12.02 Lab 7: Malware Triage Without Malware
Week 12 · 38 points · about 95 minutes · submit in Canvas
Goal
Take a real-shaped incident write-up and turn it into two structured things: a classification of what the malware was, and a map of what the operators did, in a vocabulary other defenders share.
You do not download, run, or analyze any malware in this course. You analyze a written record of an incident, which is what the overwhelming majority of security work actually consists of.
Objectives assessed
- 4.3: Classify malware by the CyBOK taxonomy and map an incident's observed behavior, including phishing used for initial access, to MITRE ATT&CK techniques.
(TLO 4)
Time estimate
| Step | Time |
|---|---|
| Read the incident report | 15 min |
| Step 1: classify | 20 min |
| Step 2: map to ATT&CK | 35 min |
| Step 3: initial access | 10 min |
| Step 4: what would have caught it | 15 min |
| Total | 95 min |
Before you start
- Read the NORTHWIND MEADOW incident report all the way through once before you start.
- CyBOK §6.1 (printed pages 202-205), a taxonomy of malware.
- CyBOK §6.2 (printed pages 205-207), malicious activities by malware.
- CyBOK §6.4 (printed pages 214-219), malware detection.
- CyBOK §7.2 (printed pages 236-242), the elements of a malicious operation.
- MITRE ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/
Using ATT&CK
ATT&CK is a catalog of what attackers do, organized into tactics (the goal: why they did it) and techniques (the method: how). A technique has an ID like T1566 and often sub-techniques like T1566.001.
The way to use it: take one sentence from the incident report, decide what the operators were trying to achieve, open that tactic's column in the matrix, and read down it until you find the technique that matches. It takes a few minutes per item at first. That is normal.
Steps
Step 1: Classify the malware
The incident involved at least three distinct pieces of malicious code: the macro in the attachment, the component downloaded on Day 0, and the payload that ran on Day 7.
For each of the three, using the taxonomy in CyBOK §6.1:
- Name it as the report describes it.
- Classify it along the dimensions CyBOK uses: is it standalone or does it need a host program? Is it persistent (installed on disk) or transient (running only in memory)?
- State its role in the operation, in one sentence.
Then answer two questions:
- The Day 0 component first ran without being written to disk, and only later dropped a copy for persistence. Using CyBOK §6.1, explain what that first stage costs a defender who relies on scanning files.
- Between Day 1 and Day 6 the operators moved between machines without installing anything, using tools already present. What is that technique commonly called, and (using CyBOK §6.4.2.1 and §6.4.2.3) why does it make host-based detection harder?
Step 2: Map the operation to ATT&CK
Build a table with at least twelve entries, covering at least six different ATT&CK tactics.
| # | What the report says (quote or close paraphrase) | Tactic | Technique ID | Technique name | Where in the report |
|---|
Rules:
- Every row must quote or closely paraphrase the report. If you cannot point at the sentence, do not include the row. This is the same discipline as Lab 2's last column, and it is worth the most points here.
- Cover the whole operation, not just the beginning. The report runs from Day 0 to Day 7 and the later tactics (credential access, defense evasion, collection, exfiltration, impact) are as important as the first one.
- Sub-technique IDs are welcome but not required.
T1566is fine;T1566.001is better if you are confident.
Tactics you should expect to find represented, though the exact set is up to you: initial access, execution, persistence, discovery, credential access, lateral movement, defense evasion, collection, command and control, exfiltration, impact.
Step 3: Initial access
The whole operation started with one email.
- Which ATT&CK technique covers it, and which sub-technique?
- The report notes several details about that email chosen to make it work: the sender domain, its registration date, the invoice number, the recipients, and the wording of the lure. Pick three and explain what each one was doing to increase the chance somebody opened it.
- The billing coordinator clicked through a macro warning banner. Was this a failure by that person? Argue a position in a short paragraph, using CyBOK §4.3 on human error from week 2. Both answers can be defended; the argument is what is graded.
- Four other people received the same message and one asked a colleague about it. What does that tell you about the organization's reporting process, and what one change would you make?
Step 4: What would have caught it
The endpoint agent raised a medium alert at 09:26 on Day 0, four minutes after the macro ran and seven days before the ransomware. It was never reviewed, in a queue of about 400 medium alerts per day.
- Identify three separate points in the timeline where the operation could have been detected or stopped. For each, say what would have had to be in place.
- For one of those three, write a detection rule in plain English: what data source it reads, what condition it fires on, and what a defender should do when it fires. You are not writing code: you are writing the sentence a detection engineer would turn into code.
- The alert that did fire was correct. It was ignored because of volume. In two or three sentences, say what that suggests about where the failure actually was. (Week 15 gives this problem a name and some arithmetic. You are meeting it here first.)
What to submit
One Canvas submission containing your Step 1 classifications and answers, your Step 2 ATT&CK table, and your Step 3 and Step 4 answers, clearly numbered.
Rubric
| Row | What is assessed | Points |
|---|---|---|
| 1 | Three malicious components identified and classified using CyBOK §6.1's dimensions; the fileless and living-off-the-land questions answered with reference to §6.1 and §6.4 | 10 |
| 2 | ATT&CK table with at least 12 entries across at least 6 tactics; technique IDs correct; the operation covered through to impact, not just initial access | 16 |
| 3 | Initial access technique correctly identified; three lure elements analyzed; a defended position on the human-error question; a reporting-process observation and recommendation | 6 |
| 4 | Three detection opportunities identified with what each requires; one written as a plain-English rule naming its data source, condition, and response; the alert-volume observation | 6 |
| Total | 38 |
What loses points in row 2: rows with no traceable sentence in the report, and tables that stop at initial access and execution. Half of this operation happened after Day 1.
AI disclosure
You may use AI tools on this assignment. If you do, add one or two sentences saying which tool and what for, per the AI policy.
Be careful with technique IDs from an AI tool: they are frequently plausible and wrong. Check each one against https://attack.mitre.org/ before you submit it. An incorrect ID scores zero for that row whether or not the technique name beside it is right.