Skip to content

Instantly share code, notes, and snippets.

@timb-machine
Created August 13, 2022 12:06
Show Gist options
  • Select an option

  • Save timb-machine/2071890f3e4dafe3140a5e74ae6378be to your computer and use it in GitHub Desktop.

Select an option

Save timb-machine/2071890f3e4dafe3140a5e74ae6378be to your computer and use it in GitHub Desktop.
Linux techniques missing from ATT&CK?
T1134.004: Parent PID Spoofing
missing from ATT&CK
* https://magisterquis.github.io/2018/03/11/process-injection-with-gdb.html (https://github.com/timb-machine/linux-malware/issues/462), citable: False (TACTICS OR TECHNIQUES WRONG)
* https://grugq.github.io/docs/ul_exec.txt (https://github.com/timb-machine/linux-malware/issues/463), citable: False (TACTICS OR TECHNIQUES WRONG)
* https://gist.github.com/timb-machine/6177721c3eafba3e95abdf112b2a5902 (https://github.com/timb-machine/linux-malware/issues/461), citable: False (TACTICS OR TECHNIQUES WRONG)
T1055.012: Process Hollowing
missing from ATT&CK
* https://magisterquis.github.io/2018/03/11/process-injection-with-gdb.html (https://github.com/timb-machine/linux-malware/issues/462), citable: False (TACTICS OR TECHNIQUES WRONG)
* https://grugq.github.io/docs/ul_exec.txt (https://github.com/timb-machine/linux-malware/issues/463), citable: False (TACTICS OR TECHNIQUES WRONG)
* https://gist.github.com/timb-machine/6177721c3eafba3e95abdf112b2a5902 (https://github.com/timb-machine/linux-malware/issues/461), citable: False (TACTICS OR TECHNIQUES WRONG)
T1202: Indirect Command Execution
missing from ATT&CK
* https://sysdig.com/blog/containers-read-only-fileless-malware/ (https://github.com/timb-machine/linux-malware/issues/415), citable: False
* https://gist.github.com/timb-machine/7bd75479ee29aee8762952ea16908eb0 (https://github.com/timb-machine/linux-malware/issues/197), citable: False
T1134.004: Parent PID Spoofing
missing from ATT&CK
* https://magisterquis.github.io/2018/03/11/process-injection-with-gdb.html (https://github.com/timb-machine/linux-malware/issues/462), citable: False
* https://grugq.github.io/docs/ul_exec.txt (https://github.com/timb-machine/linux-malware/issues/463), citable: False
* https://gist.github.com/timb-machine/6177721c3eafba3e95abdf112b2a5902 (https://github.com/timb-machine/linux-malware/issues/461), citable: False
T1055.012: Process Hollowing
missing from ATT&CK
* https://magisterquis.github.io/2018/03/11/process-injection-with-gdb.html (https://github.com/timb-machine/linux-malware/issues/462), citable: False
* https://grugq.github.io/docs/ul_exec.txt (https://github.com/timb-machine/linux-malware/issues/463), citable: False
* https://gist.github.com/timb-machine/6177721c3eafba3e95abdf112b2a5902 (https://github.com/timb-machine/linux-malware/issues/461), citable: False
T1584: Compromise Infrastructure
missing from ATT&CK - subsequent analysis identified that MITRE list this against PRE
* https://www.mandiant.com/resources/unc3524-eye-spy-email (https://github.com/timb-machine/linux-malware/issues/414), citable: True
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment