34 -04:00
2023-06-29 12:57:34 -04:00
2023-08-17 14:08:55 -04:00
2023-08-17 14:08:55 -04:00
2023-06-29 12:57:34 -04:00
2023-06-29 12:57:34 -04:00
2023-06-29 12:57:34 -04:00
2023-06-29 12:57:34 -04:00
2023-06-29 12:57:34 -04:00
2023-03-01 03:12:22 -05:00
2023-09-20 15:57:32 -04:00

Malware Corpus

The MBC malware corpus comprises a variety of malware where each entry is decomposed into behaviors that are mapped to ATT&CK and MBC. The mappings are based on open source malware analysis reports and are separated into three categories: "ATT&CK Techniques," "Enhanced ATT&CK Techniques," and "MBC Behaviors."

ATT&CK Techniques - If a malware entry is not included in ATT&CK's software collection, then all ATT&CK techniques to which its malware behaviors map are listed. If a malware entry is included in ATT&CK's software collection, then the corresponding software page is referenced under "ATT&CK Techniques" (individual mappings not captured in ATT&CK are still listed). These techniques have T identifiers (e.g., T1012).

Enhanced ATT&CK Techniques - Any ATT&CK techniques that would be listed under "ATT&CK Techniques" but have been enhanced in MBC are listed in this section instead. These techniques have E and F identifiers (e.g., E1560, F0008).

MBC Behaviors - This section lists all MBC behaviors to which an entry's malware behaviors map. These techniques have B and C identifiers (e.g., B0032, C0010).

Please see Poison-Ivy X0014 and Kovter X0009 for examples of malware samples included and not included in ATT&CK's collection, respectively.

Also, please see the FAQ for information about malware entries that illustrate the use of MBC in Attack Flow and CACAO.