12.01 Readings and Lecture Notes
April 5-11 · Reading: 16 pages · About 3 hrs with the worked example
What to do this week, and when it is due, is on the Module 12 Overview.
Readings
| Source | Sections | Printed pages | Length | Time |
|---|---|---|---|---|
| CyBOK v1.1.0 | §6.1 A taxonomy of Malware | 202-205 | 3 pp | 25 min |
| CyBOK v1.1.0 | §6.2 Malicious Activities by Malware | 205-207 | 2 pp | 15 min |
| CyBOK v1.1.0 | §6.4 Malware Detection | 214-219 | 5 pp | 40 min |
| CyBOK v1.1.0 | §7.2 The Elements of a Malicious Operation | 236-242 | 6 pp | 40 min |
| MITRE ATT&CK | Enterprise matrix, and a few technique pages | none | browse | 20 min |
MITRE ATT&CK: https://attack.mitre.org/matrices/enterprise/. You are not assigned §6.3 (malware analysis techniques, static, dynamic, fuzzing, symbolic execution), which assumes reverse engineering background. Skim it if you are curious.
Using ATT&CK
ATT&CK is a catalog of what attackers actually do, built from observed incidents. Two levels matter:
- Tactics: the goal. Why they did this. Reconnaissance, Resource Development, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, Impact.
- Techniques: the method. How.
T1566Phishing,T1053Scheduled Task/Job,T1110Brute Force.
The method that works: take one sentence from an incident report, ask what the operators were trying to achieve, open that tactic's column, and read down it until something matches. It takes a few minutes an item at first and gets fast.
The discipline that matters: every mapping traces to a specific sentence. If you cannot point at the line, do not make the claim.
Worked example
Here are four rows of the kind Lab 7 asks for, drawn from the NORTHWIND MEADOW incident report.
| What the report says | Tactic | Technique | Why |
|---|---|---|---|
"received an email appearing to come from a medical-supply vendor... attached a file named Invoice_44192_Cascade.xlsm" | Initial Access | T1566.001 Phishing: Spearphishing Attachment | A targeted email with a malicious attachment. The sub-technique is attachment rather than link. |
| "The macro... ran a PowerShell command that downloaded a second file... and executed it in memory. It did not write that payload to disk." | Execution | T1059.001 Command and Scripting Interpreter: PowerShell | Execution via a scripting interpreter already present on the host. |
"Created a scheduled task named MicrosoftEdgeUpdateTaskMachineUA set to run every 60 minutes" | Persistence | T1053.005 Scheduled Task/Job: Scheduled Task | Survives reboot. Note the name chosen to blend into a list of legitimate tasks: that is also T1036 Masquerading, under Defense Evasion. |
| "queried Active Directory for the list of domain administrators, the list of file servers, and the membership of several groups" | Discovery | T1087.002 Account Discovery: Domain Account | Learning the environment before deciding where to go. |
Four rows, four tactics, every one quoted. Lab 7 wants twelve rows across at least six tactics, and the operation runs to Day 7, so a table that stops at Execution is missing most of it.
Two things the report is really about
Fileless execution. The Day 0 payload ran without being written to disk (the copy in Temp came later, for persistence). §6.1 explains what that costs a defender: detection built on scanning files has nothing to scan. The artifact exists only in a running process's memory, and it is gone at reboot, which also means it is gone before an investigator arrives. Detection has to shift to behavior: what did that process do, what did it connect to.
Living off the land. From Day 1 to Day 6 the operators installed no new malware on the hosts they moved to. They used the operating system's own remote administration tooling and a credential they recovered from a browser store. That defeats host-based detection for a simple reason: the tools are legitimate, signed, and used by administrators every day. There is no bad file to find. The only signal is that this account used this tool on this host at this hour, which requires knowing what normal looks like, the anomaly detection of §6.4.2.1, and week 15's subject.
Three components, three classifications
The incident involved three distinct pieces of code, and §6.1's dimensions separate them cleanly. In §6.1, persistent means installed in storage (usually the file system) and transient means memory-resident, gone at reboot, so "persistent or transient" and "disk or memory" are one question:
| Standalone or host-dependent? | Persistent (on disk) or transient (memory-resident)? | |
|---|---|---|
The .xlsm macro | Host-dependent: it needs the spreadsheet application to run it | Persistent: it sits on disk inside the attachment |
| The Day 0 downloaded component | Standalone | Transient on first run (executed in memory, never written to disk), then persistent once a copy was staged in AppData\Local\Temp and the scheduled task pointed at it |
| The Day 7 ransomware payload | Standalone | Persistent: it ran from disk, briefly, on the hosts it reached |
Being able to say which is which is what stops "malware" from being one undifferentiated word. These three had different jobs, different lifetimes, and would have needed three different detection approaches.
The thing that actually went wrong
At 09:26 on Day 0, four minutes after the macro ran, the endpoint agent raised a medium alert about the PowerShell execution. It was correct. It entered a queue averaging 400 medium alerts a day and was never reviewed.
Seven days later the hospital ran on paper for nine days.
Nothing about that failure is technical. The sensor worked, the rule fired, the alert was accurate. Hold onto it: week 15 gives it a name and some arithmetic.
Key terms
| Term | Short form |
|---|---|
| Virus / worm / trojan | Host-dependent and self-replicating / standalone and self-replicating / disguised as something wanted. |
| Dropper | Small first-stage code whose job is to fetch and run the real payload. |
| Fileless malware | Executes in memory without being written to disk. |
| Living off the land | Using legitimate tools already present, so there is no malicious file to find. |
| Command and control (C2) | The channel by which operators direct compromised hosts. |
| Beaconing | Regular periodic C2 check-ins. A metadata pattern, visible without decryption. |
| Persistence | A mechanism ensuring access survives reboot. |
| Lateral movement | Moving from one compromised host to others. |
| Exfiltration | Copying data out. |
| Indicator of compromise (IoC) | An observable artifact: a hash, a domain, a filename. Cheap to change. |
| TTPs | Tactics, techniques, and procedures. Harder for an attacker to change than IoCs. |
| MITRE ATT&CK | The shared catalog of tactics and techniques. |
Looking ahead
Week 13 goes down to the source code: a single C function with a textbook bug, the stack layout it produces, and the mitigations that make it harder to exploit without removing it. It ends with the question the second half of this course keeps circling: what evidence would convince you something is actually fixed?