mirror of
https://github.com/MISP/misp-galaxy.git
synced 2024-11-22 23:07:19 +00:00
jq all the things
This commit is contained in:
parent
b50e057925
commit
fd9919e67a
30 changed files with 32705 additions and 32902 deletions
File diff suppressed because one or more lines are too long
File diff suppressed because it is too large
Load diff
File diff suppressed because it is too large
Load diff
File diff suppressed because it is too large
Load diff
File diff suppressed because it is too large
Load diff
File diff suppressed because it is too large
Load diff
File diff suppressed because it is too large
Load diff
|
@ -1,97 +1,83 @@
|
||||||
{
|
{
|
||||||
"name": "Mobile Attack - Course of Action",
|
"name": "Mobile Attack - Course of Action",
|
||||||
"type": "mitre-mobile-attack-course-of-action",
|
"type": "mitre-mobile-attack-course-of-action",
|
||||||
"description": "ATT&CK Mitigation",
|
"description": "ATT&CK Mitigation",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"source": "https://github.com/mitre/cti",
|
"source": "https://github.com/mitre/cti",
|
||||||
"uuid": "03956f9e-1708-11e8-8395-976b24233e15",
|
"uuid": "03956f9e-1708-11e8-8395-976b24233e15",
|
||||||
"authors": [
|
"authors": [
|
||||||
"MITRE"
|
"MITRE"
|
||||||
],
|
],
|
||||||
"values": [
|
"values": [
|
||||||
{
|
{
|
||||||
"description": "A variety of methods exist that can be used to enable enterprises to identify compromised (e.g. rooted/jailbroken) devices, whether using security mechanisms built directly into the device, third-party mobile security applications, enterprise mobility management (EMM)/mobile device management (MDM) capabilities, or other methods. Some methods may be trivial to evade while others may be more sophisticated.",
|
"description": "A variety of methods exist that can be used to enable enterprises to identify compromised (e.g. rooted/jailbroken) devices, whether using security mechanisms built directly into the device, third-party mobile security applications, enterprise mobility management (EMM)/mobile device management (MDM) capabilities, or other methods. Some methods may be trivial to evade while others may be more sophisticated.",
|
||||||
"value": "Deploy Compromised Device Detection Method",
|
"value": "Deploy Compromised Device Detection Method",
|
||||||
"meta": {},
|
"uuid": "cf2cccb1-cab8-431a-8ecf-f7874d05f433"
|
||||||
"uuid": "cf2cccb1-cab8-431a-8ecf-f7874d05f433"
|
},
|
||||||
},
|
{
|
||||||
{
|
"description": "In order to mitigate Signaling System 7 (SS7) exploitation, the Communications, Security, Reliability, and Interoperability Council (CSRIC) describes filtering interconnections between network operators to block inappropriate requests (Citation: CSRIC5-WG10-FinalReport).",
|
||||||
"description": "In order to mitigate Signaling System 7 (SS7) exploitation, the Communications, Security, Reliability, and Interoperability Council (CSRIC) describes filtering interconnections between network operators to block inappropriate requests (Citation: CSRIC5-WG10-FinalReport).",
|
"value": "Interconnection Filtering",
|
||||||
"value": "Interconnection Filtering",
|
"uuid": "e829ee51-1caf-4665-ba15-7f8979634124"
|
||||||
"meta": {},
|
},
|
||||||
"uuid": "e829ee51-1caf-4665-ba15-7f8979634124"
|
{
|
||||||
},
|
"description": "Application developers should use device-provided credential storage mechanisms such as Android's KeyStore or iOS's KeyChain. These can prevent credentials from being exposed to an adversary.",
|
||||||
{
|
"value": "Use Device-Provided Credential Storage",
|
||||||
"description": "Application developers should use device-provided credential storage mechanisms such as Android's KeyStore or iOS's KeyChain. These can prevent credentials from being exposed to an adversary.",
|
"uuid": "d2a199d2-dfea-4d0c-987d-6195ed17be9c"
|
||||||
"value": "Use Device-Provided Credential Storage",
|
},
|
||||||
"meta": {},
|
{
|
||||||
"uuid": "d2a199d2-dfea-4d0c-987d-6195ed17be9c"
|
"description": "New mobile operating system versions bring not only patches against discovered vulnerabilities but also often bring security architecture improvements that provide resilience against potential vulnerabilities or weaknesses that have not yet been discovered. They may also bring improvements that block use of observed adversary techniques.",
|
||||||
},
|
"value": "Use Recent OS Version",
|
||||||
{
|
"uuid": "0beabf44-e8d8-4ae4-9122-ef56369a2564"
|
||||||
"description": "New mobile operating system versions bring not only patches against discovered vulnerabilities but also often bring security architecture improvements that provide resilience against potential vulnerabilities or weaknesses that have not yet been discovered. They may also bring improvements that block use of observed adversary techniques.",
|
},
|
||||||
"value": "Use Recent OS Version",
|
{
|
||||||
"meta": {},
|
"description": "Install security updates in response to discovered vulnerabilities.\n\nPurchase devices with a vendor and/or mobile carrier commitment to provide security updates in a prompt manner for a set period of time.\n\nDecommission devices that will no longer receive security updates.\n\nLimit or block access to enterprise resources from devices that have not installed recent security updates.\n* On Android devices, access can be controlled based on each device's security patch level.\n* On iOS devices, access can be controlled based on the iOS version.",
|
||||||
"uuid": "0beabf44-e8d8-4ae4-9122-ef56369a2564"
|
"value": "Security Updates",
|
||||||
},
|
"uuid": "bcecd036-f40e-4916-9f8e-fd0ccf0ece8d"
|
||||||
{
|
},
|
||||||
"description": "Install security updates in response to discovered vulnerabilities.\n\nPurchase devices with a vendor and/or mobile carrier commitment to provide security updates in a prompt manner for a set period of time.\n\nDecommission devices that will no longer receive security updates.\n\nLimit or block access to enterprise resources from devices that have not installed recent security updates.\n* On Android devices, access can be controlled based on each device's security patch level.\n* On iOS devices, access can be controlled based on the iOS version.",
|
{
|
||||||
"value": "Security Updates",
|
"description": "On devices that provide the capability to unlock the bootloader (hence allowing any operating system code to be flashed onto the device), perform periodic checks to ensure that the bootloader is locked.",
|
||||||
"meta": {},
|
"value": "Lock Bootloader",
|
||||||
"uuid": "bcecd036-f40e-4916-9f8e-fd0ccf0ece8d"
|
"uuid": "8ccd428d-39da-4e8f-a55b-d48ea1d56e58"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"description": "On devices that provide the capability to unlock the bootloader (hence allowing any operating system code to be flashed onto the device), perform periodic checks to ensure that the bootloader is locked.",
|
"description": "Ensure that Android devices being used include and enable the Verified Boot capability, which cryptographically ensures the integrity of the system partition.",
|
||||||
"value": "Lock Bootloader",
|
"value": "System Partition Integrity",
|
||||||
"meta": {},
|
"uuid": "7b1cf46f-784b-405a-a8dd-4624c19d8321"
|
||||||
"uuid": "8ccd428d-39da-4e8f-a55b-d48ea1d56e58"
|
},
|
||||||
},
|
{
|
||||||
{
|
"description": "Enable remote attestation capabilities when available (such as Android SafetyNet or Samsung Knox TIMA Attestation) and prohibit devices that fail the attestation from accessing enterprise resources.",
|
||||||
"description": "Ensure that Android devices being used include and enable the Verified Boot capability, which cryptographically ensures the integrity of the system partition.",
|
"value": "Attestation",
|
||||||
"value": "System Partition Integrity",
|
"uuid": "ff4821f6-5afb-481b-8c0f-26c28c0d666c"
|
||||||
"meta": {},
|
},
|
||||||
"uuid": "7b1cf46f-784b-405a-a8dd-4624c19d8321"
|
{
|
||||||
},
|
"description": "Warn device users not to accept requests to grant Device Administrator access to applications without good reason.\n\nAdditionally, application vetting should include a check on whether the application requests Device Administrator access. Applications that do request Device Administrator access should be carefully scrutinized and only allowed to be used if a valid reason exists.",
|
||||||
{
|
"value": "Caution with Device Administrator Access",
|
||||||
"description": "Enable remote attestation capabilities when available (such as Android SafetyNet or Samsung Knox TIMA Attestation) and prohibit devices that fail the attestation from accessing enterprise resources.",
|
"uuid": "e944670c-d03a-4e93-a21c-b3d4c53ec4c9"
|
||||||
"value": "Attestation",
|
},
|
||||||
"meta": {},
|
{
|
||||||
"uuid": "ff4821f6-5afb-481b-8c0f-26c28c0d666c"
|
"description": "This mitigation describes any guidance or training given to developers of applications to avoid introducing security weaknesses that an adversary may be able to take advantage of.",
|
||||||
},
|
"value": "Application Developer Guidance",
|
||||||
{
|
"uuid": "25dc1ce8-eb55-4333-ae30-a7cb4f5894a1"
|
||||||
"description": "Warn device users not to accept requests to grant Device Administrator access to applications without good reason.\n\nAdditionally, application vetting should include a check on whether the application requests Device Administrator access. Applications that do request Device Administrator access should be carefully scrutinized and only allowed to be used if a valid reason exists.",
|
},
|
||||||
"value": "Caution with Device Administrator Access",
|
{
|
||||||
"meta": {},
|
"description": "Enterprises can vet applications for exploitable vulnerabilities or unwanted (privacy-invasive or malicious) behaviors. Enterprises can inspect applications themselves or use a third-party service.\n\nEnterprises may impose policies to only allow pre-approved applications to be installed on their devices or may impose policies to block use of specific applications known to have issues. In Bring Your Own Device (BYOD) environments, enterprises may only be able to impose these policies over an enterprise-managed portion of the device.\n\nApplication Vetting is not a complete mitigation. Techniques such as Detect App Analysis Environment exist that can enable adversaries to bypass vetting.",
|
||||||
"uuid": "e944670c-d03a-4e93-a21c-b3d4c53ec4c9"
|
"value": "Application Vetting",
|
||||||
},
|
"uuid": "1553b156-6767-47f7-9eb4-2a692505666d"
|
||||||
{
|
},
|
||||||
"description": "This mitigation describes any guidance or training given to developers of applications to avoid introducing security weaknesses that an adversary may be able to take advantage of.",
|
{
|
||||||
"value": "Application Developer Guidance",
|
"description": "Describes any guidance or training given to users to set particular configuration settings or avoid specific potentially risky behaviors.",
|
||||||
"meta": {},
|
"value": "User Guidance",
|
||||||
"uuid": "25dc1ce8-eb55-4333-ae30-a7cb4f5894a1"
|
"uuid": "653492e3-27be-4a0e-b08c-938dd2b7e0e1"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"description": "Enterprises can vet applications for exploitable vulnerabilities or unwanted (privacy-invasive or malicious) behaviors. Enterprises can inspect applications themselves or use a third-party service.\n\nEnterprises may impose policies to only allow pre-approved applications to be installed on their devices or may impose policies to block use of specific applications known to have issues. In Bring Your Own Device (BYOD) environments, enterprises may only be able to impose these policies over an enterprise-managed portion of the device.\n\nApplication Vetting is not a complete mitigation. Techniques such as Detect App Analysis Environment exist that can enable adversaries to bypass vetting.",
|
"description": "An enterprise mobility management (EMM), also known as mobile device management (MDM), system can be used to provision policies to mobile devices to control aspects of their allowed behavior.",
|
||||||
"value": "Application Vetting",
|
"value": "Enterprise Policy",
|
||||||
"meta": {},
|
"uuid": "649f7268-4c12-483b-ac84-4b7bca9fe2ee"
|
||||||
"uuid": "1553b156-6767-47f7-9eb4-2a692505666d"
|
},
|
||||||
},
|
{
|
||||||
{
|
"description": "Application developers should encrypt all of their application network traffic using the Transport Layer Security (TLS) protocol to ensure protection of sensitive data and deter network-based attacks. If desired, application developers could perform message-based encryption of data before passing it for TLS encryption.\n\niOS's App Transport Security feature can be used to help ensure that all application network traffic is appropriately protected. Apple intends to mandate use of App Transport Security (Citation: TechCrunch-ATS) for all apps in the Apple App Store unless appropriate justification is given.\n\nAndroid's Network Security Configuration feature similarly can be used by app developers to help ensure that all of their application network traffic is appropriately protected (Citation: Android-NetworkSecurityConfig).\n\nUse of Virtual Private Network (VPN) tunnels, e.g. using the IPsec protocol, can help mitigate some types of network attacks as well.",
|
||||||
"description": "Describes any guidance or training given to users to set particular configuration settings or avoid specific potentially risky behaviors.",
|
"value": "Encrypt Network Traffic",
|
||||||
"value": "User Guidance",
|
"uuid": "8220b57e-c400-4525-bf69-f8edc6b389a8"
|
||||||
"meta": {},
|
}
|
||||||
"uuid": "653492e3-27be-4a0e-b08c-938dd2b7e0e1"
|
]
|
||||||
},
|
}
|
||||||
{
|
|
||||||
"description": "An enterprise mobility management (EMM), also known as mobile device management (MDM), system can be used to provision policies to mobile devices to control aspects of their allowed behavior.",
|
|
||||||
"value": "Enterprise Policy",
|
|
||||||
"meta": {},
|
|
||||||
"uuid": "649f7268-4c12-483b-ac84-4b7bca9fe2ee"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"description": "Application developers should encrypt all of their application network traffic using the Transport Layer Security (TLS) protocol to ensure protection of sensitive data and deter network-based attacks. If desired, application developers could perform message-based encryption of data before passing it for TLS encryption.\n\niOS's App Transport Security feature can be used to help ensure that all application network traffic is appropriately protected. Apple intends to mandate use of App Transport Security (Citation: TechCrunch-ATS) for all apps in the Apple App Store unless appropriate justification is given.\n\nAndroid's Network Security Configuration feature similarly can be used by app developers to help ensure that all of their application network traffic is appropriately protected (Citation: Android-NetworkSecurityConfig).\n\nUse of Virtual Private Network (VPN) tunnels, e.g. using the IPsec protocol, can help mitigate some types of network attacks as well.",
|
|
||||||
"value": "Encrypt Network Traffic",
|
|
||||||
"meta": {},
|
|
||||||
"uuid": "8220b57e-c400-4525-bf69-f8edc6b389a8"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
|
|
|
@ -1,37 +1,37 @@
|
||||||
{
|
{
|
||||||
"name": "Mobile Attack - intrusion Set",
|
"name": "Mobile Attack - intrusion Set",
|
||||||
"type": "mitre-mobile-attack-intrusion-set",
|
"type": "mitre-mobile-attack-intrusion-set",
|
||||||
"description": "Name of ATT&CK Group",
|
"description": "Name of ATT&CK Group",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"source": "https://github.com/mitre/cti",
|
"source": "https://github.com/mitre/cti",
|
||||||
"uuid": "02ab4018-1708-11e8-8f9d-e735aabdfa53",
|
"uuid": "02ab4018-1708-11e8-8f9d-e735aabdfa53",
|
||||||
"authors": [
|
"authors": [
|
||||||
"MITRE"
|
"MITRE"
|
||||||
],
|
],
|
||||||
"values": [
|
"values": [
|
||||||
{
|
{
|
||||||
"description": "APT28 is a threat group that has been attributed to the Russian government. (Citation: FireEye APT28) (Citation: SecureWorks TG-4127) (Citation: FireEye APT28) January 2017 (Citation: GRIZZLY STEPPE JAR) This group reportedly compromised the Democratic National Committee in April 2016. (Citation: Crowdstrike DNC June 2016)",
|
"description": "APT28 is a threat group that has been attributed to the Russian government. (Citation: FireEye APT28) (Citation: SecureWorks TG-4127) (Citation: FireEye APT28) January 2017 (Citation: GRIZZLY STEPPE JAR) This group reportedly compromised the Democratic National Committee in April 2016. (Citation: Crowdstrike DNC June 2016)",
|
||||||
"value": "APT28",
|
"value": "APT28",
|
||||||
"meta": {
|
"meta": {
|
||||||
"synonyms": [
|
"synonyms": [
|
||||||
"APT28",
|
"APT28",
|
||||||
"Sednit",
|
"Sednit",
|
||||||
"Sofacy",
|
"Sofacy",
|
||||||
"Pawn Storm",
|
"Pawn Storm",
|
||||||
"Fancy Bear",
|
"Fancy Bear",
|
||||||
"STRONTIUM",
|
"STRONTIUM",
|
||||||
"Tsar Team",
|
"Tsar Team",
|
||||||
"Threat Group-4127",
|
"Threat Group-4127",
|
||||||
"TG-4127"
|
"TG-4127"
|
||||||
],
|
],
|
||||||
"refs": [
|
"refs": [
|
||||||
"https://attack.mitre.org/wiki/Group/G0007",
|
"https://attack.mitre.org/wiki/Group/G0007",
|
||||||
"https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/",
|
"https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/",
|
||||||
"https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf",
|
"https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf",
|
||||||
"https://www.secureworks.com/research/threat-group-4127-targets-hillary-clinton-presidential-campaign"
|
"https://www.secureworks.com/research/threat-group-4127-targets-hillary-clinton-presidential-campaign"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"uuid": "bef4c620-0787-42a8-a96d-b7eb6e85917c"
|
"uuid": "bef4c620-0787-42a8-a96d-b7eb6e85917c"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|
File diff suppressed because it is too large
Load diff
File diff suppressed because it is too large
Load diff
|
@ -1,27 +1,27 @@
|
||||||
{
|
{
|
||||||
"name": "Mobile Attack - Tool",
|
"name": "Mobile Attack - Tool",
|
||||||
"type": "mitre-mobile-attack-tool",
|
"type": "mitre-mobile-attack-tool",
|
||||||
"description": "Name of ATT&CK software",
|
"description": "Name of ATT&CK software",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"source": "https://github.com/mitre/cti",
|
"source": "https://github.com/mitre/cti",
|
||||||
"uuid": "02cee87e-1708-11e8-8f15-8b33e4d6194b",
|
"uuid": "02cee87e-1708-11e8-8f15-8b33e4d6194b",
|
||||||
"authors": [
|
"authors": [
|
||||||
"MITRE"
|
"MITRE"
|
||||||
],
|
],
|
||||||
"values": [
|
"values": [
|
||||||
{
|
{
|
||||||
"description": "Xbot is a family of Android malware analyzed by Palo Alto Networks (Citation: PaloAlto-Xbot) that \"tries to steal victims' banking credentials and credit card information\", \"can also remotely lock infected Android devices, encrypt the user's files in external storage (e.g., SD card), and then ask for a U.S. $100 PayPal cash card as ransom\" and \"will steal all SMS message and contact information, intercept certain SMS messages, and parse SMS messages for mTANs (Mobile Transaction Authentication Number) from banks.\"\n\nAliases: Xbot",
|
"description": "Xbot is a family of Android malware analyzed by Palo Alto Networks (Citation: PaloAlto-Xbot) that \"tries to steal victims' banking credentials and credit card information\", \"can also remotely lock infected Android devices, encrypt the user's files in external storage (e.g., SD card), and then ask for a U.S. $100 PayPal cash card as ransom\" and \"will steal all SMS message and contact information, intercept certain SMS messages, and parse SMS messages for mTANs (Mobile Transaction Authentication Number) from banks.\"\n\nAliases: Xbot",
|
||||||
"value": "Xbot",
|
"value": "Xbot",
|
||||||
"meta": {
|
"meta": {
|
||||||
"refs": [
|
"refs": [
|
||||||
"https://attack.mitre.org/mobile/index.php/Software/MOB-S0014",
|
"https://attack.mitre.org/mobile/index.php/Software/MOB-S0014",
|
||||||
"http://researchcenter.paloaltonetworks.com/2016/02/new-android-trojan-xbot-phishes-credit-cards-and-bank-accounts-encrypts-devices-for-ransom/"
|
"http://researchcenter.paloaltonetworks.com/2016/02/new-android-trojan-xbot-phishes-credit-cards-and-bank-accounts-encrypts-devices-for-ransom/"
|
||||||
],
|
],
|
||||||
"synonyms": [
|
"synonyms": [
|
||||||
"Xbot"
|
"Xbot"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"uuid": "da21929e-40c0-443d-bdf4-6b60d15448b4"
|
"uuid": "da21929e-40c0-443d-bdf4-6b60d15448b4"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|
File diff suppressed because it is too large
Load diff
|
@ -1,132 +1,132 @@
|
||||||
{
|
{
|
||||||
"name": "Pre Attack - intrusion Set",
|
"name": "Pre Attack - intrusion Set",
|
||||||
"type": "mitre-pre-attack-intrusion-set",
|
"type": "mitre-pre-attack-intrusion-set",
|
||||||
"description": "Name of ATT&CK Group",
|
"description": "Name of ATT&CK Group",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"source": "https://github.com/mitre/cti",
|
"source": "https://github.com/mitre/cti",
|
||||||
"uuid": "1fdc8fa2-1708-11e8-99a3-67b4efc13c4f",
|
"uuid": "1fdc8fa2-1708-11e8-99a3-67b4efc13c4f",
|
||||||
"authors": [
|
"authors": [
|
||||||
"MITRE"
|
"MITRE"
|
||||||
],
|
],
|
||||||
"values": [
|
"values": [
|
||||||
{
|
{
|
||||||
"description": "APT16 is a China-based threat group that has launched spearphishing campaigns targeting Japanese and Taiwanese organizations. (Citation: FireEye EPS Awakens Part 2)",
|
"description": "APT16 is a China-based threat group that has launched spearphishing campaigns targeting Japanese and Taiwanese organizations. (Citation: FireEye EPS Awakens Part 2)",
|
||||||
"value": "APT16",
|
"value": "APT16",
|
||||||
"meta": {
|
"meta": {
|
||||||
"synonyms": [
|
"synonyms": [
|
||||||
"APT16"
|
"APT16"
|
||||||
],
|
],
|
||||||
"refs": [
|
"refs": [
|
||||||
"https://attack.mitre.org/wiki/Group/G0023",
|
"https://attack.mitre.org/wiki/Group/G0023",
|
||||||
"https://www.fireeye.com/blog/threat-research/2015/12/the-eps-awakens-part-two.html"
|
"https://www.fireeye.com/blog/threat-research/2015/12/the-eps-awakens-part-two.html"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"uuid": "d6e88e18-81e8-4709-82d8-973095da1e70"
|
"uuid": "d6e88e18-81e8-4709-82d8-973095da1e70"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"description": "APT28 is a threat group that has been attributed to the Russian government. (Citation: FireEye APT28) (Citation: SecureWorks TG-4127) (Citation: FireEye APT28) January 2017 (Citation: GRIZZLY STEPPE JAR) This group reportedly compromised the Democratic National Committee in April 2016. (Citation: Crowdstrike DNC June 2016)",
|
"description": "APT28 is a threat group that has been attributed to the Russian government. (Citation: FireEye APT28) (Citation: SecureWorks TG-4127) (Citation: FireEye APT28) January 2017 (Citation: GRIZZLY STEPPE JAR) This group reportedly compromised the Democratic National Committee in April 2016. (Citation: Crowdstrike DNC June 2016)",
|
||||||
"value": "APT28",
|
"value": "APT28",
|
||||||
"meta": {
|
"meta": {
|
||||||
"synonyms": [
|
"synonyms": [
|
||||||
"APT28",
|
"APT28",
|
||||||
"Sednit",
|
"Sednit",
|
||||||
"Sofacy",
|
"Sofacy",
|
||||||
"Pawn Storm",
|
"Pawn Storm",
|
||||||
"Fancy Bear",
|
"Fancy Bear",
|
||||||
"STRONTIUM",
|
"STRONTIUM",
|
||||||
"Tsar Team",
|
"Tsar Team",
|
||||||
"Threat Group-4127",
|
"Threat Group-4127",
|
||||||
"TG-4127"
|
"TG-4127"
|
||||||
],
|
],
|
||||||
"refs": [
|
"refs": [
|
||||||
"https://attack.mitre.org/wiki/Group/G0007",
|
"https://attack.mitre.org/wiki/Group/G0007",
|
||||||
"https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/",
|
"https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/",
|
||||||
"https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf",
|
"https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/rpt-apt28.pdf",
|
||||||
"https://www.secureworks.com/research/threat-group-4127-targets-hillary-clinton-presidential-campaign"
|
"https://www.secureworks.com/research/threat-group-4127-targets-hillary-clinton-presidential-campaign"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"uuid": "bef4c620-0787-42a8-a96d-b7eb6e85917c"
|
"uuid": "bef4c620-0787-42a8-a96d-b7eb6e85917c"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"description": "Cleaver is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver. (Citation: Cylance Cleaver) Strong circumstantial evidence suggests Cleaver is linked to Threat Group 2889 (TG-2889). (Citation: Dell Threat Group 2889)",
|
"description": "Cleaver is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver. (Citation: Cylance Cleaver) Strong circumstantial evidence suggests Cleaver is linked to Threat Group 2889 (TG-2889). (Citation: Dell Threat Group 2889)",
|
||||||
"value": "Cleaver",
|
"value": "Cleaver",
|
||||||
"meta": {
|
"meta": {
|
||||||
"synonyms": [
|
"synonyms": [
|
||||||
"Cleaver",
|
"Cleaver",
|
||||||
"TG-2889",
|
"TG-2889",
|
||||||
"Threat Group 2889"
|
"Threat Group 2889"
|
||||||
],
|
],
|
||||||
"refs": [
|
"refs": [
|
||||||
"https://attack.mitre.org/wiki/Group/G0003",
|
"https://attack.mitre.org/wiki/Group/G0003",
|
||||||
"https://www.cylance.com/content/dam/cylance/pages/operation-cleaver/Cylance%20Operation%20Cleaver%20Report.pdf",
|
"https://www.cylance.com/content/dam/cylance/pages/operation-cleaver/Cylance%20Operation%20Cleaver%20Report.pdf",
|
||||||
"http://www.secureworks.com/cyber-threat-intelligence/threats/suspected-iran-based-hacker-group-creates-network-of-fake-linkedin-profiles/"
|
"http://www.secureworks.com/cyber-threat-intelligence/threats/suspected-iran-based-hacker-group-creates-network-of-fake-linkedin-profiles/"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"uuid": "8f5e8dc7-739d-4f5e-a8a1-a66e004d7063"
|
"uuid": "8f5e8dc7-739d-4f5e-a8a1-a66e004d7063"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"description": "APT12 is a threat group that has been attributed to China. (Citation: Meyers Numbered Panda)",
|
"description": "APT12 is a threat group that has been attributed to China. (Citation: Meyers Numbered Panda)",
|
||||||
"value": "APT12",
|
"value": "APT12",
|
||||||
"meta": {
|
"meta": {
|
||||||
"synonyms": [
|
"synonyms": [
|
||||||
"APT12",
|
"APT12",
|
||||||
"IXESHE",
|
"IXESHE",
|
||||||
"DynCalc",
|
"DynCalc",
|
||||||
"Numbered Panda",
|
"Numbered Panda",
|
||||||
"DNSCALC"
|
"DNSCALC"
|
||||||
],
|
],
|
||||||
"refs": [
|
"refs": [
|
||||||
"https://attack.mitre.org/wiki/Group/G0005",
|
"https://attack.mitre.org/wiki/Group/G0005",
|
||||||
"http://www.crowdstrike.com/blog/whois-numbered-panda/"
|
"http://www.crowdstrike.com/blog/whois-numbered-panda/"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"uuid": "c47f937f-1022-4f42-8525-e7a4779a14cb"
|
"uuid": "c47f937f-1022-4f42-8525-e7a4779a14cb"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"description": "APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People\u2019s Liberation Army (PLA) General Staff Department\u2019s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398. (Citation: Mandiant APT1)",
|
"description": "APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398. (Citation: Mandiant APT1)",
|
||||||
"value": "APT1",
|
"value": "APT1",
|
||||||
"meta": {
|
"meta": {
|
||||||
"synonyms": [
|
"synonyms": [
|
||||||
"APT1",
|
"APT1",
|
||||||
"Comment Crew",
|
"Comment Crew",
|
||||||
"Comment Group",
|
"Comment Group",
|
||||||
"Comment Panda"
|
"Comment Panda"
|
||||||
],
|
],
|
||||||
"refs": [
|
"refs": [
|
||||||
"https://attack.mitre.org/wiki/Group/G0006",
|
"https://attack.mitre.org/wiki/Group/G0006",
|
||||||
"https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf"
|
"https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"uuid": "6a2e693f-24e5-451a-9f88-b36a108e5662"
|
"uuid": "6a2e693f-24e5-451a-9f88-b36a108e5662"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"description": "Night Dragon is a threat group that has conducted activity originating primarily in China. (Citation: McAfee Night Dragon)",
|
"description": "Night Dragon is a threat group that has conducted activity originating primarily in China. (Citation: McAfee Night Dragon)",
|
||||||
"value": "Night Dragon",
|
"value": "Night Dragon",
|
||||||
"meta": {
|
"meta": {
|
||||||
"synonyms": [
|
"synonyms": [
|
||||||
"Night Dragon"
|
"Night Dragon"
|
||||||
],
|
],
|
||||||
"refs": [
|
"refs": [
|
||||||
"https://attack.mitre.org/wiki/Group/G0014",
|
"https://attack.mitre.org/wiki/Group/G0014",
|
||||||
"http://www.mcafee.com/us/resources/white-papers/wp-global-energy-cyberattacks-night-dragon.pdf"
|
"http://www.mcafee.com/us/resources/white-papers/wp-global-energy-cyberattacks-night-dragon.pdf"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"uuid": "23b6a0f5-fa95-46f9-a6f3-4549c5e45ec8"
|
"uuid": "23b6a0f5-fa95-46f9-a6f3-4549c5e45ec8"
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"description": "APT17 is a China-based threat group that has conducted network intrusions against U.S. government entities, the defense industry, law firms, information technology companies, mining companies, and non-government organizations. (Citation: FireEye APT17)",
|
"description": "APT17 is a China-based threat group that has conducted network intrusions against U.S. government entities, the defense industry, law firms, information technology companies, mining companies, and non-government organizations. (Citation: FireEye APT17)",
|
||||||
"value": "APT17",
|
"value": "APT17",
|
||||||
"meta": {
|
"meta": {
|
||||||
"synonyms": [
|
"synonyms": [
|
||||||
"APT17",
|
"APT17",
|
||||||
"Deputy Dog"
|
"Deputy Dog"
|
||||||
],
|
],
|
||||||
"refs": [
|
"refs": [
|
||||||
"https://attack.mitre.org/wiki/Group/G0025",
|
"https://attack.mitre.org/wiki/Group/G0025",
|
||||||
"https://www2.fireeye.com/rs/fireye/images/APT17%20Report.pdf"
|
"https://www2.fireeye.com/rs/fireye/images/APT17%20Report.pdf"
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
"uuid": "090242d7-73fc-4738-af68-20162f7a5aae"
|
"uuid": "090242d7-73fc-4738-af68-20162f7a5aae"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|
File diff suppressed because it is too large
Load diff
|
@ -1,8 +1,8 @@
|
||||||
{
|
{
|
||||||
"name": "Entreprise Attack - Attack Pattern",
|
"name": "Entreprise Attack - Attack Pattern",
|
||||||
"type": "mitre-entreprise-attack-attack-pattern",
|
"type": "mitre-entreprise-attack-attack-pattern",
|
||||||
"description": "ATT&CK Tactic",
|
"description": "ATT&CK Tactic",
|
||||||
"uuid": "fa7016a8-1707-11e8-82d0-1b73d76eb204",
|
"uuid": "fa7016a8-1707-11e8-82d0-1b73d76eb204",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"icon": "map"
|
"icon": "map"
|
||||||
}
|
}
|
||||||
|
|
|
@ -1,8 +1,8 @@
|
||||||
{
|
{
|
||||||
"name": "Entreprise Attack - Course of Action",
|
"name": "Entreprise Attack - Course of Action",
|
||||||
"type": "mitre-entreprise-attack-course-of-action",
|
"type": "mitre-entreprise-attack-course-of-action",
|
||||||
"description": "ATT&CK Mitigation",
|
"description": "ATT&CK Mitigation",
|
||||||
"uuid": "fb5a36c0-1707-11e8-81f5-d732b22a4982",
|
"uuid": "fb5a36c0-1707-11e8-81f5-d732b22a4982",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"icon": "chain"
|
"icon": "chain"
|
||||||
}
|
}
|
||||||
|
|
|
@ -1,8 +1,8 @@
|
||||||
{
|
{
|
||||||
"name": "Entreprise Attack -Intrusion Set",
|
"name": "Entreprise Attack -Intrusion Set",
|
||||||
"type": "mitre-entreprise-attack-intrusion-set",
|
"type": "mitre-entreprise-attack-intrusion-set",
|
||||||
"description": "Name of ATT&CK Group",
|
"description": "Name of ATT&CK Group",
|
||||||
"uuid": "1f3b8c56-1708-11e8-b211-17a60c0f73ee",
|
"uuid": "1f3b8c56-1708-11e8-b211-17a60c0f73ee",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"icon": "user-secret"
|
"icon": "user-secret"
|
||||||
}
|
}
|
||||||
|
|
|
@ -1,8 +1,8 @@
|
||||||
{
|
{
|
||||||
"name": "Entreprise Attack - Malware",
|
"name": "Entreprise Attack - Malware",
|
||||||
"type": "mitre-entreprise-attack-malware",
|
"type": "mitre-entreprise-attack-malware",
|
||||||
"description": "Name of ATT&CK software",
|
"description": "Name of ATT&CK software",
|
||||||
"uuid": "fbb19af0-1707-11e8-9fd6-dbd88a04d33a",
|
"uuid": "fbb19af0-1707-11e8-9fd6-dbd88a04d33a",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"icon": "optin-monster"
|
"icon": "optin-monster"
|
||||||
}
|
}
|
||||||
|
|
|
@ -1,8 +1,8 @@
|
||||||
{
|
{
|
||||||
"name": "Entreprise Attack - Relationship",
|
"name": "Entreprise Attack - Relationship",
|
||||||
"type": "mitre-entreprise-attack-relationship",
|
"type": "mitre-entreprise-attack-relationship",
|
||||||
"description": "Mitre Relationship",
|
"description": "Mitre Relationship",
|
||||||
"uuid": "fc404638-1707-11e8-a5cf-b78b9b562766",
|
"uuid": "fc404638-1707-11e8-a5cf-b78b9b562766",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"icon": "link"
|
"icon": "link"
|
||||||
}
|
}
|
||||||
|
|
|
@ -1,8 +1,8 @@
|
||||||
{
|
{
|
||||||
"name": "Entreprise Attack - Tool",
|
"name": "Entreprise Attack - Tool",
|
||||||
"type": "mitre-entreprise-attack-tool",
|
"type": "mitre-entreprise-attack-tool",
|
||||||
"description": "Name of ATT&CK software",
|
"description": "Name of ATT&CK software",
|
||||||
"uuid": "fbfa0470-1707-11e8-be22-eb46b373fdd3",
|
"uuid": "fbfa0470-1707-11e8-be22-eb46b373fdd3",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"icon": "gavel"
|
"icon": "gavel"
|
||||||
}
|
}
|
||||||
|
|
|
@ -1,8 +1,8 @@
|
||||||
{
|
{
|
||||||
"name": "Mobile Attack - Attack Pattern",
|
"name": "Mobile Attack - Attack Pattern",
|
||||||
"type": "mitre-mobile-attack-attack-pattern",
|
"type": "mitre-mobile-attack-attack-pattern",
|
||||||
"description": "ATT&CK Tactic",
|
"description": "ATT&CK Tactic",
|
||||||
"uuid": "1c6d1332-1708-11e8-847c-e3c5643c41a5",
|
"uuid": "1c6d1332-1708-11e8-847c-e3c5643c41a5",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"icon": "map"
|
"icon": "map"
|
||||||
}
|
}
|
||||||
|
|
|
@ -1,8 +1,8 @@
|
||||||
{
|
{
|
||||||
"name": "Mobile Attack - Course of Action",
|
"uuid": "0282356a-1708-11e8-8f53-975633d5c03c",
|
||||||
"type": "mitre-mobile-attack-course-of-action",
|
"description": "ATT&CK Mitigation",
|
||||||
"description": "ATT&CK Mitigation",
|
"version": 1,
|
||||||
"uuid": "0282356a-1708-11e8-8f53-975633d5c03c",
|
"icon": "chain",
|
||||||
"version": 1,
|
"type": "mitre-mobile-attack-course-of-action",
|
||||||
"icon": "chain"
|
"name": "Mobile Attack - Course of Action"
|
||||||
}
|
}
|
||||||
|
|
|
@ -1,8 +1,8 @@
|
||||||
{
|
{
|
||||||
"name": "Mobile Attack - Intrusion Set",
|
"name": "Mobile Attack - Intrusion Set",
|
||||||
"type": "mitre-mobile-attack-intrusion-set",
|
"type": "mitre-mobile-attack-intrusion-set",
|
||||||
"description": "Name of ATT&CK Group",
|
"description": "Name of ATT&CK Group",
|
||||||
"uuid": "0314e554-1708-11e8-b049-8f8a42b5bb62",
|
"uuid": "0314e554-1708-11e8-b049-8f8a42b5bb62",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"icon": "user-secret"
|
"icon": "user-secret"
|
||||||
}
|
}
|
||||||
|
|
|
@ -1,8 +1,8 @@
|
||||||
{
|
{
|
||||||
"name": "Mobile Attack - Malware",
|
"name": "Mobile Attack - Malware",
|
||||||
"type": "mitre-mobile-attack-malware",
|
"type": "mitre-mobile-attack-malware",
|
||||||
"description": "Name of ATT&CK software",
|
"description": "Name of ATT&CK software",
|
||||||
"uuid": "03e3853a-1708-11e8-95c1-67cf3f801a18",
|
"uuid": "03e3853a-1708-11e8-95c1-67cf3f801a18",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"icon": "optin-monster"
|
"icon": "optin-monster"
|
||||||
}
|
}
|
||||||
|
|
|
@ -1,8 +1,8 @@
|
||||||
{
|
{
|
||||||
"name": "Mobile Attack - Relationship",
|
"name": "Mobile Attack - Relationship",
|
||||||
"type": "mitre-mobile-attack-relationship",
|
"type": "mitre-mobile-attack-relationship",
|
||||||
"description": "Mitre Relationship",
|
"description": "Mitre Relationship",
|
||||||
"uuid": "fc8471aa-1707-11e8-b306-33cbe96a1ede",
|
"uuid": "fc8471aa-1707-11e8-b306-33cbe96a1ede",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"icon": "link"
|
"icon": "link"
|
||||||
}
|
}
|
||||||
|
|
|
@ -1,8 +1,8 @@
|
||||||
{
|
{
|
||||||
"name": "Mobile Attack - Tool",
|
"name": "Mobile Attack - Tool",
|
||||||
"type": "mitre-mobile-attack-tool",
|
"type": "mitre-mobile-attack-tool",
|
||||||
"description": "Name of ATT&CK software",
|
"description": "Name of ATT&CK software",
|
||||||
"uuid": "1d0b4bce-1708-11e8-9e6e-1b130c9b0a91",
|
"uuid": "1d0b4bce-1708-11e8-9e6e-1b130c9b0a91",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"icon": "gavel"
|
"icon": "gavel"
|
||||||
}
|
}
|
||||||
|
|
|
@ -1,8 +1,8 @@
|
||||||
{
|
{
|
||||||
"name": "Pre Attack - Attack Pattern",
|
"name": "Pre Attack - Attack Pattern",
|
||||||
"type": "mitre-pre-attack-attack-pattern",
|
"type": "mitre-pre-attack-attack-pattern",
|
||||||
"description": "ATT&CK Tactic",
|
"description": "ATT&CK Tactic",
|
||||||
"uuid": "1f665850-1708-11e8-9cfe-4792b2a91402",
|
"uuid": "1f665850-1708-11e8-9cfe-4792b2a91402",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"icon": "map"
|
"icon": "map"
|
||||||
}
|
}
|
||||||
|
|
|
@ -1,8 +1,8 @@
|
||||||
{
|
{
|
||||||
"name": "Pre Attack - Intrusion Set",
|
"name": "Pre Attack - Intrusion Set",
|
||||||
"type": "mitre-pre-attack-intrusion-set",
|
"type": "mitre-pre-attack-intrusion-set",
|
||||||
"description": "Name of ATT&CK Group",
|
"description": "Name of ATT&CK Group",
|
||||||
"uuid": "1fb6d5b4-1708-11e8-9836-8bbc8ce6866e",
|
"uuid": "1fb6d5b4-1708-11e8-9836-8bbc8ce6866e",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"icon": "user-secret"
|
"icon": "user-secret"
|
||||||
}
|
}
|
||||||
|
|
|
@ -1,8 +1,8 @@
|
||||||
{
|
{
|
||||||
"name": "Pre Attack - Relationship",
|
"name": "Pre Attack - Relationship",
|
||||||
"type": "mitre-pre-attack-relashipship",
|
"type": "mitre-pre-attack-relashipship",
|
||||||
"description": "Mitre Relationship",
|
"description": "Mitre Relationship",
|
||||||
"uuid": "1f8e3bae-1708-11e8-8e97-4bd2150e5aae",
|
"uuid": "1f8e3bae-1708-11e8-8e97-4bd2150e5aae",
|
||||||
"version": 1,
|
"version": 1,
|
||||||
"icon": "link"
|
"icon": "link"
|
||||||
}
|
}
|
||||||
|
|
Loading…
Reference in a new issue