Skip to content

Commit

Permalink
Update Muddy Water flow to better match the examples in the best prac…
Browse files Browse the repository at this point in the history
…tices guide
  • Loading branch information
mehaase committed Jan 24, 2024
1 parent 8ff75c9 commit 40e57a0
Show file tree
Hide file tree
Showing 4 changed files with 5 additions and 2 deletions.
2 changes: 1 addition & 1 deletion corpus/Muddy Water.afb

Large diffs are not rendered by default.

Binary file modified docs/_static/IngressTool.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/_static/VBAMacros.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
5 changes: 4 additions & 1 deletion docs/best_practices.rst
Original file line number Diff line number Diff line change
Expand Up @@ -136,7 +136,10 @@ This section works through an example of mapping a report to illustrate the proc
report used is from Cisco Talos: `"Iranian APT MuddyWater targets Turkish users via
malicious PDFs, executables"
<https://blog.talosintelligence.com/2022/01/iranian-apt-muddywater-targets-turkey.html>`_.
The corresponding attack flow can be found in :doc:`example_flows`.
The corresponding "Muddy Water" Attack Flow can be found in :doc:`example_flows`. The
"Muddy Water" Attack Flow has some additional details and depicts two variants of the
Muddy Water beahvior. This section is based on the older variant of Muddy Water
campaigns.

**Initial Access**

Expand Down

0 comments on commit 40e57a0

Please sign in to comment.