[
  {
    "instruction": "Which technique is mapped to the following procedure: MacSpy stores itself in <code>~/Library/.DS_Stores/</code>\n\nPossible answers:\nA. Virtualization/Sandbox Evasion, B. Use Alternate Authentication Material, C. Modify Authentication Process: Multi-Factor Authentication, D. Hide Artifacts: Hidden Files and Directories",
    "context": "",
    "output": "D. Hide Artifacts: Hidden Files and Directories",
    "category": "MitreFlan",
    "instruction_type": "mitre_procedure_options_mitre_procedure_options",
    "parsed_raw_data": {
      "question": "Which technique is mapped to the following procedure: MacSpy stores itself in <code>~/Library/.DS_Stores/</code>",
      "options": "A. Virtualization/Sandbox Evasion, B. Use Alternate Authentication Material, C. Modify Authentication Process: Multi-Factor Authentication, D. Hide Artifacts: Hidden Files and Directories",
      "choice": "D. Hide Artifacts: Hidden Files and Directories",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_procedure_options_mitre_procedure_options"
    }
  },
  {
    "instruction": "What technique was utilized in the procedure: Dragonfly has commonly created Web shells on victims' publicly accessible email and web servers, which they used to maintain access to a victim network and download additional malicious files.\n\nA. Boot or Logon Initialization Scripts, B. Phishing, C. Server Software Component: Web Shell, D. Stage Capabilities\nAnswer:",
    "context": "",
    "output": "C. Server Software Component: Web Shell",
    "category": "MitreFlan",
    "instruction_type": "mitre_procedure_options_mitre_procedure_options",
    "parsed_raw_data": {
      "question": "What technique was utilized in the procedure: Dragonfly has commonly created Web shells on victims' publicly accessible email and web servers, which they used to maintain access to a victim network and download additional malicious files.",
      "options": "A. Boot or Logon Initialization Scripts, B. Phishing, C. Server Software Component: Web Shell, D. Stage Capabilities",
      "choice": "C. Server Software Component: Web Shell",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_procedure_options_mitre_procedure_options"
    }
  },
  {
    "instruction": "Which technique is mapped to the following procedure: Woody RAT has used Base64 encoded strings and scripts.\n\nA. Obfuscated Files or Information: Encrypted/Encoded File, B. Data Manipulation: Transmitted Data Manipulation, C. Group Policy Discovery, D. Process Injection\nAnswer:",
    "context": "",
    "output": "A. Obfuscated Files or Information: Encrypted/Encoded File",
    "category": "MitreFlan",
    "instruction_type": "mitre_procedure_options_mitre_procedure_options",
    "parsed_raw_data": {
      "question": "Which technique is mapped to the following procedure: Woody RAT has used Base64 encoded strings and scripts.",
      "options": "A. Obfuscated Files or Information: Encrypted/Encoded File, B. Data Manipulation: Transmitted Data Manipulation, C. Group Policy Discovery, D. Process Injection",
      "choice": "A. Obfuscated Files or Information: Encrypted/Encoded File",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_procedure_options_mitre_procedure_options"
    }
  },
  {
    "instruction": "Question: Which technique is mapped to the following procedure: Gelsemium can modify the Registry to store its components.\nA. Obtain Capabilities: Tool, B. Modify Registry, C. Container and Resource Discovery, D. OS Credential Dumping: LSASS Memory\nAnswer:",
    "context": "",
    "output": "B. Modify Registry",
    "category": "MitreFlan",
    "instruction_type": "mitre_procedure_options_mitre_procedure_options",
    "parsed_raw_data": {
      "question": "Which technique is mapped to the following procedure: Gelsemium can modify the Registry to store its components.",
      "options": "A. Obtain Capabilities: Tool, B. Modify Registry, C. Container and Resource Discovery, D. OS Credential Dumping: LSASS Memory",
      "choice": "B. Modify Registry",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_procedure_options_mitre_procedure_options"
    }
  },
  {
    "instruction": "Q: Which technique is mapped to the following procedure: Bisonal has supported use of a proxy server.\n\nOptions:\nA. Remote Services: Distributed Component Object Model, B. Proxy, C. Data Staged, D. Subvert Trust Controls: Mark-of-the-Web Bypass",
    "context": "",
    "output": "B. Proxy",
    "category": "MitreFlan",
    "instruction_type": "mitre_procedure_options_mitre_procedure_options",
    "parsed_raw_data": {
      "question": "Which technique is mapped to the following procedure: Bisonal has supported use of a proxy server.",
      "options": "A. Remote Services: Distributed Component Object Model, B. Proxy, C. Data Staged, D. Subvert Trust Controls: Mark-of-the-Web Bypass",
      "choice": "B. Proxy",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_procedure_options_mitre_procedure_options"
    }
  },
  {
    "instruction": "Q: Which technique is mapped to the following procedure: Janicab used a valid AppleDeveloperID to sign the code to get past security restrictions.\n\nA. Forge Web Credentials: SAML Tokens, B. Subvert Trust Controls: Code Signing, C. Masquerading, D. Phishing: Spearphishing Attachment\nA:",
    "context": "",
    "output": "B. Subvert Trust Controls: Code Signing",
    "category": "MitreFlan",
    "instruction_type": "mitre_procedure_options_mitre_procedure_options",
    "parsed_raw_data": {
      "question": "Which technique is mapped to the following procedure: Janicab used a valid AppleDeveloperID to sign the code to get past security restrictions.",
      "options": "A. Forge Web Credentials: SAML Tokens, B. Subvert Trust Controls: Code Signing, C. Masquerading, D. Phishing: Spearphishing Attachment",
      "choice": "B. Subvert Trust Controls: Code Signing",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_procedure_options_mitre_procedure_options"
    }
  },
  {
    "instruction": "Which technique is mapped to the following procedure: KOCTOPUS has added and deleted keys from the Registry.\n\nPossible answers:\nA. Credentials from Password Stores: Keychain, B. Modify Registry, C. Acquire Infrastructure: Domains, D. Inter-Process Communication: Dynamic Data Exchange",
    "context": "",
    "output": "B. Modify Registry",
    "category": "MitreFlan",
    "instruction_type": "mitre_procedure_options_mitre_procedure_options",
    "parsed_raw_data": {
      "question": "Which technique is mapped to the following procedure: KOCTOPUS has added and deleted keys from the Registry.",
      "options": "A. Credentials from Password Stores: Keychain, B. Modify Registry, C. Acquire Infrastructure: Domains, D. Inter-Process Communication: Dynamic Data Exchange",
      "choice": "B. Modify Registry",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_procedure_options_mitre_procedure_options"
    }
  },
  {
    "instruction": "Q: What technique was utilized in the procedure: SPACESHIP identifies files with certain extensions and copies them to a directory in the user's profile.\n\nOptions:\nA. Stage Capabilities, B. Reflective Code Loading, C. Data Staged: Local Data Staging, D. Credentials from Password Stores: Password Managers",
    "context": "",
    "output": "C. Data Staged: Local Data Staging",
    "category": "MitreFlan",
    "instruction_type": "mitre_procedure_options_mitre_procedure_options",
    "parsed_raw_data": {
      "question": "What technique was utilized in the procedure: SPACESHIP identifies files with certain extensions and copies them to a directory in the user's profile.",
      "options": "A. Stage Capabilities, B. Reflective Code Loading, C. Data Staged: Local Data Staging, D. Credentials from Password Stores: Password Managers",
      "choice": "C. Data Staged: Local Data Staging",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_procedure_options_mitre_procedure_options"
    }
  },
  {
    "instruction": "What technique was utilized in the procedure: jRAT has the capability to capture video from a webcam.\nA. Video Capture, B. Process Injection: Process Doppelg\u00e4nging, C. Acquire Infrastructure: Domains, D. System Owner/User Discovery",
    "context": "",
    "output": "A. Video Capture",
    "category": "MitreFlan",
    "instruction_type": "mitre_procedure_options_mitre_procedure_options",
    "parsed_raw_data": {
      "question": "What technique was utilized in the procedure: jRAT has the capability to capture video from a webcam.",
      "options": "A. Video Capture, B. Process Injection: Process Doppelg\u00e4nging, C. Acquire Infrastructure: Domains, D. System Owner/User Discovery",
      "choice": "A. Video Capture",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_procedure_options_mitre_procedure_options"
    }
  },
  {
    "instruction": "Q: What technique was utilized in the procedure: APT29 has stolen data from compromised hosts.\n\nA. Data from Local System, B. Remote Services: SMB/Windows Admin Shares, C. Stage Capabilities, D. Template Injection\nA:",
    "context": "",
    "output": "A. Data from Local System",
    "category": "MitreFlan",
    "instruction_type": "mitre_procedure_options_mitre_procedure_options",
    "parsed_raw_data": {
      "question": "What technique was utilized in the procedure: APT29 has stolen data from compromised hosts.",
      "options": "A. Data from Local System, B. Remote Services: SMB/Windows Admin Shares, C. Stage Capabilities, D. Template Injection",
      "choice": "A. Data from Local System",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_procedure_options_mitre_procedure_options"
    }
  }
]