[
  {
    "instruction": "What is tactic: 'Impact - TA0040'",
    "context": "",
    "output": "Mitre tactic 'Impact - TA0040':\n\nThe adversary is trying to manipulate, interrupt, or destroy your systems and data.\n \nImpact consists of techniques that adversaries use to disrupt availability or compromise integrity by manipulating business and operational processes. Techniques used for impact can include destroying or tampering with data. In some cases, business processes can look fine, but may have been altered to benefit the adversaries\u2019 goals. These techniques might be used by adversaries to follow through on their end goal or to provide cover for a confidentiality breach.",
    "category": "MitreFlan",
    "instruction_type": "mitre_description_tactic",
    "parsed_raw_data": {
      "question": "What is tactic: 'Impact - TA0040'",
      "answer": "Mitre tactic 'Impact - TA0040':\n\nThe adversary is trying to manipulate, interrupt, or destroy your systems and data.\n \nImpact consists of techniques that adversaries use to disrupt availability or compromise integrity by manipulating business and operational processes. Techniques used for impact can include destroying or tampering with data. In some cases, business processes can look fine, but may have been altered to benefit the adversaries\u2019 goals. These techniques might be used by adversaries to follow through on their end goal or to provide cover for a confidentiality breach.",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_description_tactic"
    }
  },
  {
    "instruction": "Describe MITRE tactic: 'Collection (TA0009)'?",
    "context": "",
    "output": "Certainly! Description for tactic 'Collection (TA0009)':\nThe adversary is trying to gather data of interest to their goal.\n\nCollection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary's objectives. Frequently, the next goal after collecting data is to steal (exfiltrate) the data. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.",
    "category": "MitreFlan",
    "instruction_type": "mitre_description_tactic",
    "parsed_raw_data": {
      "question": "Describe MITRE tactic: 'Collection (TA0009)'",
      "answer": "Certainly! Description for tactic 'Collection (TA0009)':\nThe adversary is trying to gather data of interest to their goal.\n\nCollection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary's objectives. Frequently, the next goal after collecting data is to steal (exfiltrate) the data. Common target sources include various drive types, browsers, audio, video, and email. Common collection methods include capturing screenshots and keyboard input.",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_description_tactic"
    }
  },
  {
    "instruction": "Describe MITRE tactic 'Lateral Movement (TA0008)'",
    "context": "",
    "output": "Here is the description for tactic 'Lateral Movement (TA0008)':\nThe adversary is trying to move through your environment.\n\nLateral Movement consists of techniques that adversaries use to enter and control remote systems on a network. Following through on their primary objective often requires exploring the network to find their target and subsequently gaining access to it. Reaching their objective often involves pivoting through multiple systems and accounts to gain. Adversaries might install their own remote access tools to accomplish Lateral Movement or use legitimate credentials with native network and operating system tools, which may be stealthier.",
    "category": "MitreFlan",
    "instruction_type": "mitre_description_tactic",
    "parsed_raw_data": {
      "question": "Describe MITRE tactic 'Lateral Movement (TA0008)'",
      "answer": "Here is the description for tactic 'Lateral Movement (TA0008)':\nThe adversary is trying to move through your environment.\n\nLateral Movement consists of techniques that adversaries use to enter and control remote systems on a network. Following through on their primary objective often requires exploring the network to find their target and subsequently gaining access to it. Reaching their objective often involves pivoting through multiple systems and accounts to gain. Adversaries might install their own remote access tools to accomplish Lateral Movement or use legitimate credentials with native network and operating system tools, which may be stealthier.",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_description_tactic"
    }
  },
  {
    "instruction": "Describe tactic named Exfiltration - TA0010",
    "context": "",
    "output": "Sure. The description for the MITRE tactic named Exfiltration (TA0010) is:\nThe adversary is trying to steal data.\n\nExfiltration consists of techniques that adversaries may use to steal data from your network. Once they\u2019ve collected data, adversaries often package it to avoid detection while removing it. This can include compression and encryption. Techniques for getting data out of a target network typically include transferring it over their command and control channel or an alternate channel and may also include putting size limits on the transmission.",
    "category": "MitreFlan",
    "instruction_type": "mitre_description_tactic",
    "parsed_raw_data": {
      "question": "Describe tactic named Exfiltration - TA0010",
      "answer": "Sure. The description for the MITRE tactic named Exfiltration (TA0010) is:\nThe adversary is trying to steal data.\n\nExfiltration consists of techniques that adversaries may use to steal data from your network. Once they\u2019ve collected data, adversaries often package it to avoid detection while removing it. This can include compression and encryption. Techniques for getting data out of a target network typically include transferring it over their command and control channel or an alternate channel and may also include putting size limits on the transmission.",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_description_tactic"
    }
  },
  {
    "instruction": "Describe the following MITRE tactic: Credential Access - TA0006",
    "context": "",
    "output": "Description for the MITRE tactic Credential Access (TA0006):\nThe adversary is trying to steal account names and passwords.\n\nCredential Access consists of techniques for stealing credentials like account names and passwords. Techniques used to get credentials include keylogging or credential dumping. Using legitimate credentials can give adversaries access to systems, make them harder to detect, and provide the opportunity to create more accounts to help achieve their goals.",
    "category": "MitreFlan",
    "instruction_type": "mitre_description_tactic",
    "parsed_raw_data": {
      "question": "Describe the following MITRE tactic: Credential Access - TA0006",
      "answer": "Description for the MITRE tactic Credential Access (TA0006):\nThe adversary is trying to steal account names and passwords.\n\nCredential Access consists of techniques for stealing credentials like account names and passwords. Techniques used to get credentials include keylogging or credential dumping. Using legitimate credentials can give adversaries access to systems, make them harder to detect, and provide the opportunity to create more accounts to help achieve their goals.",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_description_tactic"
    }
  },
  {
    "instruction": "Describe the following MITRE ATT&CK tactic - Command and Control (TA0011)",
    "context": "",
    "output": "Description of MITRE ATT&CK 'Command and Control (TA0011)' - The adversary is trying to communicate with compromised systems to control them.\n\nCommand and Control consists of techniques that adversaries may use to communicate with systems under their control within a victim network. Adversaries commonly attempt to mimic normal, expected traffic to avoid detection. There are many ways an adversary can establish command and control with various levels of stealth depending on the victim\u2019s network structure and defenses.",
    "category": "MitreFlan",
    "instruction_type": "mitre_description_tactic",
    "parsed_raw_data": {
      "question": "Describe the following MITRE ATT&CK tactic - Command and Control (TA0011)",
      "answer": "Description of MITRE ATT&CK 'Command and Control (TA0011)' - The adversary is trying to communicate with compromised systems to control them.\n\nCommand and Control consists of techniques that adversaries may use to communicate with systems under their control within a victim network. Adversaries commonly attempt to mimic normal, expected traffic to avoid detection. There are many ways an adversary can establish command and control with various levels of stealth depending on the victim\u2019s network structure and defenses.",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_description_tactic"
    }
  },
  {
    "instruction": "Can you please describe the MITRE ATT&CK tactic: 'Resource Development (TA0042)'?",
    "context": "",
    "output": "Indeed. Description for MITRE ATT&CK tactic 'Resource Development (TA0042)':\n\nThe adversary is trying to establish resources they can use to support operations.\n\nResource Development consists of techniques that involve adversaries creating, purchasing, or compromising/stealing resources that can be used to support targeting. Such resources include infrastructure, accounts, or capabilities. These resources can be leveraged by the adversary to aid in other phases of the adversary lifecycle, such as using purchased domains to support Command and Control, email accounts for phishing as a part of Initial Access, or stealing code signing certificates to help with Defense Evasion.",
    "category": "MitreFlan",
    "instruction_type": "mitre_description_tactic",
    "parsed_raw_data": {
      "question": "Can you please describe the MITRE ATT&CK tactic: 'Resource Development (TA0042)'",
      "answer": "Indeed. Description for MITRE ATT&CK tactic 'Resource Development (TA0042)':\n\nThe adversary is trying to establish resources they can use to support operations.\n\nResource Development consists of techniques that involve adversaries creating, purchasing, or compromising/stealing resources that can be used to support targeting. Such resources include infrastructure, accounts, or capabilities. These resources can be leveraged by the adversary to aid in other phases of the adversary lifecycle, such as using purchased domains to support Command and Control, email accounts for phishing as a part of Initial Access, or stealing code signing certificates to help with Defense Evasion.",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_description_tactic"
    }
  },
  {
    "instruction": "Describe the following MITRE tactic: Persistence - TA0003",
    "context": "",
    "output": "Description for the MITRE tactic Persistence (TA0003):\nThe adversary is trying to maintain their foothold.\n\nPersistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access. Techniques used for persistence include any access, action, or configuration changes that let them maintain their foothold on systems, such as replacing or hijacking legitimate code or adding startup code.",
    "category": "MitreFlan",
    "instruction_type": "mitre_description_tactic",
    "parsed_raw_data": {
      "question": "Describe the following MITRE tactic: Persistence - TA0003",
      "answer": "Description for the MITRE tactic Persistence (TA0003):\nThe adversary is trying to maintain their foothold.\n\nPersistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access. Techniques used for persistence include any access, action, or configuration changes that let them maintain their foothold on systems, such as replacing or hijacking legitimate code or adding startup code.",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_description_tactic"
    }
  },
  {
    "instruction": "Describe the following tactic - Execution (TA0002)",
    "context": "",
    "output": "Description: The adversary is trying to run malicious code.\n\nExecution consists of techniques that result in adversary-controlled code running on a local or remote system. Techniques that run malicious code are often paired with techniques from all other tactics to achieve broader goals, like exploring a network or stealing data. For example, an adversary might use a remote access tool to run a PowerShell script that does Remote System Discovery.",
    "category": "MitreFlan",
    "instruction_type": "mitre_description_tactic",
    "parsed_raw_data": {
      "question": "Describe the following tactic - Execution (TA0002)",
      "answer": "Description: The adversary is trying to run malicious code.\n\nExecution consists of techniques that result in adversary-controlled code running on a local or remote system. Techniques that run malicious code are often paired with techniques from all other tactics to achieve broader goals, like exploring a network or stealing data. For example, an adversary might use a remote access tool to run a PowerShell script that does Remote System Discovery.",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_description_tactic"
    }
  },
  {
    "instruction": "Describe the MITRE ATT&CK tactic: Initial Access (TA0001)?",
    "context": "",
    "output": "Below is the description for the MITRE ATT&CK tactic named 'Initial Access (TA0001)':\nThe adversary is trying to get into your network.\n\nInitial Access consists of techniques that use various entry vectors to gain their initial foothold within a network. Techniques used to gain a foothold include targeted spearphishing and exploiting weaknesses on public-facing web servers. Footholds gained through initial access may allow for continued access, like valid accounts and use of external remote services, or may be limited-use due to changing passwords.",
    "category": "MitreFlan",
    "instruction_type": "mitre_description_tactic",
    "parsed_raw_data": {
      "question": "Describe the MITRE ATT&CK tactic: Initial Access (TA0001)",
      "answer": "Below is the description for the MITRE ATT&CK tactic named 'Initial Access (TA0001)':\nThe adversary is trying to get into your network.\n\nInitial Access consists of techniques that use various entry vectors to gain their initial foothold within a network. Techniques used to gain a foothold include targeted spearphishing and exploiting weaknesses on public-facing web servers. Footholds gained through initial access may allow for continued access, like valid accounts and use of external remote services, or may be limited-use due to changing passwords.",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_description_tactic"
    }
  }
]