Group/section restrictions. Must post first.
This week, we dive deeper into the practical aspects of Cyber Threat Intelligence
(CTI), focusing on the extraction and analysis of Indicators of Compromise (IOCs)
from real-world scenarios. Understanding and correctly identifying atomic,
computed, and behavioral IOCs, and their relationship with MITRE ATT&CK Tactics
and Techniques, is crucial for cybersecurity professionals. This exercise builds
directly upon your foundational knowledge of MITRE ATT&CK and STIX introduced
in Weeks 1 and 2.
Scenario Overview:
In Week 3, we present a challenging intrusion event that requires you to sift
through narrative reports to identify atomic and computed IOCs. You will then
progress to constructing behavioral IOCs from these findings and map them to
specific ATT&CK Tactics and Techniques. This exercise aims to refine your analytical
skills and deepen your understanding of the dynamic interplay between different
types of IOCs and the broader strategic implications of cyber threat behaviors.
Spoiler Alert: One of the MITRE ATT&CK Groups from Weeks 1 & 2 discussions
conducted this attack!
Task Description:
Your task involves three main components:
Identification and Listing of IOCS: Based on the scenario document
(CYBV435_ioc_Scenario_3C.pdf in Cyber 3 content), identify and list the
atomic and computed IOCs. You will have to do this for the quiz. So, get a
head start on it in the discussion.
Construction of Behavioral IOCS: Utilizing the identified atomic and
computed IOCs, construct clear and concise behavioral IOCs. Each
behavioral IOC should illustrate a narrative that describes a specific
malicious behavior, incorporating relevant ATT&CK Tactics and Techniques.
Mapping to MITRE ATT&CK: For each behavioral IOC you construct, map it
to the corresponding ATT&CK Tactics and Techniques. Highlight how these
IOCs provide insight into the adversary's objectives and methods.
Questions to Consider:
• How can atomic and computed IOCs be effectively integrated into
behavioral IOCs to provide a more comprehensive view of an intrusion
event?
• What challenges do you encounter when trying to map behavioral IOCs to
specific ATT&CK Tactics and Techniques? How can these challenges be
overcome?
• In what ways do behavioral IOCS enhance our understanding of threat actors
and their methodologies compared to atomic and computed IOCS alone?
Original Post Requirements:
• Summarize your analysis and findings in a narrative format, incorporating
discussion on the transition from atomic and computed IOCs to behavioral
IOCs and their mapping to ATT&CK Tactics and Techniques.
.
.
Provide examples from the scenario to illustrate your points.
Pose at least one question to your peers to encourage further discussion./n 1
CYBV435_PQ3_SCENARIO_3C
Extracting Indicators of Compromise from Narrative Reporting
This week, we discussed extracting atomic, computed, and behavioral indicators of
compromise (IOC) from narrative reporting. Mastering this skill is essential for all cyber
professionals, particularly those interested in cyber intelligence. For this practical quiz (PQ), you
must identify and list the IOCs by type in the scenario starting on the next page.
About Hyperlinks in the Scenario
Hyperlinks to additional background information are embedded in the text. Hyperlinks
enclosed in {braces} lead to cyber industry resources. Follow and read these web pages to
improve your understanding of the incident and general cybersecurity knowledge. Bookmark
these sites for future reference.
•
Embedded Hyperlinks. You will find hyperlinks that provide additional background
information throughout the text. Follow and read the web pages linked through these
hyperlinks to deepen your understanding of the incident and general cybersecurity
knowledge. These are crucial for understanding the context and technical details of the
scenario.
Industry Resource Links. Hyperlinks enclosed in {braces} specifically lead to valuable
cyber industry resources. Bookmark these sites for future reference, as they are valuable
resources for anyone in the field of cyber threat intelligence. These are not just optional
reads; they are part of the learning experience for this PQ.
By actively engaging with these links, you will answer the PQ more effectively and
enrich your overall understanding of cybersecurity. CYBV435_PQ3_SCENARIO_3C
IOC Scenario 3C
This Indicators of Compromise (IOC) scenario has a difficulty level of 3 out of 5. The
narrative report at this level will be unordered, and the sequence of events will be interspersed
with moderate amounts of irrelevant information, such as additional software running on the
compromised system or unrelated network traffic. Students sift through the noise to identify the
relevant IOCs, put them into chronological order, and construct a coherent Behavioral IOC
narrative.
Scenario
2
Background
Three notional aviation-industry companies, all headquartered in Cyberapolis with
additional international branches, are pivotal to this scenario. You will not need all the details for
this IOC activity, but they may be necessary for the attribution practical quiz in a later week.
1. Hitchcock Avia. This medium-size company provides unmanned aerial systems
(UAS) to government and commercial entities. Two years ago {2014 in real-time},
Hitchcock Avia secured a contract to deliver McGuffin UAS vehicles to the Republic
of Korea (ROK). Subsequently, they established a manufacturing plant in Daegu to
produce the UAS vehicles.
2. AirHammett, Inc. A general aviation company, AirHammett specializes in twin-
seat, propeller-driven airplanes. The company operates a dealership and service center
in Riyadh, Saudi Arabia.
3. Hedren Aviation Supply. Recognized as a key supplier in the aviation sector,
Hedren supports both Hitchcock Avia and AirHammett. An unknown Chinese
company based in Shanghai provided most of Hedren's products. CYBV435_PQ3_SCENARIO_3C
Relationships. Hitchcock and AirHammett operate in different market segments and
maintain a friendly rapport. Hedren plays a vendor role for both. The leadership triad - Ms.
Hammett of AirHammett, Mr. Hitchcock of Hitchcock Avia, and John Smith, the COO of
Hedren share a U.S. Air Force background. Their bond has only strengthened over the years, as
-
evidenced by their annual visits with spouses to the EAA AirVenture show in Oshkosh,
Wisconsin. Regular interactions like email communications and website visits are commonplace
among these companies, and several employees have had tenure across all three firms.
Your Role in the Scenario
You are the newest member of the Security Operations Center (SOC). Here is the
welcome message you received on your first day.
Welcome to the Security Operations Center (SOC) at Hitchcock Avia!
The SOC at Hitchcock serves as the central nerve of our cybersecurity efforts. As a
medium-sized entity in the aviation sector, the need to protect our sensitive data,
intellectual property, and operational systems is paramount. Our SOC is equipped with
state-of-the-art technology and tools that monitor, assess, and defend our digital
environments from potential threats 24/7.
Staffed by a dedicated team of cybersecurity professionals, the SOC's primary objectives
are to detect, respond to, and mitigate security incidents in real time. Our analysts closely
monitor network traffic, user activities, and system behaviors for unusual patterns. Our
incident response team springs into action when a potential security incident is identified,
ensuring minimum disruption and risk to our operations.
As a key hub for threat intelligence, the SOC also plays a role in proactively identifying
vulnerabilities and strengthening our defense mechanisms. Collaborative efforts with
3 CYBV435_PQ3_SCENARIO_3C
other departments ensure that the company is aware of and aligned with our security
protocols and policies.
As a new member of the SOC, you are now an integral part of a team that safeguards
Hitchcock Avia's reputation, assets, and future. You will start on the Swing Shift from
5:00 p.m. to 2:00 a.m. Welcome aboard, and here's to fortifying our skies and systems!
Narrative Report of Cyber Incident
4
This morning, Hitchcock's Intrusion Detection System (IDS) alerted on the exfiltration of
a large amount of data from the machine of one of your company's senior engineers working on
the UAS's guidance system. A quick-thinking security analyst stopped the exfiltration before too
large an amount of data was compromised.
The initial investigation into the incident shows that the senior engineer, Melanie Daniels,
received an email bearing the subject line “AirHammett Job Oportunitees" [sic] {T1566}. The
email contained a Portable Document File (PDF) attachment that, when opened, resulted in
downloading a file called edg32.dll from http[:]//www[.] hedren [.] com/edg32[.] d11 to
her machine {T1204.002}. This file subsequently established an encrypted connection to a host
at IP address 104.151.248 [.] 173. {Internet Storce Center (ISC) / VirusTotal (VT)}
The malicious email was sent from jsmith[@]hedren [.] com, and the attached PDF was
named Available_Postions.pdf [sic]{T1544.001}. The edg32.dll file's encrypted
connection to IP address 104.151.248 [.] 173 was established using an HTTPS connection
{T1071.001} between port 8352 {IANA / ISC} on the victim machine and port 1913 {IANA /
ISC} on the adversary's machine {T1571}. The malware then searched for accounts with a
lockout threshold of zero {T1087}, saving that information to a file named wordsearch.xlsx.
The edg32.dll then conducted a Boolean search of the infected system for document files using CYBV435_PQ3_SCENARIO_3C
the string ".xls or .xlsx or .doc or .docx or .pdf" {T1083} and transmitted them to the
previously mentioned C2 server.
The PDF file had a Message Digest 5 (MD5) hash value of
4c18ea5860e91988aef25601fa4c7934e. The malicious downloaded DLL file had an MD5
hash value of 7c3243895a3de83ec48ead3271405849. The created XLSX file had an MD5 of
e83ec43895a3d14058498ead3277c324.
Timeline of Cyber Incident
-
Day 1 (Today's month and day in 2016) – Day Shift (9:00 am to 6:00 pm local time)
1. 09:00 AM: Melanie Daniels, a senior engineer, starts her workday and checks her email.
2. 10:15 AM: Melanie receives an email with the subject line "AirHammett Job
Oportunitees" [sic] from jsmith[@]hedren[.]com.
3. 10:30 AM: Melanie opens the PDF attachment named "Available_Postions.pdf" [sic]
from the email.
4. 10:32 AM: The PDF triggers the download of edg32.dll from
http://www[.]hedren[.]com/edg32[.]dll.
5. 10:35 AM: edg32.dll establishes an encrypted HTTPS connection to IP address
104.151.248[.]173.
6. 10:40 AM: Hitchcock's Intrusion Detection System (IDS) alerts the Security Operations
Center (SOC) about a potential data exfiltration from Melanie's machine.
7. 10:42 AM: A security analyst in the SOC identifies the alert and takes immediate action
to stop the data exfiltration.
8. 10:45 AM: The security analyst isolates Melanie's machine from the network to prevent
further data loss.
5
