Instructions
Need typed answer
fill in the correct, relevant static atomic indicator of compromise (AIOC) for each prompt.
and
AND use this for 23-28
https://attack.mitre.org//n Static Behavioral IOCS (Manually Graded)
In this section, your task is to create static behavioral indicators of compromise
(SBIOCS) for each phase of the cyber incident described in the scenario. You'll notice
that each phase aligns with a specific tactic from the MITRE ATT&CK framework.
But what exactly is a BIOC? Let's recall: Behavioral Indicators of Compromise are
essentially narratives or stories of the activities that a threat actor, or a piece of
malware, performs during a cyber incident. They aren't single data points, but rather,
collections of multiple smaller indicators (both atomic and computed), tied together
with logical context to provide a holistic view of the incident.
For instance, an atomic indicator might be an IP address or an email subject line,
while a computed indicator could be a file hash or regular expression. When we use
logical connections to string these together - like noting that a file with a specific
hash was downloaded from a particular IP address - we start to build a BIOC.
For each phase of the incident in the scenario, you should aim to identify the
relevant atomic and computed indicators and then construct a narrative, a story of
what happened in that phase using logical links between the indicators. This will
provide more meaningful insights about the cyber incident.
Remember, your BIOCS should help someone who reads them understand the story
of the incident: what the attacker did, how they did it, and what changes they caused
in the system or network.
As a standard of practice, your BIOC's must contain all relevant computed and
atomic indicators to that BIOC. This requirement implies that all computed and
atomic indicators must appear in at least one BIOC. In addition, write your BIOCS
clearly and concisely in the present tense and active voice.
To earn full points, map each BIOC to one or more MITRE ATT&CK Techniques by
placing the technique number in braces after the phrase or sentence describing the
technique in the format [ATT&CK Tactic}. A subject performs an action on an object
[ATT&CK Technique).
Here is an example: [Discovery] Code within the edg32.dll file searches victim host
for accounts with a lockout threshold of zero (i.e., accounts that allow unlimited
login attempts) [T1087).
And don't forget, writing a good BIOC is like detective work - you're piecing
together clues to get a clear picture of the incident. So put on your detective hat, and
let's get started!
Question 23 (10 points)
Listen
Write a clear and concise static behavioral IOC that describes the initial access phase
of the cyber incident. Use present tense and active voice. Question 23 (10 points)
Listen
Write a clear and concise static behavioral IOC that describes the initial access phase
of the cyber incident. Use present tense and active voice.
Paragraph
BI UA
ов
00
✓
58
11.
Question 24 (10 points)
Listen
Write a clear and concise static behavioral IOC that describes the execution phase of
the cyber incident. Use present tense and active voice.
Paragraph
BI U A
A
Question 25 (10 points)
Listen
Write a clear and concise static behavioral IOC that describes the command and
control phase of the cyber incident. Use present tense and active voice.
11. Question 26 (10 points)
Listen
Write a clear and concise static behavioral IOC that describes the Discovery:
Account Discovery phase of the cyber incident. Use present tense and active voice.
Paragraph
BI UAE
11.
Question 27 (8 points)
Listen
Write a clear and concise static behavioral IOC that describes the Discovery: File and
Directory Discovery phase of the cyber incident. Use present tense and active voice.
Paragraph
BI UA
Question 28 (10 points)
Listen
Write a clear and concise static behavioral IOC that describes the Exfiltration phase
of the cyber incident. Use present tense and active voice.
Paragraph
BI UA/n Instructions for Static Atomic IOC Section
In this section, your task is to fill in the correct, relevant static atomic indicator of
compromise (AIOC) for each prompt. You will receive one (1) point for each correct
answer up to a total of 16 points. Be sure to defang any potentially malicious IOCS
using square brackets as shown below.
WARNING. These are examples of correct format. They are NOT the correct
answers. If you put the examples in as correct answers I will give you a zero for the
entire quiz. Why is this warning here? Because students keep doing it!
IOC Type Potentially Malicious IOCS
Domain namemalicious.com
Email address jdoe@malicious.com
File name
malware.exe
C:/Windows/System32/malware.exe
URL
IPv4 address 192.0.2.128
File path
Defanged with square brackets
malicious[.]com
jdoe[@]malicious[.]com
malware[.]exe
C:/Windows/System32/malware[.]exe
http://www.malicious.com/malware.exehttp[:]//www[.]malicious[.]com/malware[.]exe
192.0.2[.]128 1. Internet Domain Name:
2. Email address:
3. Email subject:
4. Email attachment:
5. Malware URL:
6. Malware filename:
7. Created filename:
8. Protocol
9. Remote IP:
10. Local port:
11. Remote port:
12. File type 1 (first one in list):
13. File type 2 (second one in list):
14. File type 3 (third one in list):
15. File type 4 (fourth one in list):
16. File type 5 (fifth one in list):
