2022-02-20 15:37:38 -05:00
|
|
|
{
|
|
|
|
"type": "bundle",
|
2022-07-02 15:40:09 -04:00
|
|
|
"id": "bundle--292a3e6e-763f-4c4d-a5b7-41823dcae350",
|
2022-02-20 15:37:38 -05:00
|
|
|
"objects": [
|
|
|
|
{
|
|
|
|
"type": "attack-pattern",
|
|
|
|
"spec_version": "2.1",
|
2022-07-02 15:40:09 -04:00
|
|
|
"id": "attack-pattern--73ad4a21-0baa-41ae-8b94-44b897f2a5e0",
|
|
|
|
"created_by_ref": "identity--e5e40f22-db89-406f-ae1d-8e2be9fa2bcd",
|
|
|
|
"created": "2022-07-02T19:37:33.836064Z",
|
|
|
|
"modified": "2022-07-02T19:37:33.836064Z",
|
2022-07-02 13:29:40 -04:00
|
|
|
"name": "Conduct Symbolic Action",
|
|
|
|
"description": "TA10",
|
2022-02-20 15:37:38 -05:00
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "mitre-attack",
|
|
|
|
"phase_name": "drive-offline-activity"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"external_references": [
|
|
|
|
{
|
|
|
|
"source_name": "DISARM",
|
2022-07-02 13:29:40 -04:00
|
|
|
"url": "https://github.com/DISARMFoundation/DISARM_framework/blob/master/techniques/T0057.002.md",
|
|
|
|
"external_id": "T0057.002"
|
2022-02-20 15:37:38 -05:00
|
|
|
}
|
|
|
|
],
|
|
|
|
"object_marking_refs": [
|
2022-07-02 15:40:09 -04:00
|
|
|
"marking-definition--2f13aa63-b17a-48c1-9087-9bcda65504ae"
|
2022-02-20 15:37:38 -05:00
|
|
|
],
|
2022-07-02 00:28:52 -04:00
|
|
|
"x_mitre_is_subtechnique": true,
|
2022-02-20 15:37:38 -05:00
|
|
|
"x_mitre_platforms": [
|
|
|
|
"Windows",
|
|
|
|
"Linux",
|
|
|
|
"Mac"
|
|
|
|
],
|
2022-07-02 00:28:52 -04:00
|
|
|
"x_mitre_version": "1.0"
|
2022-02-20 15:37:38 -05:00
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|