Files
cti/pre-attack/attack-pattern/attack-pattern--2011ffeb-8003-41ef-b962-9d1cbfa35e6d.json
T
2018-04-18 11:24:20 -07:00

40 lines
2.8 KiB
JSON

{
"objects": [
{
"name": "Determine physical locations",
"created": "2017-12-14T16:46:06.044Z",
"created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
"description": "Physical locality information may be used by an adversary to shape social engineering attempts (language, culture, events, weather, etc.) or to plan for physical actions such as dumpster diving or attempting to access a facility. (Citation: RSA-APTRecon)\n\nDetectable by Common Defenses: No\n\nDetectable by Common Defenses explanation: Adversary searches publicly available sources that list physical locations that cannot be monitored by a defender or are not necessarily monitored (e.g., all IP addresses touching their public web space listing physical locations).\n\nDifficulty for the Adversary: Yes\n\nDifficulty for the Adversary explanation: Most corporations now list their locations on public facing websites. Some challenge still exists to find covert or sensitive locations.",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-pre-attack",
"phase_name": "organizational-information-gathering"
}
],
"external_references": [
{
"url": "https://attack.mitre.org/pre-attack/index.php/Technique/PRE-T1059",
"source_name": "mitre-pre-attack",
"external_id": "PRE-T1059"
},
{
"description": "Rotem Kerner. (2015, October). RECONNAISSANCE: A Walkthrough of the \u201cAPT\u201d Intelligence Gathering Process. Retrieved March 1, 2017.",
"source_name": "RSA-APTRecon"
}
],
"object_marking_refs": [
"marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
],
"id": "attack-pattern--2011ffeb-8003-41ef-b962-9d1cbfa35e6d",
"modified": "2018-04-18T17:59:24.739Z",
"x_mitre_detectable_by_common_defenses": "No",
"x_mitre_detectable_by_common_defenses_explanation": "Adversary searches publicly available sources that list physical locations that cannot be monitored by a defender or are not necessarily monitored (e.g., all IP addresses touching their public web space listing physical locations).",
"x_mitre_difficulty_for_adversary": "Yes",
"x_mitre_difficulty_for_adversary_explanation": "Most corporations now list their locations on public facing websites. Some challenge still exists to find covert or sensitive locations.",
"type": "attack-pattern"
}
],
"type": "bundle",
"id": "bundle--d68080fb-3cf2-48eb-90c8-70c5c74bd565",
"spec_version": "2.0"
}