2022-02-20 15:37:38 -05:00
|
|
|
{
|
|
|
|
"type": "bundle",
|
2022-07-02 16:01:17 -04:00
|
|
|
"id": "bundle--45b2d620-093f-4fc4-9eb3-0cbc7412c81c",
|
2022-02-20 15:37:38 -05:00
|
|
|
"objects": [
|
|
|
|
{
|
|
|
|
"type": "attack-pattern",
|
|
|
|
"spec_version": "2.1",
|
2022-07-02 16:01:17 -04:00
|
|
|
"id": "attack-pattern--d4254a49-6d3a-46cc-9b41-e56a1c0ea8f6",
|
|
|
|
"created_by_ref": "identity--56ecd0d7-2c77-4daa-afe7-6e811d9e456b",
|
|
|
|
"created": "2022-07-02T19:59:12.736942Z",
|
|
|
|
"modified": "2022-07-02T19:59:12.736942Z",
|
2022-07-02 00:28:52 -04:00
|
|
|
"name": "Use Shell Organizations",
|
2022-07-02 16:01:17 -04:00
|
|
|
"description": "Use Shell Organizations to conceal sponsorship.",
|
2022-02-20 15:37:38 -05:00
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "mitre-attack",
|
2022-06-30 23:30:18 -04:00
|
|
|
"phase_name": "persist-in-the-information-environment"
|
2022-02-20 15:37:38 -05:00
|
|
|
}
|
|
|
|
],
|
|
|
|
"external_references": [
|
|
|
|
{
|
|
|
|
"source_name": "DISARM",
|
2022-07-02 00:28:52 -04:00
|
|
|
"url": "https://github.com/DISARMFoundation/DISARM_framework/blob/master/techniques/T0130.003.md",
|
|
|
|
"external_id": "T0130.003"
|
2022-02-20 15:37:38 -05:00
|
|
|
}
|
|
|
|
],
|
|
|
|
"object_marking_refs": [
|
2022-07-02 16:01:17 -04:00
|
|
|
"marking-definition--8c38a88c-17da-4495-b5f3-7e1ebf6e9b8d"
|
2022-02-20 15:37:38 -05:00
|
|
|
],
|
2022-07-02 00:28:52 -04:00
|
|
|
"x_mitre_is_subtechnique": true,
|
2022-02-20 15:37:38 -05:00
|
|
|
"x_mitre_platforms": [
|
|
|
|
"Windows",
|
|
|
|
"Linux",
|
|
|
|
"Mac"
|
|
|
|
],
|
2022-07-02 00:28:52 -04:00
|
|
|
"x_mitre_version": "1.0"
|
2022-02-20 15:37:38 -05:00
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|