vz-risk / veris

Vocabulary for Event Recording and Incident Sharing (VERIS)
http://verisframework.org
Other
565 stars 161 forks source link

Update "integrity.Software installation" to include both in memory and on disk #422

Open gdbassett opened 2 years ago

gdbassett commented 2 years ago

"Software installation" is currently defined "Software installation or code modification" however, it somewhat implies on-disk installation. Unfortunately that leaves no impact for in-memory malware. A short term fix is to clarify the definition of "Software installation" to include in-memory or on-disk malware. A mid-point would be to add an integrity variety specific to in-memory malware, (potentially as a child of software installation along with an on-disk child). Finally, there are more wide-impacting changes around defining a new attribute associated with volatile memory manipulation (or no impact at all).

gdbassett commented 1 year ago

Update definition to specify on disk and for folks to use 'in-memory' if a malware only exists in memory.