[
  {
    "instruction": "Which technique is related to the following procedure description:\n\nStuxnet transforms encrypted binary data into an ASCII string in order to use it as a URL parameter value.",
    "context": "",
    "output": "The provided description pertains to the Mitre procedure involving the application of sub-technique Standard Encoding (T1132.001) by software Stuxnet;\nSub technique Standard Encoding (T1132.001) is a type of technique Data Encoding (T1132);\nTherefore, the given description is related to technique Data Encoding (T1132).",
    "category": "MitreFlan",
    "instruction_type": "cot_procedure_technique_mapping_CoT",
    "parsed_raw_data": {
      "question": "Which technique is related to the following procedure description:\n\nStuxnet transforms encrypted binary data into an ASCII string in order to use it as a URL parameter value.",
      "answer": "The provided description pertains to the Mitre procedure involving the application of sub-technique Standard Encoding (T1132.001) by software Stuxnet;\nSub technique Standard Encoding (T1132.001) is a type of technique Data Encoding (T1132);\nTherefore, the given description is related to technique Data Encoding (T1132).",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "cot_procedure_technique_mapping_CoT"
    }
  },
  {
    "instruction": "Which technique is related to the following procedure description:\n\nCardinal RAT and its watchdog component are compiled and executed after being delivered to victims as embedded, uncompiled source code.",
    "context": "",
    "output": "The provided description pertains to the Mitre procedure involving the application of sub-technique Compile After Delivery (T1027.004) by software Cardinal RAT;\nSub technique Compile After Delivery (T1027.004) is a type of technique Obfuscated Files or Information (T1027);\nTherefore, the given description is related to technique Obfuscated Files or Information (T1027).",
    "category": "MitreFlan",
    "instruction_type": "cot_procedure_technique_mapping_CoT",
    "parsed_raw_data": {
      "question": "Which technique is related to the following procedure description:\n\nCardinal RAT and its watchdog component are compiled and executed after being delivered to victims as embedded, uncompiled source code.",
      "answer": "The provided description pertains to the Mitre procedure involving the application of sub-technique Compile After Delivery (T1027.004) by software Cardinal RAT;\nSub technique Compile After Delivery (T1027.004) is a type of technique Obfuscated Files or Information (T1027);\nTherefore, the given description is related to technique Obfuscated Files or Information (T1027).",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "cot_procedure_technique_mapping_CoT"
    }
  },
  {
    "instruction": "Which technique is related to the following procedure description - APT33 has used a variety of publicly available tools like Gpppassword to gather credentials.?",
    "context": "",
    "output": "The provided description pertains to the Mitre procedure concerning how group APT33 employs the sub-technique Group Policy Preferences (T1552.006);\nSub technique Group Policy Preferences (T1552.006) is a type of technique Unsecured Credentials (T1552);\nTherefore, the given description is related to technique Unsecured Credentials (T1552).",
    "category": "MitreFlan",
    "instruction_type": "cot_procedure_technique_mapping_CoT",
    "parsed_raw_data": {
      "question": "Which technique is related to the following procedure description - APT33 has used a variety of publicly available tools like Gpppassword to gather credentials.",
      "answer": "The provided description pertains to the Mitre procedure concerning how group APT33 employs the sub-technique Group Policy Preferences (T1552.006);\nSub technique Group Policy Preferences (T1552.006) is a type of technique Unsecured Credentials (T1552);\nTherefore, the given description is related to technique Unsecured Credentials (T1552).",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "cot_procedure_technique_mapping_CoT"
    }
  },
  {
    "instruction": "Which technique is related to the following procedure description - TeamTNT has used shell scripts for execution.?",
    "context": "",
    "output": "The provided description pertains to the Mitre procedure concerning how group TeamTNT employs the sub-technique Unix Shell (T1059.004);\nSub technique Unix Shell (T1059.004) is a type of technique Command and Scripting Interpreter (T1059);\nTherefore, the given description is related to technique Command and Scripting Interpreter (T1059).",
    "category": "MitreFlan",
    "instruction_type": "cot_procedure_technique_mapping_CoT",
    "parsed_raw_data": {
      "question": "Which technique is related to the following procedure description - TeamTNT has used shell scripts for execution.",
      "answer": "The provided description pertains to the Mitre procedure concerning how group TeamTNT employs the sub-technique Unix Shell (T1059.004);\nSub technique Unix Shell (T1059.004) is a type of technique Command and Scripting Interpreter (T1059);\nTherefore, the given description is related to technique Command and Scripting Interpreter (T1059).",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "cot_procedure_technique_mapping_CoT"
    }
  },
  {
    "instruction": "Which technique is related to the following procedure description:\n\nAnchor has obfuscated code with stack strings and string encryption.",
    "context": "",
    "output": "The provided description pertains to the Mitre procedure involving the application of technique Obfuscated Files or Information (T1027) by software Anchor.",
    "category": "MitreFlan",
    "instruction_type": "cot_procedure_technique_mapping_CoT",
    "parsed_raw_data": {
      "question": "Which technique is related to the following procedure description:\n\nAnchor has obfuscated code with stack strings and string encryption.",
      "answer": "The provided description pertains to the Mitre procedure involving the application of technique Obfuscated Files or Information (T1027) by software Anchor.",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "cot_procedure_technique_mapping_CoT"
    }
  },
  {
    "instruction": "Which technique is related to the following procedure description - During the 2015 Ukraine Electric Power Attack, Sandworm Team loaded BlackEnergy into svchost.exe, which then launched iexplore.exe for their C2.",
    "context": "",
    "output": "The provided description pertains to the Mitre procedure concerning how campaign 2015 Ukraine Electric Power Attack employs the technique Process Injection (T1055);\nTherefore, the given description is related to technique Process Injection (T1055).",
    "category": "MitreFlan",
    "instruction_type": "cot_procedure_technique_mapping_CoT",
    "parsed_raw_data": {
      "question": "Which technique is related to the following procedure description - During the 2015 Ukraine Electric Power Attack, Sandworm Team loaded BlackEnergy into svchost.exe, which then launched iexplore.exe for their C2.",
      "answer": "The provided description pertains to the Mitre procedure concerning how campaign 2015 Ukraine Electric Power Attack employs the technique Process Injection (T1055);\nTherefore, the given description is related to technique Process Injection (T1055).",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "cot_procedure_technique_mapping_CoT"
    }
  },
  {
    "instruction": "Which technique is related to the following procedure description - PlugX can use API hashing and modify the names of strings to evade detection.?",
    "context": "",
    "output": "The provided description pertains to the Mitre procedure concerning how software PlugX employs the technique Obfuscated Files or Information (T1027);\nTherefore, the given description is related to technique Obfuscated Files or Information (T1027).",
    "category": "MitreFlan",
    "instruction_type": "cot_procedure_technique_mapping_CoT",
    "parsed_raw_data": {
      "question": "Which technique is related to the following procedure description - PlugX can use API hashing and modify the names of strings to evade detection.",
      "answer": "The provided description pertains to the Mitre procedure concerning how software PlugX employs the technique Obfuscated Files or Information (T1027);\nTherefore, the given description is related to technique Obfuscated Files or Information (T1027).",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "cot_procedure_technique_mapping_CoT"
    }
  },
  {
    "instruction": "Which technique is related to the following procedure description - Emotet has been delivered by phishing emails containing attachments.?",
    "context": "",
    "output": "The provided description pertains to the Mitre procedure concerning how software Emotet employs the sub-technique Spearphishing Attachment (T1566.001);\nSub technique Spearphishing Attachment (T1566.001) is a type of technique Phishing (T1566);\nTherefore, the given description is related to technique Phishing (T1566).",
    "category": "MitreFlan",
    "instruction_type": "cot_procedure_technique_mapping_CoT",
    "parsed_raw_data": {
      "question": "Which technique is related to the following procedure description - Emotet has been delivered by phishing emails containing attachments.",
      "answer": "The provided description pertains to the Mitre procedure concerning how software Emotet employs the sub-technique Spearphishing Attachment (T1566.001);\nSub technique Spearphishing Attachment (T1566.001) is a type of technique Phishing (T1566);\nTherefore, the given description is related to technique Phishing (T1566).",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "cot_procedure_technique_mapping_CoT"
    }
  },
  {
    "instruction": "Which technique is related to the following procedure description:\n\nMatryoshka obfuscates API function names using a substitute cipher combined with Base64 encoding.?",
    "context": "",
    "output": "The provided description pertains to the Mitre procedure involving the application of technique Obfuscated Files or Information (T1027) by software Matryoshka.",
    "category": "MitreFlan",
    "instruction_type": "cot_procedure_technique_mapping_CoT",
    "parsed_raw_data": {
      "question": "Which technique is related to the following procedure description:\n\nMatryoshka obfuscates API function names using a substitute cipher combined with Base64 encoding.",
      "answer": "The provided description pertains to the Mitre procedure involving the application of technique Obfuscated Files or Information (T1027) by software Matryoshka.",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "cot_procedure_technique_mapping_CoT"
    }
  },
  {
    "instruction": "Which technique is related to the following procedure description:\n\nKasidet can execute commands using cmd.exe.",
    "context": "",
    "output": "The provided description pertains to the Mitre procedure involving the application of sub-technique Windows Command Shell (T1059.003) by software Kasidet;\nSub technique Windows Command Shell (T1059.003) is a type of technique Command and Scripting Interpreter (T1059);\nTherefore, the given description is related to technique Command and Scripting Interpreter (T1059).",
    "category": "MitreFlan",
    "instruction_type": "cot_procedure_technique_mapping_CoT",
    "parsed_raw_data": {
      "question": "Which technique is related to the following procedure description:\n\nKasidet can execute commands using cmd.exe.",
      "answer": "The provided description pertains to the Mitre procedure involving the application of sub-technique Windows Command Shell (T1059.003) by software Kasidet;\nSub technique Windows Command Shell (T1059.003) is a type of technique Command and Scripting Interpreter (T1059);\nTherefore, the given description is related to technique Command and Scripting Interpreter (T1059).",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "cot_procedure_technique_mapping_CoT"
    }
  }
]