Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support ATT&CK v14.1 Techniques #887

Open
7 tasks
mr-tz opened this issue Mar 6, 2024 · 3 comments
Open
7 tasks

Support ATT&CK v14.1 Techniques #887

mr-tz opened this issue Mar 6, 2024 · 3 comments

Comments

@mr-tz
Copy link
Collaborator

mr-tz commented Mar 6, 2024

Thank you very much for your contributions.
May I ask if you have any plans in the near future to synchronize capa rules with ATT&CK v14.1?

Originally posted by @Iroxious in #222 (comment)

I see the following potential new techniques:

  • Exfiltration Over Web Service: Exfiltration Over Webhook
  • Hide Artifacts: Ignore Process Interrupts
  • Impair Defenses: Disable or Modify Linux Audit System
  • Log Enumeration
  • Masquerading: Break Process Trees
  • Power Settings
  • System Network Configuration Discovery: Wi-Fi Discovery
@Iroxious
Copy link

Iroxious commented Mar 7, 2024

Thank you for your response. May I understand that for other earlier techniques not mentioned by you, if they can be utilized in CAPA analysis, they are already roughly included in capa-rules? (I saw that capa-rules currently involve a total of 120 TTP techniques.)

@mr-tz
Copy link
Collaborator Author

mr-tz commented Mar 7, 2024

Yes, we don't exactly track the supported version or coverage but many rules have ATT&CK and MBC mappings included.

@Iroxious
Copy link

Iroxious commented Mar 8, 2024

I understand, thank you for your explanation. :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants