[
  {
    "instruction": "List of mitigation IDs for the following technique SSH Authorized Keys (T1098.004)",
    "context": "",
    "output": "Mitigation ID: M1042 \nMitigation ID: M1022 \nMitigation ID: M1018 \n",
    "category": "MitreFlan",
    "instruction_type": "mitre_mitigation_technique_mitigations",
    "parsed_raw_data": {
      "question": "List of mitigation IDs for the following technique SSH Authorized Keys (T1098.004)",
      "answer": "Mitigation ID: M1042 \nMitigation ID: M1022 \nMitigation ID: M1018 \n",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mitigation_technique_mitigations"
    }
  },
  {
    "instruction": "Given the MITRE ATT&CK technique Additional Cloud Credentials (T1098.001), how should I defend?",
    "context": "",
    "output": "You can defend using the following mitigations:\nMitigation ID: M1032 \n Mitigation name: Additional Cloud Credentials\n Mitigation description: Use multi-factor authentication for user and privileged accounts. Consider enforcing multi-factor authentication for the <code>CreateKeyPair</code> and <code>ImportKeyPair</code> API calls through IAM policies.\n\nMitigation ID: M1030 \n Mitigation name: Additional Cloud Credentials\n Mitigation description: Configure access controls and firewalls to limit access to critical systems and domain controllers. Most cloud environments support separate virtual private cloud (VPC) instances that enable further segmentation of cloud systems.\n\nMitigation ID: M1026 \n Mitigation name: Additional Cloud Credentials\n Mitigation description: Do not allow domain administrator or root accounts to be used for day-to-day operations that may expose them to potential adversaries on unprivileged systems.\n\nMitigation ID: M1018 \n Mitigation name: Additional Cloud Credentials\n Mitigation description: Ensure that low-privileged user accounts do not have permission to add access keys to accounts. In AWS environments, prohibit users from calling the `sts:GetFederationToken` API unless explicitly required.\n\n",
    "category": "MitreFlan",
    "instruction_type": "mitre_mitigation_technique_mitigations",
    "parsed_raw_data": {
      "question": "Given the MITRE ATT&CK technique Additional Cloud Credentials (T1098.001), how should I defend",
      "answer": "You can defend using the following mitigations:\nMitigation ID: M1032 \n Mitigation name: Additional Cloud Credentials\n Mitigation description: Use multi-factor authentication for user and privileged accounts. Consider enforcing multi-factor authentication for the <code>CreateKeyPair</code> and <code>ImportKeyPair</code> API calls through IAM policies.\n\nMitigation ID: M1030 \n Mitigation name: Additional Cloud Credentials\n Mitigation description: Configure access controls and firewalls to limit access to critical systems and domain controllers. Most cloud environments support separate virtual private cloud (VPC) instances that enable further segmentation of cloud systems.\n\nMitigation ID: M1026 \n Mitigation name: Additional Cloud Credentials\n Mitigation description: Do not allow domain administrator or root accounts to be used for day-to-day operations that may expose them to potential adversaries on unprivileged systems.\n\nMitigation ID: M1018 \n Mitigation name: Additional Cloud Credentials\n Mitigation description: Ensure that low-privileged user accounts do not have permission to add access keys to accounts. In AWS environments, prohibit users from calling the `sts:GetFederationToken` API unless explicitly required.\n\n",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mitigation_technique_mitigations"
    }
  },
  {
    "instruction": "List of mitigation IDs for the following technique Server (T1584.004)",
    "context": "",
    "output": "Mitigation ID: M1056 \n",
    "category": "MitreFlan",
    "instruction_type": "mitre_mitigation_technique_mitigations",
    "parsed_raw_data": {
      "question": "List of mitigation IDs for the following technique Server (T1584.004)",
      "answer": "Mitigation ID: M1056 \n",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mitigation_technique_mitigations"
    }
  },
  {
    "instruction": "Retrieve a list of mitigation IDs for the following technique Data from Configuration Repository (T1602)?",
    "context": "",
    "output": "Mitigation ids for Data from Configuration Repository: Mitigation ID: M1041 \nMitigation ID: M1037 \nMitigation ID: M1031 \nMitigation ID: M1030 \nMitigation ID: M1054 \nMitigation ID: M1051 \n",
    "category": "MitreFlan",
    "instruction_type": "mitre_mitigation_technique_mitigations",
    "parsed_raw_data": {
      "question": "Retrieve a list of mitigation IDs for the following technique Data from Configuration Repository (T1602)",
      "answer": "Mitigation ids for Data from Configuration Repository: Mitigation ID: M1041 \nMitigation ID: M1037 \nMitigation ID: M1031 \nMitigation ID: M1030 \nMitigation ID: M1054 \nMitigation ID: M1051 \n",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mitigation_technique_mitigations"
    }
  },
  {
    "instruction": "List of mitigation IDs for the following technique Credential Stuffing (T1110.004)?",
    "context": "",
    "output": "Mitigation ID: M1036 \nMitigation ID: M1032 \nMitigation ID: M1027 \nMitigation ID: M1018 \n",
    "category": "MitreFlan",
    "instruction_type": "mitre_mitigation_technique_mitigations",
    "parsed_raw_data": {
      "question": "List of mitigation IDs for the following technique Credential Stuffing (T1110.004)",
      "answer": "Mitigation ID: M1036 \nMitigation ID: M1032 \nMitigation ID: M1027 \nMitigation ID: M1018 \n",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mitigation_technique_mitigations"
    }
  },
  {
    "instruction": "List mitigation names for the following technique Browser Extensions - T1176",
    "context": "",
    "output": "Mitigation name: Browser Extensions \nMitigation name: Browser Extensions \nMitigation name: Browser Extensions \nMitigation name: Browser Extensions \nMitigation name: Browser Extensions \n",
    "category": "MitreFlan",
    "instruction_type": "mitre_mitigation_technique_mitigations",
    "parsed_raw_data": {
      "question": "List mitigation names for the following technique Browser Extensions - T1176",
      "answer": "Mitigation name: Browser Extensions \nMitigation name: Browser Extensions \nMitigation name: Browser Extensions \nMitigation name: Browser Extensions \nMitigation name: Browser Extensions \n",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mitigation_technique_mitigations"
    }
  },
  {
    "instruction": "How to mitigate Mitre technique: Cloud Accounts (T1586.003)?",
    "context": "",
    "output": "Mitigation ID: M1056 \n Mitigation name: Cloud Accounts\n Mitigation description: This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.\n\n",
    "category": "MitreFlan",
    "instruction_type": "mitre_mitigation_technique_mitigations",
    "parsed_raw_data": {
      "question": "How to mitigate Mitre technique: Cloud Accounts (T1586.003)",
      "answer": "Mitigation ID: M1056 \n Mitigation name: Cloud Accounts\n Mitigation description: This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.\n\n",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mitigation_technique_mitigations"
    }
  },
  {
    "instruction": "Retrieve a list of mitigation IDs for the following technique Clear Windows Event Logs (T1070.001)?",
    "context": "",
    "output": "Mitigation ids for Clear Windows Event Logs: Mitigation ID: M1041 \nMitigation ID: M1029 \nMitigation ID: M1022 \n",
    "category": "MitreFlan",
    "instruction_type": "mitre_mitigation_technique_mitigations",
    "parsed_raw_data": {
      "question": "Retrieve a list of mitigation IDs for the following technique Clear Windows Event Logs (T1070.001)",
      "answer": "Mitigation ids for Clear Windows Event Logs: Mitigation ID: M1041 \nMitigation ID: M1029 \nMitigation ID: M1022 \n",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mitigation_technique_mitigations"
    }
  },
  {
    "instruction": "How to mitigate Mitre technique: Defacement (T1491)?",
    "context": "",
    "output": "Mitigation ID: M1053 \n Mitigation name: Defacement\n Mitigation description: Consider implementing IT disaster recovery plans that contain procedures for taking regular data backups that can be used to restore organizational data. Ensure backups are stored off system and is protected from common methods adversaries may use to gain access and destroy the backups to prevent recovery.\n\n",
    "category": "MitreFlan",
    "instruction_type": "mitre_mitigation_technique_mitigations",
    "parsed_raw_data": {
      "question": "How to mitigate Mitre technique: Defacement (T1491)",
      "answer": "Mitigation ID: M1053 \n Mitigation name: Defacement\n Mitigation description: Consider implementing IT disaster recovery plans that contain procedures for taking regular data backups that can be used to restore organizational data. Ensure backups are stored off system and is protected from common methods adversaries may use to gain access and destroy the backups to prevent recovery.\n\n",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mitigation_technique_mitigations"
    }
  },
  {
    "instruction": "Retrieve a list of mitigation IDs for the following technique Clear Mailbox Data (T1070.008)?",
    "context": "",
    "output": "Mitigation ids for Clear Mailbox Data: Mitigation ID: M1047 \nMitigation ID: M1029 \nMitigation ID: M1022 \n",
    "category": "MitreFlan",
    "instruction_type": "mitre_mitigation_technique_mitigations",
    "parsed_raw_data": {
      "question": "Retrieve a list of mitigation IDs for the following technique Clear Mailbox Data (T1070.008)",
      "answer": "Mitigation ids for Clear Mailbox Data: Mitigation ID: M1047 \nMitigation ID: M1029 \nMitigation ID: M1022 \n",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mitigation_technique_mitigations"
    }
  }
]