{"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nGazer can establish persistence by creating a .lnk file in the Start menu.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBisonal has the capability to download files to execute on the victim\u2019s machine.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nJPIN's installer/uninstaller component deletes itself if it encounters a version of Windows earlier than Windows XP or identifies security-related processes running.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nFatDuke can collect the user name, Windows version, computer name, and available space on discs from a compromised host.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nmenuPass executes commands using a command-line interface and reverse shell. The group has used a modified version of pentesting script wmiexec.vbs to execute commands. menuPass has used malicious macros embedded inside Office documents to execute files.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nChaes has collected system information, including the machine name and OS version.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDerusbi is capable of deleting files. It has been observed loading a Linux Kernel Module and then deleting it from the hard disk as well as overwriting the data with null bytes.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nSeveral tools used by Suckfly have been command-line driven.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAgent Tesla can collect the system's computer name and also has the capability to collect information on the processor, memory, OS, and video card from the system.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBRONZE BUTLER has used batch scripts and the command-line interface for execution.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCarbon can list the processes on the victim\u2019s machine.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nRocke has used uname -m to collect the name and information about the infected system's kernel.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nInnaputRAT has a command to delete files.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nABK has the ability to use HTTP in communications with C2.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nKOPILUWAK has used HTTP POST requests to send data to C2.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nInvisiMole uses HTTP for C2 communications.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nWIRTE has used Base64 to decode malicious VBS script.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nFIN7 used the command prompt to launch commands on the victim\u2019s machine.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\n3PARA RAT uses HTTP for command and control.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nIndustroyer decrypts code to connect to a remote C2 server.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDDKONG downloads and uploads files on the victim\u2019s machine.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nHTTPBrowser deletes its original installer file once installation is complete.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDiavol has used HTTP GET and POST requests for C2.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAstaroth spawns a CMD process to execute commands.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBumblebee can use `cmd.exe` to drop and run files.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBackConfig has the ability to remove files and folders related to previous infections.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCarberp has connected to C2 servers via HTTP.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAPT38 have enumerated files and directories, or searched in specific locations within a compromised host.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nGuLoader can delete its executable from the AppData\\Local\\Temp directory on the compromised host.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAPT38 used a backdoor, NESTEGG, that has the capability to download and upload files to and from a victim\u2019s machine.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nFunnyDream can delete files including its dropper component.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nGet2 has the ability to identify running processes on an infected host.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nClambling can enumerate the IP address of a compromised machine.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nWater Curupira Pikabot Distribution used Curl.exe to download the Pikabot payload from an external server, saving the file to the victim machine's temporary directory.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nThreat Group-3390 actors use NBTscan to discover vulnerable systems.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDacls can scan directories on a compromised host.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBLUELIGHT can enumerate files and collect associated metadata.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAquatic Panda has deleted malicious executables from compromised machines.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBADFLICK can decode shellcode using a custom rotating XOR cipher.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBITTER has downloaded additional malware and tools onto a compromised host.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAcidRain identifies specific files and directories in the Linux operating system associated with storage devices.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nLizar has a plugin designed to obtain a list of processes.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nTA551 has used cmd.exe to execute commands.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nEvilGrab adds a Registry Run key for ctfmon.exe to establish persistence.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nSeveral Lazarus Group malware families collect information on the type and version of the victim OS, as well as the victim computer name and CPU information. A Destover-like variant used by Lazarus Group also collects disk space information and sends it to its C2 server.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nMacMa can enumerate running processes.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nMuddyWater has used malware that checked if the ProgramData folder had folders or files with the keywords \"Kasper,\" \"Panda,\" or \"ESET.\"\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nSowbug identified and extracted all Word documents on a server by using a command containing * .doc and *.docx. The actors also searched for documents based on a specific date range and attempted to identify all installed software on a victim.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAria-body has the ability to delete files and directories on compromised hosts.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nInnaputRAT gathers volume drive information and system information.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBBK has the ability to download files from C2 to the infected host.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCrackMapExec can enumerate the system drives and associated system name.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nPatchwork removed certain files and replaced them so they could not be retrieved.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nRocke's miner has created UPX-packed files in the Windows Start Menu Folder.\n"}], "ground_truth": "T1547.001", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nKGH_SPY can decrypt encrypted strings and write them to a newly created folder.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nFoggyWeb can be decrypted in memory using a Lightweight Encryption Algorithm -128 key and decoded using a XOR key.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDuring Frankenstein, the threat actors downloaded files and tools onto a victim machine.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nToddyCat has run `cmd /c start /b tasklist` to enumerate processes.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nApostle writes batch scripts to disk, such as system.bat and remover.bat, that perform various anti-analysis and anti-forensic tasks, before finally deleting themselves at the end of execution. Apostle attempts to delete itself after encryption or wiping operations are complete and before shutting down the victim machine.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nFELIXROOT adds a shortcut file to the startup folder for persistence.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nEmotet has used a self-extracting RAR file to deliver modules to victims. Emotet has also extracted embedded executables from files using hard-coded buffer offsets.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAPT37's Freenki malware lists running processes using the Microsoft Windows API.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nINC Ransomware can use the Microsoft Win32 Restart Manager to kill processes with a specific handle or that are accessing resources it wants to encrypt.\n"}], "ground_truth": "T1057", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nHAFNIUM has used `tasklist` to enumerate processes.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nOne persistence mechanism used by CozyCar is to set itself to be executed at system startup by adding a Registry value under one of the following Registry keys:
HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\
HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\
HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run
HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run\n
"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCORESHELL downloads another dropper from its C2 server.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBackdoor.Oldrea collects information about available drives, default browser, desktop file list, My Documents, Internet history, program files, and root of available drives. It also searches for ICS-related software files.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nLunarMail can decrypt strings to retrieve configuration settings.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nFlagpro has dropped an executable file to the startup directory.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDarkTortilla can enumerate a list of running processes on a compromised system.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nHydraq creates a backdoor through which remote attackers can retrieve IP addresses of compromised machines.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nMalteiro collects the machine information, system architecture, the OS version, computer name, and Windows product name.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nApostle compiled code is obfuscated in an unspecified fashion prior to delivery to victims.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDipsind can spawn remote shells.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nZIRCONIUM has used a tool to open a Windows Command Shell on a remote host.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAPT18 can list files information for specific directories.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nTurla surveys a system upon check-in to discover network configuration details using the arp -a, nbtstat -n, net config, ipconfig /all, and route commands, as well as NBTscan. Turla RPC backdoors have also retrieved registered RPC interface information from process memory.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nGelsemium can use HTTP/S in C2 communications.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nFlawedAmmyy can collect the victim's operating system and computer name during the initial infection.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nEpic uses the tasklist /v command to obtain a list of processes.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nRancor has downloaded additional malware, including by using certutil.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCSPY Downloader can download additional tools to a compromised host.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDustySky collects information about running processes from victims.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nINC Ransomware can run `CryptStringToBinaryA` to decrypt base64 content containing its ransom note.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nGravityRAT collects the victim IP address, MAC address, as well as the victim account domain name.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCaterpillar WebShell has a module to gather information from the compromrised asset, including the computer version, computer name, IIS version, and more.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDuring C0015, the threat actors conducted a file listing discovery against multiple hosts to ensure locker encryption was successful.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nKe3chang malware including RoyalCli and BS2005 have communicated over HTTP with the C2 server through Internet Explorer by using the COM interface IWebBrowser2.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDownPaper uses PowerShell to add a Registry Run key in order to establish persistence.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBADFLICK has searched for files on the infected host.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDuring C0015, the threat actors downloaded additional tools and files onto a compromised network.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nMoonstone Sleet delivered payloads using multiple rounds of obfuscation and encoding to evade defenses and analysis.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nHotCroissant has the ability to list running processes on the infected host.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nGeminiDuke collects information on running processes and environment variables from the victim.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nadmin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about files and directories: dir c:\\ >> %temp%\\download dir \"c:\\Documents and Settings\" >> %temp%\\download dir \"c:\\Program Files\\\" >> %temp%\\download dir d:\\ >> %temp%\\download\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nTonto Team has downloaded malicious DLLs which served as a ShadowPad loader.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDuring Operation Wocao, the threat actors consistently removed traces of their activity by first overwriting a file using `/c cd /d c:\\windows\\temp\\ & copy \\\\\\c$\\windows\\system32\\devmgr.dll \\\\\\c$\\windows\\temp\\LMAKSW.ps1 /y` and then deleting the overwritten file using `/c cd /d c:\\windows\\temp\\ & del \\\\\\c$\\windows\\temp\\LMAKSW.ps1`.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDarkGate uses the Delphi methods Sysutils::DiskSize and GlobalMemoryStatusEx to collect disk size and physical memory as part of the malware's anti-analysis checks for running in a virtualized environment. DarkGate will gather various system information such as display adapter description, operating system type and version, processor type, and RAM amount.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBoxCaon can collect the victim's MAC address by using the GetAdaptersInfo API.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nGorgon Group malware can decode contents from a payload that was Base64 encoded and write the contents to a file.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBACKSPACE achieves persistence by creating a shortcut to itself in the CSIDL_STARTUP directory.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAgent Tesla can collect the IP address of the victim machine and spawn instances of netsh.exe to enumerate wireless settings.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nThreat Group-3390 has downloaded additional malware and tools, including through the use of `certutil`, onto a compromised host .\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nFELIXROOT uses HTTP and HTTPS to communicate with the C2 server.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nChinoxy has established persistence via the `HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run` registry key and by loading a dropper to ``.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nHydraq creates a backdoor through which remote attackers can retrieve information such as computer name, OS version, processor speed, memory size, and CPU speed.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBrute Ratel C4 can download files to compromised hosts.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAuTo Stealer can use HTTP to communicate with its C2 servers.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nWinter Vivern executed PowerShell scripts to create scheduled tasks to retrieve remotely-hosted payloads.\n"}], "ground_truth": "T1105", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nA dropper used by Putter Panda installs itself into the ASEP Registry key HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run with a value named McUpdate.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDuring Operation CuckooBees, the threat actors used `ipconfig`, `nbtstat`, `tracert`, `route print`, and `cat /etc/hosts` commands.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDuring Operation Sharpshooter, a first-stage downloader installed Rising Sun to `%Startup%\\mssync.exe` on a compromised host.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCrimson can decode its encoded PE file prior to execution.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nElise is capable of launching a remote shell on the host to delete itself.\n"}], "ground_truth": "T1070.004", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nSome versions of DarkGate search for the hard-coded folder C:\\Program Files\\e Carte Bleue.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAvosLocker has searched for files and directories on a compromised network.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDarkGate uses a malicious Windows Batch script to run the Windows code utility to retrieve follow-on script payloads.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDark Caracal's version of Bandook adds a registry key to HKEY_USERS\\Software\\Microsoft\\Windows\\CurrentVersion\\Run for persistence.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nWinter Vivern distributed Windows batch scripts disguised as virus scanners to prompt download of malicious payloads using built-in system tools.\n"}], "ground_truth": "T1059.003", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBLUELIGHT can uninstall itself.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAutoIt backdoor is capable of identifying documents on the victim with the following extensions: .doc; .pdf, .csv, .ppt, .docx, .pst, .xls, .xlsx, .pptx, and .jpeg.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDarkTortilla can decrypt its payload and associated configuration elements using the Rijndael cipher.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nOrangeworm has used HTTP for C2.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBabyShark has added a Registry key to ensure all future macros are enabled for Microsoft Word and Excel as well as for additional persistence.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDarkWatchman has the ability to enumerate file and folder names.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCosmicDuke can use HTTP or HTTPS for command and control to hard-coded C2 servers.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCardinal RAT can download and execute additional payloads.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDaggerfly utilizes victim machine operating system information to create custom User Agent strings for subsequent command and control communication.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nThe IceApple Server Variable Dumper module iterates over all server variables present for the current request and returns them to the adversary.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nChChes collects the victim hostname, window resolution, and Microsoft Windows version.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nIPsec Helper connects to command and control servers via HTTP POST requests based on parameters hard-coded into the malware.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDaserf uses HTTP for C2.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCalisto has the capability to upload and download files to the victim's machine.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDuring Operation CuckooBees, the threat actors used batch scripts to perform reconnaissance.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAPT28 has deployed malware that has copied itself to the startup directory for persistence.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nFlawedAmmyy has used HTTP for C2.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nTeamTNT has used batch scripts to download tools and executing cryptocurrency miners.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDuring Operation Dream Job, Lazarus Group launched malicious DLL files, created new folders, and renamed folders with the use of the Windows command shell.\n"}], "ground_truth": "T1059.003", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nLinfo creates a backdoor through which remote attackers can retrieve a list of running processes.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nTropic Trooper has created shortcuts in the Startup folder to establish persistence.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAppleJeus has collected the victim host information after infection.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nFIN8 has used HTTPS for command and control.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nFIN7 has downloaded additional malware to execute on the victim's machine, including by using a PowerShell script to launch shellcode that retrieves an additional payload.\n"}], "ground_truth": "T1105", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDEADEYE can run `cmd /c copy /y /b C:\\Users\\public\\syslog_6-*.dat C:\\Users\\public\\syslog.dll` to combine separated sections of code into a single DLL prior to execution.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAPT41 used cmd.exe /c to execute commands on remote machines. APT41 used a batch file to install persistence for the Cobalt Strike BEACON loader.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nKV Botnet Activity removes on-disk copies of tools and other artifacts after it the primary botnet payload has been loaded into memory on the victim device.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBrute Ratel C4 can enumerate all processes and locate specific process IDs .\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBandook has decoded its PowerShell script.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nTeamTNT has searched for rival malware and removes it if found. TeamTNT has also searched for running processes containing the strings aliyun or liyun to identify machines running Alibaba Cloud Security tools.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nEvilBunny has executed C2 commands directly via HTTP.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBLACKCOFFEE has the capability to discover processes.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nHigaisa used certutil to decode Base64 binaries at runtime and a 16-byte XOR key to decrypt data.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBabyShark has used dir to search for \"programfiles\" and \"appdata\".\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDuring C0017, APT41 used `cmd.exe /c ping %userdomain%` for discovery.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nTeamTNT has enumerated the host machine\u2019s IP address.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nVolt Typhoon has used the Windows command line to perform hands-on-keyboard activities in targeted environments including for discovery.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBankshot marks files to be deleted upon the next system reboot and uninstalls and removes itself from the system.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAvosLocker has discovered system processes by calling `RmGetList`.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nSidewinder has used malware to collect information on network interfaces, including the MAC address.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDuring Night Dragon, threat actors used HTTP for C2.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nEpic uses the nbtstat -n and nbtstat -s commands on the victim\u2019s machine.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nPatchwork payloads download additional files from the C2 server.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nRedCurl has searched for and collected files on local and network drives.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBoomBox has the ability to download next stage malware components to a compromised system.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nHEXANE has downloaded additional payloads and malicious scripts onto a compromised host.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nTurla has used a custom decryption routine, which pulls key and salt values from other artifacts such as a WMI filter or PowerShell Profile, to decode encrypted PowerShell payloads.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nTeamTNT has added batch scripts to the startup folder.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nVolt Typhoon has downloaded an outdated version of comsvcs.dll to a compromised domain controller in a non-standard folder.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAPT32 established persistence using Registry Run keys, both to execute PowerShell and VBS scripts as well as to execute their backdoor directly.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAria-body has the ability to identify the hostname, computer name, Windows version, processor speed, machine GUID, and disk information on a compromised host.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDarkTortilla has used HTTP and HTTPS for C2.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAria-body has the ability to gather metadata from a file and to search for file and directory names.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAction RAT has the ability to collect drive and file information on an infected machine.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAPT18 uses HTTP for C2 communications.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nWinter Vivern uses HTTP and HTTPS protocols for exfiltration and command and control activity.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nExplosive has used HTTP for communication.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nTurla has used shellcode to download Meterpreter after compromising a victim.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCardinal RAT can execute commands.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDragonfly has used batch scripts to enumerate network information, including information about trusts, zones, and the domain.\n"}], "ground_truth": "T1016", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nWinter Vivern delivered exploit payloads via base64-encoded payloads in malicious email messages.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBundlore has used openssl to decrypt AES encrypted payload data. Bundlore has also used base64 and RC4 with a hardcoded key to deobfuscate data.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nRocke has deleted files on infected machines.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAuditCred uses XOR and RC4 to perform decryption on the code functions.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBundlore has used the ps command to list processes.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nConti can discover files on a local system.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCookieMiner has used Google Chrome's decryption and extraction operations.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nMuddyWater has used malware to collect the victim\u2019s IP address and domain name.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAn APT28 loader Trojan will enumerate the victim's processes searching for explorer.exe if its current process does not have necessary permissions.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nThe reconnaissance modules used with Duqu can collect information on network configuration.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAn APT19 HTTP malware variant establishes persistence by setting the Registry key HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Windows Debug Tools-%LOCALAPPDATA%\\.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBLUELIGHT can collect IP information from the victim\u2019s machine.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nMolerats saved malicious files within the AppData and Startup folders to maintain persistence.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nConti can enumerate through all open processes to search for any that have the string \u201csql\u201d in their process name.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nHAFNIUM has used `cmd.exe` to execute commands on the victim's machine.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAkira examines files prior to encryption to determine if they meet requirements for encryption and can be encrypted by the ransomware. These checks are performed through native Windows functions such as GetFileAttributesW.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nSideCopy has identified the IP address of a compromised host.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCyclops Blink can use the Linux API `statvfs` to enumerate the current working directory.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nThreat Group-3390's malware can add a Registry key to `Software\\Microsoft\\Windows\\CurrentVersion\\Run` for persistence.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\ncan collect system information, including computer name, system manufacturer, IsDebuggerPresent state, and execution path.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nFoggyWeb has the ability to communicate with C2 servers over HTTP GET/POST requests.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nGootloader can create an autorun entry for a PowerShell script to run at reboot.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nGazer has commands to delete files and persistence mechanisms from the victim.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nFIN10 has executed malicious .bat files containing PowerShell commands.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nTropic Trooper has used a delivered trojan to download additional files.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nTeamTNT has used a payload that removes itself after running. TeamTNT also has deleted locally staged files for collecting credentials or scan results for local IP addresses after exfiltrating them.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nFIN5 uses SDelete to clean up the environment and attempt to prevent detection.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nToddyCat has run scripts to enumerate recently modified documents having either a .pdf, .doc, .docx, .xls or .xlsx extension.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDridex has collected the computer name and OS architecture information from the system.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nMagic Hound malware has used Registry Run keys to establish persistence.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBADFLICK has captured victim computer name, memory space, and CPU details.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nGamaredon Group tools decrypted additional payloads from the C2. Gamaredon Group has also decoded base64-encoded source code of a downloader. Additionally, Gamaredon Group has decoded Telegram content to reveal the IP address for C2 communications.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAPT32 has collected the OS version and computer name from victims. One of the group's backdoors can also query the Windows Registry to gather system information, and another macOS backdoor performs a fingerprint of the machine on its first connection to the C&C server. APT32 executed shellcode to identify the name of the infected host.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBisonal can obtain a list of running processes on the victim\u2019s machine.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDuring Operation Dream Job, Lazarus Group downloaded multistage malware and tools onto a compromised host.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nMustang Panda has created the registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\AdobelmdyU to maintain persistence.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nWindshift has used tools to deploy additional payloads to compromised hosts.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCobalt Group deleted the DLL dropper from the victim\u2019s machine to cover their tracks.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAdFind can extract subnet information from Active Directory.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAction RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCARROTBALL has the ability to download and install a remote payload.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nKimsuky has decoded malicious VBScripts using Base64.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nIxeshe has a command to delete a file from the machine.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAmadey can identify the IP address of a victim machine.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBandook has a command to delete a file.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBlackCat can obtain the computer name and UUID, and enumerate local drives.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nTropic Trooper has used scripts to collect the host's network topology.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDUSTTRAP can enumerate running processes.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nWindigo has used a script to check for the presence of files created by OpenSSH backdoors.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAvosLocker has been executed via the `RunOnce` Registry key to run itself on safe mode.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDanBot has the ability to execute arbitrary commands via `cmd.exe`.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nGALLIUM used ipconfig /all to obtain information about the victim network configuration. The group also ran a modified version of NBTscan to identify available NetBIOS name servers.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAPT3 has a tool that can list out currently running processes.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nFIN8 has used remote code execution to download subsequent payloads.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCarbanak lists running processes.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nLazarus Group malware IndiaIndia obtains and sends to its C2 server information about the first network interface card\u2019s configuration, including IP address, gateways, subnet mask, DHCP information, and whether WINS is available.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDuring Operation Honeybee, malicious files were decoded prior to execution.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAPT5 has used Windows-based utilities to carry out tasks including tasklist.exe.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nKessel has decrypted the binary's configuration once the main function was launched.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAuditCred can delete files from the system.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nPatchwork has added the path of its second-stage malware to the startup folder to achieve persistence. One of its file stealers has also persisted by adding a Registry Run key.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBRONZE BUTLER has used a batch script that adds a Registry Run key to establish malware persistence.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nChrommme can decrypt its encrypted internal code.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBUBBLEWRAP can communicate using HTTP or HTTPS.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nMoonstone Sleet has gathered information on victim systems.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAPT3 places scripts in the startup folder for persistence.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDUSTTRAP can execute commands via `cmd.exe`.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nGravityRAT collects the MAC address, computer name, and CPU information.\n"}], "ground_truth": "T1082", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nGazer communicates with its C2 servers over HTTP.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nEarth Lusca has used certutil to decode a string into a cabinet file.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nGamaredon Group tools can delete files used during an operation.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nChrommme has the ability to list drives and obtain the computer name of a compromised host.\n"}], "ground_truth": "T1082", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nFunnyDream can parse the `ProxyServer` string in the Registry to discover http proxies.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCatchamas gathers the Mac address, IP address, and the network adapter information from the victim\u2019s machine.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nConti has decrypted its payload using a hardcoded AES-256 key.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCreepyDrive can download files to the compromised host.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDuring FunnyDream, the threat actors used ipconfig for discovery on remote systems.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nHermeticWiper has the ability to overwrite its own file with random bites.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBazar can decrypt downloaded payloads. Bazar also resolves strings and other artifacts at runtime.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nKazuar gathers information about network adapters.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nKe3chang uses command-line interaction to search files and directories.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nRedCurl has used the Windows Command Prompt to execute commands.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nFerocious can delete files from a compromised host.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCARROTBAT has the ability to execute command line arguments on a compromised host.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nEvilBunny has created Registry keys for persistence in HKLM|HKCU\\\u2026\\CurrentVersion\\Run.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nLater implants used by APT28, such as CHOPSTICK, use a blend of HTTP, HTTPS, and other legitimate channels for C2, depending on module configuration.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nMalteiro has the ability to deobfuscate downloaded files prior to execution.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nSidewinder has used tools to collect the computer name, OS version, installed hotfixes, as well as information regarding the memory and processor on a compromised host.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nOilRig has run tasklist on a victim's machine.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAttor\u2019s plugin deletes the collected files and log files after exfiltration.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBackdoor.Oldrea collects information about the Internet adapter configuration.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nClambling can browse directories on a compromised host.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDuring C0017, APT41 issued `ping -n 1 .split-1+` commands to find the volume serial number of compromised systems.\n"}], "ground_truth": "T1082", "generated_content": "T1082"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCarbon can collect the IP address of the victims and other computers on the network using the commands: ipconfig -all nbtstat -n, and nbtstat -s.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBADNEWS is capable of executing commands via cmd.exe.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nChChes establishes persistence by adding a Registry Run key.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBoxCaon can execute arbitrary commands and utilize the \"ComSpec\" environment variable.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nEVILNUM can achieve persistence through the Registry Run key.\n"}], "ground_truth": "T1547.001", "generated_content": "T1547.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCreepyDrive can specify the local file path to upload files from.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBankshot uses HTTP for command and control communication.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAria-body has used HTTP in C2 communications.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCrimson has the ability to delete files from a compromised host.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nVarious implementations of CHOPSTICK communicate with C2 over HTTP.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDuring its initial execution, BACKSPACE extracts operating system information from the infected host.\n"}], "ground_truth": "T1082", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nOne variant of CloudDuke uses HTTP and HTTPS for C2.\n"}], "ground_truth": "T1071.001", "generated_content": "T1071.001"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDownPaper uses the command line.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBackdoor.Oldrea collects information about running processes.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBad Rabbit can enumerate all running processes to compare hashes.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nHi-Zor deletes its RAT installer file as it executes its DLL payload file.\n"}], "ground_truth": "T1070.004", "generated_content": "T1070.004"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nConfucius has used a file stealer that can examine system drives, including those other than the C drive.\n"}], "ground_truth": "T1082", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nAvenger has the ability to download files from C2 to a compromised host.\n"}], "ground_truth": "T1105", "generated_content": "T1105"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBackConfig has used a custom routine to decrypt strings.\n"}], "ground_truth": "T1140", "generated_content": "T1140"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCreepySnail can use `getmac` and `Get-NetIPAddress` to enumerate network settings.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDUSTTRAP can enumerate files and directories.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCrimson contains a command to collect the victim MAC address and LAN IP.\n"}], "ground_truth": "T1016", "generated_content": "T1016"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nScattered Spider Spider enumerates a target organization for files and directories of interest, including source code.\n"}], "ground_truth": "T1083", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nOilRig has used macros to deliver malware such as QUADAGENT and OopsIE. OilRig has used batch scripts.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nCinnamon Tempest has executed ransomware using batch scripts deployed via GPO.\n"}], "ground_truth": "T1059.003", "generated_content": "T1059.003"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nConti can utilize command line options to allow an attacker control over how it scans and encrypts files.\n"}], "ground_truth": "T1059.003", "generated_content": "T1083"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nDuring Frankenstein, the threat actors used Empire to obtain a list of all running processes.\n"}], "ground_truth": "T1057", "generated_content": "T1057"} {"messages": [{"role": "user", "content": "What ATT&CK technique does the following CTI procedure sentence describe?\n\n\nBlackCat can enumerate files for encryption.\n"}], "ground_truth": "T1083", "generated_content": "T1083"}