Question
Instructions Need typed answer fill in the correct, relevant static atomic indicator of compromise (AIOC) for each prompt. and AND use this for 23-28 https://attack.mitre.org//n Static Behavioral IOCS (Manually Graded) In this section, your task is to create static behavioral indicators of compromise (SBIOCS) for each phase of the cyber incident described in the scenario. You'll notice that each phase aligns with a specific tactic from the MITRE ATT&CK framework. But what exactly is a BIOC? Let's recall: Behavioral Indicators of Compromise are essentially narratives or stories of the activities that a threat actor, or a piece of malware, performs during a cyber incident. They aren't single data points, but rather, collections of multiple smaller indicators (both atomic and computed), tied together with logical context to provide a holistic view of the incident. For instance, an atomic indicator might be an IP address or an email subject line, while a computed indicator could be a file hash or regular expression. When we use logical connections to string these together - like noting that a file with a specific hash was downloaded from a particular IP address - we start to build a BIOC. For each phase of the incident in the scenario, you should aim to identify the relevant atomic and computed indicators and then construct a narrative, a story of what happened in that phase using logical links between the indicators. This will provide more meaningful insights about the cyber incident. Remember, your BIOCS should help someone who reads them understand the story of the incident: what the attacker did, how they did it, and what changes they caused in the system or network. As a standard of practice, your BIOC's must contain all relevant computed and atomic indicators to that BIOC. This requirement implies that all computed and atomic indicators must appear in at least one BIOC. In addition, write your BIOCS clearly and concisely in the present tense and active voice. To earn full points, map each BIOC to one or more MITRE ATT&CK Techniques by placing the technique number in braces after the phrase or sentence describing the technique in the format [ATT&CK Tactic}. A subject performs an action on an object [ATT&CK Technique). Here is an example: [Discovery] Code within the edg32.dll file searches victim host for accounts with a lockout threshold of zero (i.e., accounts that allow unlimited login attempts) [T1087). And don't forget, writing a good BIOC is like detective work - you're piecing together clues to get a clear picture of the incident. So put on your detective hat, and let's get started! Question 23 (10 points) Listen Write a clear and concise static behavioral IOC that describes the initial access phase of the cyber incident. Use present tense and active voice. Question 23 (10 points) Listen Write a clear and concise static behavioral IOC that describes the initial access phase of the cyber incident. Use present tense and active voice. Paragraph BI UA ов 00 ✓ 58 11. Question 24 (10 points) Listen Write a clear and concise static behavioral IOC that describes the execution phase of the cyber incident. Use present tense and active voice. Paragraph BI U A A Question 25 (10 points) Listen Write a clear and concise static behavioral IOC that describes the command and control phase of the cyber incident. Use present tense and active voice. 11. Question 26 (10 points) Listen Write a clear and concise static behavioral IOC that describes the Discovery: Account Discovery phase of the cyber incident. Use present tense and active voice. Paragraph BI UAE 11. Question 27 (8 points) Listen Write a clear and concise static behavioral IOC that describes the Discovery: File and Directory Discovery phase of the cyber incident. Use present tense and active voice. Paragraph BI UA Question 28 (10 points) Listen Write a clear and concise static behavioral IOC that describes the Exfiltration phase of the cyber incident. Use present tense and active voice. Paragraph BI UA/n Instructions for Static Atomic IOC Section In this section, your task is to fill in the correct, relevant static atomic indicator of compromise (AIOC) for each prompt. You will receive one (1) point for each correct answer up to a total of 16 points. Be sure to defang any potentially malicious IOCS using square brackets as shown below. WARNING. These are examples of correct format. They are NOT the correct answers. If you put the examples in as correct answers I will give you a zero for the entire quiz. Why is this warning here? Because students keep doing it! IOC Type Potentially Malicious IOCS Domain namemalicious.com Email address jdoe@malicious.com File name malware.exe C:/Windows/System32/malware.exe URL IPv4 address 192.0.2.128 File path Defanged with square brackets malicious[.]com jdoe[@]malicious[.]com malware[.]exe C:/Windows/System32/malware[.]exe http://www.malicious.com/malware.exehttp[:]//www[.]malicious[.]com/malware[.]exe 192.0.2[.]128 1. Internet Domain Name: 2. Email address: 3. Email subject: 4. Email attachment: 5. Malware URL: 6. Malware filename: 7. Created filename: 8. Protocol 9. Remote IP: 10. Local port: 11. Remote port: 12. File type 1 (first one in list): 13. File type 2 (second one in list): 14. File type 3 (third one in list): 15. File type 4 (fourth one in list): 16. File type 5 (fifth one in list):
Question image 1