
MITRE ATT&CK Framework के अपने API के माध्यम से इंटरैक्ट करने के लिए एक PowerShell स्क्रिप्ट
MITRE ATT&CK टीम @MITREattack द्वारा प्रदान की गई तकनीकों, रणनीतियों, समूहों, सॉफ्टवेयर और संदर्भों के बारे में जानकारी एकत्र करने के लिए अपने स्वयं के API के माध्यम से MITRE ATT&CK Framework के साथ इंटरैक्ट करने के लिए एक PowerShell स्क्रिप्ट। यह स्क्रिप्ट अभी भी अप्रचलित MEEDIAWIKI API का उपयोग कर रही है। इसे अभी तक सार्वजनिक TAXII सर्वर्स API का उपयोग करने के लिए अपडेट नहीं किया गया है
git clone https://github.com/Cyb3rWard0g/Invoke-ATTACKAPI.git cd Invoke-ATTACKAPI Import-Module .\Invoke-ATTACKAPI.ps1
/$$$$$$ /$$$$$$$$ /$$$$$$$$ /$$$ /$$$$$$ /$$ /$$ /$$$$$$ /$$$$$$$ /$$$$$$ /$$__ $$|__ $$/| $$//$$ $$ /$$ $$| $$ /$$/ /$$__ $$| $$__ $$|_ $$/ | $$ \ $$ | $$ | $$ | $$$ | $$ _/| $$ /$$/ | $$ \ $$| $$ \ $$ | $$ | $$$$$$$$ | $$ | $$ /$$ $$/$$| $$ | $$$$$/ | $$$$$$$$| $$$$$$$/ | $$ | $$__ $$ | $$ | $$ | $$ $$/| $$ | $$ $$ | $$__ $$| $$/ | $$ | $$ | $$ | $$ | $$ | $$\ $$ | $$ $$| $$\ $$ | $$ | $$| $$ | $$ | $$ | $$ | $$ | $$ | $$$$/$$| $$$$$$/| $$ \ $$ | $$ | $$| $$ /$$$$$$ |/ |/ |/ |/ _/_/ _/ |/ _/ |/ |/|/ |______/ V.0.9[BETA]
Adversarial Tactics, Techniques & Common Knowledge API
[*] Author: Roberto Rodriguez @Cyb3rWard0g
[++] Pulling MITRE ATT&CK Data
## उदाहरण
### यह क्वेरी सभी तकनीकों से मेल खाती है```
Invoke-ATTACKAPI -Category -Technique
ID : {T1001}
Bypass : {}
Contributor : {}
Requires System : {}
Data Source : {Packet capture, Process use of network, Process monitoring, Network protocol analysis}
Description : {Command and control (C2) communications are hidden (but not necessarily encrypted) in an
attempt to make the content more difficult to discover or decipher and to make the
communication less conspicuous and hide commands from being seen. This encompasses many
methods, such as adding junk data to protocol traffic, using steganography, commingling
legitimate traffic with C2 communications traffic, or using a non-standard data encoding
system, such as a modified Base64 encoding for the message body of an HTTP request.}
Mitigation : {Network intrusion detection and prevention systems that use network signatures to
identify traffic for specific adversary malware can be used to mitigate activity at the
network level. Signatures are often for unique indicators within protocols and may be
based on the specific obfuscation technique used by a particular adversary or tool, and
will likely be different across various malware families and versions. Adversaries will
likely change tool C2 signatures over time or construct protocols in such a way as to
avoid detection by common defensive tools.[[CiteRef::University of Birmingham C2]]}
Tactic : Command and Control
Analytic Details : {Analyze network data for uncommon data flows (e.g., a client sending significantly more
data than it receives from a server). Processes utilizing the network that do not normally
have network communication or have never been seen before are suspicious. Analyze packet
contents to detect communications that do not follow the expected protocol behavior for
the port that is being used.[[CiteRef::University of Birmingham C2]]}
TechniqueName : {Data Obfuscation}
FullText : Technique/T1001
Link Text : {[[Technique/T1001|Data Obfuscation]]}
Reference : {University of Birmingham C2, FireEye APT28, Axiom, FireEye APT30...}
Platform : {Windows Server 2003, Windows Server 2008, Windows Server 2012, Windows XP...}
Name : {Data Obfuscation}
CAPEC ID : {}
Requires Permission : {}
URL : https://attack.mitre.org/wiki/Technique/T1001
.............
..................