CybercentreCanada / CCCS-Yara

YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA
MIT License
93 stars 19 forks source link

Add Malware Behavior Catalog Codes #54

Closed utkonos closed 1 year ago

utkonos commented 1 year ago

In addition to the mitre_att metadata field already in this spec, there should also be mitre_mbc. This is a newer and more appropriare classification system for malware samples than ATT&CK framework. The capa project has aligned with MBC over the past year as well.

https://github.com/MBCProject/mbc-markdown/blob/master/yfaq/README.md