from pyattck import Attck
attack = Attck()
for technique in attack.enterprise.techniques:
print("# " + technique.name)
for subtechnique in technique.subtechniques:
if "Linux" in subtechnique.platforms:
print("## " + subtechnique.id + " " + subtechnique.name)
for ref in subtechnique.reference:
try:
print("\r * " + ref["url"])
except:
pass
print("\r")
if subtechnique.commands:
print("Atomic Red Team:\r * https://github.com/redcanaryco/atomic-red-team/tree/master/atomics/%s/%s.md" % (subtechnique.id, subtechnique.id))
print("\r\n")
Atomic Red Team:
-
https://blog.malwarebytes.com/threat-analysis/2017/04/new-osx-dok-malware-intercepts-web-traffic/
-
https://www.cybereason.com/blog/labs-proton-b-what-this-mac-malware-actually-does
Atomic Red Team:
-
https://www.elastic.co/blog/embracing-offensive-tooling-building-detections-against-koadic-using-eql
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
-
https://volatility-labs.blogspot.com/2012/10/phalanx-2-revealed-using-volatility-to.html
-
https://www.crowdstrike.com/blog/http-iframe-injecting-linux-rootkit/
-
https://www.virusbulletin.com/uploads/pdf/conference/vb2014/VB2014-Wardle.pdf
-
https://www.synack.com/2017/09/08/high-sierras-secure-kernel-extension-loading-is-broken/
-
https://securelist.com/the-ventir-trojan-assemble-your-macos-spy/67267/
-
https://pikeralpha.wordpress.com/2017/08/29/user-approved-kernel-extension-loading/
-
https://richard-purves.com/2017/11/09/mdm-and-the-kextpocalypse-2/
-
https://developer.apple.com/business/documentation/Configuration-Profile-Reference.pdf
Atomic Red Team:
-
https://specifications.freedesktop.org/autostart-spec/autostart-spec-latest.html
-
https://specifications.freedesktop.org/desktop-entry-spec/1.2/ar01s06.html
-
https://iranthreats.github.io/resources/attribution-flying-rocket-kitten/
-
https://www.intezer.com/blog-hiddenwasp-malware-targeting-linux-systems/
-
https://www.intezer.com/blog/research/kaiji-new-chinese-linux-malware-turning-to-golang/
-
https://www.virusbulletin.com/uploads/pdf/conference/vb2014/VB2014-Wardle.pdf
-
http://manpages.ubuntu.com/manpages/bionic/man8/systemd-rc-local-generator.8.html
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
-
https://devblogs.microsoft.com/vbteam/visual-basic-support-planned-for-net-5-0/
-
https://docs.microsoft.com/previous-versions//1kw29xwf(v=vs.85)
Atomic Red Team:
Atomic Red Team:
-
https://docs.microsoft.com/windows/win32/com/translating-to-jscript
-
https://docs.microsoft.com/archive/blogs/gauravseth/the-world-of-jscript-javascript-ecmascript
-
https://docs.microsoft.com/scripting/winscript/windows-script-interfaces
-
https://www.sentinelone.com/blog/macos-red-team-calling-apple-apis-without-building-binaries/
-
https://www.mdsec.co.uk/2021/01/macos-post-exploitation-shenanigans-with-vscode-extensions/
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
-
https://www.anomali.com/blog/rocke-evolves-its-arsenal-with-a-new-malware-family-written-in-golang
-
https://www.rapid7.com/db/modules/exploit/linux/local/service_persistence
Atomic Red Team:
-
http://juusosalonen.com/post/30923743427/breaking-into-the-os-x-keychain
-
https://www.welivesecurity.com/2016/07/06/new-osxkeydnap-malware-hungry-credentials/
-
http://www.slideshare.net/StephanBorosh/external-to-da-the-os-x-way
-
https://blog.talosintelligence.com/2018/02/olympic-destroyer.html
-
https://docs.microsoft.com/en-us/windows/desktop/api/dpapi/nf-dpapi-cryptunprotectdata
-
https://www.proofpoint.com/us/threat-insight/post/new-vega-stealer-shines-brightly-targeted-campaign
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
-
https://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/ib-entertainment.pdf
-
https://www.intelligence.senate.gov/sites/default/files/documents/os-kmandia-033017.pdf
-
https://documents.trendmicro.com/assets/white_papers/wp-a-deep-dive-into-defacement.pdf
-
https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Report.pdf
-
https://www.justice.gov/opa/press-release/file/1092091/download
-
https://www.fireeye.com/blog/threat-research/2016/11/fireeye_respondsto.html
-
http://researchcenter.paloaltonetworks.com/2016/11/unit42-shamoon-2-return-disttrack-wiper/
-
https://unit42.paloaltonetworks.com/shamoon-3-targets-oil-gas-organization/
-
https://resources.infosecinstitute.com/fast-flux-networks-working-detection-part-1/#gref
-
https://resources.infosecinstitute.com/fast-flux-networks-working-detection-part-2/#gref
-
https://www.welivesecurity.com/2017/01/12/fast-flux-networks-work/
-
https://umbrella.cisco.com/blog/2016/10/10/domain-generation-algorithms-effective/
-
https://unit42.paloaltonetworks.com/threat-brief-understanding-domain-generation-algorithms-dga/
-
http://blog.talosintelligence.com/2017/09/avast-distributes-malware.html
-
https://blogs.akamai.com/2018/01/a-death-match-of-domain-generation-algorithms.html
-
https://www.fireeye.com/blog/threat-research/2017/03/dissecting_one_ofap.html
-
https://www.welivesecurity.com/2017/12/21/sednit-update-fancy-bear-spent-year/
-
https://datadrivensecurity.info/blog/posts/2014/Oct/dga-part2/
-
https://www.fireeye.com/blog/threat-research/2014/09/darwins-favorite-apt-group-2.html
-
https://blog.rapid7.com/2013/08/26/upcoming-g20-summit-fuels-espionage-operations/
-
https://blog.compass-security.com/2018/09/hidden-inbox-rules-in-microsoft-exchange/
-
https://blogs.technet.microsoft.com/timmcmic/2015/06/08/exchange-and-office-365-mail-forwarding-2/
-
https://support.apple.com/guide/mail/reply-to-forward-or-redirect-emails-mlhlp1010/mac
-
http://www.sans.org/reading-room/whitepapers/analyst/finding-hidden-threats-decrypting-ssl-34840
-
https://insights.sei.cmu.edu/cert/2015/03/the-risks-of-ssl-inspection.html
-
https://www.cloudflare.com/learning/ddos/syn-flood-ddos-attack/
-
https://www.corero.com/resources/ddos-attack-types/syn-flood-ack.html
-
https://www.cloudflare.com/learning/ddos/http-flood-ddos-attack/
-
https://www.netscout.com/blog/asert/ddos-attacks-ssl-something-old-something-new
-
https://www.intezer.com/blog/research/kaiji-new-chinese-linux-malware-turning-to-golang/
-
https://bencane.com/2013/09/16/understanding-a-little-more-about-etcprofile-and-etcbashrc/
-
https://unit42.paloaltonetworks.com/unit42-new-iotlinux-malware-targets-dvrs-forms-botnet/
-
https://www.anomali.com/blog/pulling-linux-rabbit-rabbot-malware-out-of-a-hat
-
https://blog.sucuri.net/2018/05/shell-logins-as-a-magento-reinfection-vector.html
-
https://scriptingosx.com/2019/06/moving-to-zsh-part-2-configuration-files/
-
https://github.com/D00MFist/PersistentJXA/blob/master/BashProfilePersist.js
-
https://cedowens.medium.com/macos-ms-office-sandbox-brain-dump-4509b5fed49a
Atomic Red Team:
Atomic Red Team:
-
https://www.schneier.com/academic/paperfiles/paper-clueless-agents.pdf
-
https://pdfs.semanticscholar.org/2721/3d206bc3c1e8c229fb4820b6af09e7f975da.pdf
-
https://research.nccgroup.com/2017/08/08/smuggling-hta-files-in-internet-explorer-edge/
-
https://github.com/Genetic-Malware/Ebowla/blob/master/Eko_2016_Morrow_Pitts_Master.pdf
-
https://github.com/nccgroup/demiguise/blob/master/examples/virginkey.js
Atomic Red Team:
Atomic Red Team:
T1564.001 Hidden Files and Directories
-
https://researchcenter.paloaltonetworks.com/2016/09/unit42-sofacys-komplex-os-x-trojan/
-
https://blog.malwarebytes.com/threat-analysis/2017/01/new-mac-backdoor-using-antiquated-code/
Atomic Red Team:
T1564.005 Hidden File System
-
https://www.malwaretech.com/2014/11/virtual-file-systems-for-beginners.html
-
https://www.fireeye.com/blog/threat-research/2015/12/fin1-targets-boot-record.html
-
https://www.welivesecurity.com/wp-content/uploads/2020/05/ESET_Turla_ComRAT.pdf
-
https://outflank.nl/blog/2019/05/05/evil-clippy-ms-office-maldoc-assistant/
-
https://medium.com/walmartglobaltech/vba-stomping-advanced-maldoc-techniques-612c484ab278
-
https://support.apple.com/guide/mail/use-rules-to-manage-emails-you-receive-mlhlp1017/mac
-
https://docs.microsoft.com/en-us/powershell/module/exchange/new-inboxrule?view=exchange-ps
-
https://docs.microsoft.com/en-us/powershell/module/exchange/set-inboxrule?view=exchange-ps
-
https://www.tldp.org/HOWTO/Program-Library-HOWTO/shared-libraries.html
-
https://theevilbit.github.io/posts/dyld_insert_libraries_dylib_injection_in_macos_osx_deep_dive/
-
https://blog.timac.org/2012/1218-simple-code-injection-using-dyld_insert_libraries/
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
-
https://www.crowdstrike.com/blog/how-falcon-complete-stopped-a-big-game-hunting-ransomware-attack/
-
https://www.mandiant.com/resources/bring-your-own-land-novel-red-teaming-technique
-
https://www.praetorian.com/blog/man-in-the-middle-tls-ssl-protocol-downgrade-attack/
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
-
https://baesystemsai.blogspot.com/2015/06/new-mac-os-malware-exploits-mackeeper.html
-
https://www.welivesecurity.com/2016/07/06/new-osxkeydnap-malware-hungry-credentials/
-
https://embracethered.com/blog/posts/2021/spoofing-credential-dialogs/
-
https://enigma0x3.net/2015/01/21/phishing-for-credentials-if-you-want-it-just-ask/
Atomic Red Team:
-
https://resources.infosecinstitute.com/spoof-using-right-to-left-override-rtlo-technique-2/
-
https://securelist.com/zero-day-vulnerability-in-telegram/83800/
-
http://pages.endgame.com/rs/627-YBU-612/images/EndgameJournal_The%20Masquerade%20Ball_Pages_R2.pdf
-
https://blog-assets.f-secure.com/wp-content/uploads/2019/10/15163418/CozyDuke.pdf
-
https://twitter.com/ItsReallyNick/status/1055321652777619457
Atomic Red Team:
-
https://www.freedesktop.org/software/systemd/man/systemd.service.html
-
http://researchcenter.paloaltonetworks.com/2016/11/unit42-shamoon-2-return-disttrack-wiper/
Atomic Red Team:
-
http://pages.endgame.com/rs/627-YBU-612/images/EndgameJournal_The%20Masquerade%20Ball_Pages_R2.pdf
-
https://twitter.com/ItsReallyNick/status/1055321652777619457
-
https://docs.docker.com/engine/reference/commandline/images/
Atomic Red Team:
Atomic Red Team:
-
https://www.cloudflare.com/learning/ddos/dns-amplification-ddos-attack/
-
https://www.cloudflare.com/learning/ddos/ntp-amplification-ddos-attack/
-
https://blog.cloudflare.com/memcrashed-major-amplification-attacks-from-port-11211/
Atomic Red Team:
-
https://www.tldp.org/LDP/lame/LAME/linux-admin-made-easy/shadow-file-formats.html
-
https://www.cyberciti.biz/faq/unix-linux-password-cracking-john-the-ripper/
Atomic Red Team:
-
https://www.welivesecurity.com/2018/03/13/oceanlotus-ships-new-backdoor/
-
https://securelist.com/old-malware-tricks-to-bypass-detection-in-the-age-of-big-data/78010/
Atomic Red Team:
-
https://www.clearskysec.com/wp-content/uploads/2018/11/MuddyWater-Operations-in-Lebanon-and-Oman.pdf
Atomic Red Team:
-
https://outflank.nl/blog/2018/08/14/html-smuggling-explained/
-
https://research.nccgroup.com/2017/08/08/smuggling-hta-files-in-internet-explorer-edge/
Atomic Red Team:
Atomic Red Team:
-
https://www.cyber.gov.au/sites/default/files/2019-03/spoof_email_sender_policy_framework.pdf
-
https://www.elastic.co/blog/embracing-offensive-tooling-building-detections-against-koadic-using-eql
Atomic Red Team:
-
https://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/rpt-mtrends-2016.pdf
-
http://www.symantec.com/connect/blogs/are-mbr-infections-back-fashion
-
https://medium.com/@jain.sm/code-injection-in-running-process-using-ptrace-d3ea7191a4be
-
https://github.com/gaffe23/linux-inject/blob/master/slides_BHArsenal2015.pdf
-
http://www.chokepoint.net/2014/02/detecting-userland-preload-rootkits.html
-
https://web.archive.org/web/20150711051625/http://vxer.org/lib/vrn00.html
-
https://backtrace.io/blog/backtrace/elf-shared-library-injection-forensics/
-
https://web.archive.org/web/20051013084246/http://www.trilithium.com/johan/2005/08/linux-gate/
-
http://www.chokepoint.net/2014/02/detecting-userland-preload-rootkits.html
Atomic Red Team:
-
https://www.slideshare.net/morisson/mistrusting-and-abusing-ssh-13526219
-
https://www.blackhat.com/presentations/bh-usa-05/bh-us-05-boileau.pdf
-
https://www.clockwork.com/news/2012/09/28/602/ssh_agent_hijacking
-
https://matrix.org/blog/2019/05/08/post-mortem-and-remediations-for-apr-11-security-incident
Atomic Red Team:
-
https://help.realvnc.com/hc/en-us/articles/360002250097-Setting-up-System-Authentication
-
https://int0x33.medium.com/day-70-hijacking-vnc-enum-brute-access-and-crack-d3d18a4601cc
-
https://www.tenable.com/blog/detecting-macos-high-sierra-root-account-without-authentication
-
https://www.offensive-security.com/metasploit-unleashed/vnc-authentication/
-
http://lists.openstack.org/pipermail/openstack/2013-December/004138.html
-
https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/blob/9aa9181e/src/grd-settings.c#L207
-
https://kifarunix.com/scheduling-tasks-using-at-command-in-linux/
-
https://www.linkedin.com/pulse/getting-attacker-ip-address-from-malicious-linux-job-craig-rowland/
Atomic Red Team:
Atomic Red Team:
-
https://www.tecmint.com/control-systemd-services-on-remote-linux-server/
-
https://www.bleepingcomputer.com/news/security/malware-found-in-arch-linux-aur-package-repository/
-
https://gist.github.com/campuscodi/74d0d2e35d8fd9499c76333ce027345a
-
https://lists.archlinux.org/pipermail/aur-general/2018-July/034153.html
Atomic Red Team:
-
https://blog.netspi.com/sql-server-persistence-part-1-startup-stored-procedures/
-
https://securelist.com/malicious-tasks-in-ms-sql-server/92167/
-
https://blog.netspi.com/attacking-sql-server-clr-assemblies/
-
https://docs.microsoft.com/en-us/exchange/transport-agents-exchange-2013-help
-
https://www.welivesecurity.com/wp-content/uploads/2019/05/ESET-LightNeuron.pdf
Atomic Red Team:
Atomic Red Team:
Atomic Red Team:
-
https://www.kaspersky.com/blog/lenovo-pc-with-adware-superfish-preinstalled/7712/
-
https://posts.specterops.io/code-signing-certificate-cloning-attacks-and-defenses-6f98657fc6ec
-
https://www.tripwire.com/state-of-security/off-topic/appunblocker-bypassing-applocker/
Atomic Red Team:
-
https://www.welivesecurity.com/2009/01/15/malware-trying-to-avoid-some-countries/
-
https://www.crowdstrike.com/blog/big-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/
-
https://www.cybereason.com/blog/cybereason-vs-darkside-ransomware
-
https://securelist.com/evolution-of-jsworm-ransomware/102428/
-
https://securelist.com/synack-targeted-ransomware-uses-the-doppelganging-technique/85431/
-
http://carnal0wnage.attackresearch.com/2014/05/mimikatz-against-virtual-machine-memory.html
-
https://unit42.paloaltonetworks.com/hildegard-malware-teamtnt/
Atomic Red Team:
Atomic Red Team:
-
https://kasperskycontenthub.com/wp-content/uploads/sites/43/vlpdfs/unveilingthemask_v1.0.pdf
-
https://researchcenter.paloaltonetworks.com/2016/06/unit42-prince-of-persia-game-over/
Atomic Red Team:
Atomic Red Team:
-
https://docs.microsoft.com/en-us/windows/security/identity-protection/access-control/local-accounts
-
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_root-user.html
-
https://www.microsoft.com/security/blog/2020/04/02/attack-matrix-kubernetes/
-
https://github.com/rapid7/metasploit-framework/tree/master/modules/exploits/linux/ssh
Atomic Red Team:
Atomic Red Team:
-
https://drive.google.com/file/d/1t0jn3xr4ff2fR30oQAUn_RsWSnMpOAQc
-
https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/stopping-malware-fake-virtual-machine/
Atomic Red Team:
-
https://drive.google.com/file/d/1t0jn3xr4ff2fR30oQAUn_RsWSnMpOAQc
-
https://unit42.paloaltonetworks.com/unit42-sofacy-continues-global-attacks-wheels-new-cannon-trojan/
-
https://www.fireeye.com/blog/threat-research/2017/04/fin7-phishing-lnk.html
-
https://drive.google.com/file/d/1t0jn3xr4ff2fR30oQAUn_RsWSnMpOAQc
-
https://www.netskope.com/blog/nitol-botnet-makes-resurgence-evasive-sandbox-analysis-technique
Atomic Red Team: