2022-02-20 15:37:38 -05:00
|
|
|
{
|
|
|
|
"type": "bundle",
|
2022-07-02 16:01:17 -04:00
|
|
|
"id": "bundle--2cbdefdc-feb4-4c3c-b16b-31d6493b1139",
|
2022-02-20 15:37:38 -05:00
|
|
|
"objects": [
|
|
|
|
{
|
|
|
|
"type": "attack-pattern",
|
|
|
|
"spec_version": "2.1",
|
2022-07-02 16:01:17 -04:00
|
|
|
"id": "attack-pattern--ac20552b-5bb8-470b-93f7-f241991bc60b",
|
|
|
|
"created_by_ref": "identity--7d1b1243-797f-431e-9cad-f3c2e13c0a61",
|
|
|
|
"created": "2022-07-02T19:59:12.73212Z",
|
|
|
|
"modified": "2022-07-02T19:59:12.73212Z",
|
2022-06-30 23:30:18 -04:00
|
|
|
"name": "Conceal Operational Activity",
|
2022-07-02 16:01:17 -04:00
|
|
|
"description": "Conceal the campaign's operational activity to avoid takedown and attribution.",
|
2022-02-20 15:37:38 -05:00
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "mitre-attack",
|
2022-06-30 23:30:18 -04:00
|
|
|
"phase_name": "persist-in-the-information-environment"
|
2022-02-20 15:37:38 -05:00
|
|
|
}
|
|
|
|
],
|
|
|
|
"external_references": [
|
|
|
|
{
|
|
|
|
"source_name": "DISARM",
|
2022-06-30 23:30:18 -04:00
|
|
|
"url": "https://github.com/DISARMFoundation/DISARM_framework/blob/master/techniques/T0129.md",
|
|
|
|
"external_id": "T0129"
|
2022-02-20 15:37:38 -05:00
|
|
|
}
|
|
|
|
],
|
|
|
|
"object_marking_refs": [
|
2022-07-02 16:01:17 -04:00
|
|
|
"marking-definition--74bc890b-1a79-435f-ba35-09c5b98ed6a8"
|
2022-02-20 15:37:38 -05:00
|
|
|
],
|
|
|
|
"x_mitre_is_subtechnique": false,
|
|
|
|
"x_mitre_platforms": [
|
|
|
|
"Windows",
|
|
|
|
"Linux",
|
|
|
|
"Mac"
|
|
|
|
],
|
2022-07-02 00:28:52 -04:00
|
|
|
"x_mitre_version": "1.0"
|
2022-02-20 15:37:38 -05:00
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|