Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Example reports including capabilites/behaviours #3

Open
3c7 opened this issue Jun 14, 2017 · 3 comments
Open

Example reports including capabilites/behaviours #3

3c7 opened this issue Jun 14, 2017 · 3 comments

Comments

@3c7
Copy link

3c7 commented Jun 14, 2017

Hello MAEC-Team,

I'm not sure if this is the right place, but I'm wondering if there are any reports available that include capabilites and behaviours according to the MAEC-language as these datasets only using actions?

Searched a lot, but really found nothing useful.

@ikiril01
Copy link
Member

Hi @3c7, great question. Unfortunately the only examples we currently have with Capabilities and Behaviours are the manually generated ones: https://github.com/MAECProject/schemas/tree/master/examples

However, we are working on an updated output module for Cuckoo Sandbox that will likely include support for Capabilities and Behaviors. Also, Joe Sandbox and some other tools do currently output Behaviors, for example:

https://www.joesecurity.org/resources/wannacry/maecreport-db349b97c37d22f5ea1d1841e3c89eb4.xml

Hope this helps a bit.

@3c7
Copy link
Author

3c7 commented Jun 25, 2017

Hey @ikiril01, thank you very much for your answer. That helps for sure. :)

I'm using MAEC as a base for my bachelor thesis and I created an overview of Capabilites and Behaviours and just recognized that the WannaCry sample does not include the combination of availability violation / compromise data availability / encrypt files Capabilities and Behaviours. I'd expect that in a ransomware MAEC report, especially if found during analysis. 😄

@kloepma
Copy link

kloepma commented Mar 15, 2021

Hello MAEC Team

I'm looking for MAEC 5.0 real world data sets. Something like the wannacry report referenced above would be great if it were MAEC 5.0. Would you be able to point me in the right direction to find some MAEC 5.0 real world data sets?

Thank you for your time.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants