[
  {
    "instruction": "To which Mitre software does the following description refers: The software is malware that was used by APT29 from 2013 to 2015.",
    "context": "",
    "output": "The software that refer to the above description is OnionDuke (S0052)",
    "category": "MitreFlan",
    "instruction_type": "mitre_mapping_software",
    "parsed_raw_data": {
      "question": "To which Mitre software does the following description refers: The software is malware that was used by APT29 from 2013 to 2015.",
      "answer": "The software that refer to the above description is OnionDuke (S0052)",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mapping_software"
    }
  },
  {
    "instruction": "Which Mitre software meets the following description: The software is an open source remote administration and post-exploitation framework that is publicly available on GitHub. The server-side components of the tool are primarily written in Python, while the implants are written in PowerShell. Although The software is primarily focused on Windows implantation, it does contain a basic Python dropper for Linux/macOS.",
    "context": "",
    "output": "The software that meets the above description is PoshC2 (S0378)",
    "category": "MitreFlan",
    "instruction_type": "mitre_mapping_software",
    "parsed_raw_data": {
      "question": "Which Mitre software meets the following description: The software is an open source remote administration and post-exploitation framework that is publicly available on GitHub. The server-side components of the tool are primarily written in Python, while the implants are written in PowerShell. Although The software is primarily focused on Windows implantation, it does contain a basic Python dropper for Linux/macOS.",
      "answer": "The software that meets the above description is PoshC2 (S0378)",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mapping_software"
    }
  },
  {
    "instruction": "Consider the following description: The software is a malware family that is notable due to its use of DNS as a C2 protocol as well as its use of anti-analysis tactics. It has been used by APT18 and is similar to another malware family, HTTPBrowser, that has been used by the group.\n\nTo which MITRE software the given description refers",
    "context": "",
    "output": "The MITRE ATT&CK software that is related to the given description is: 'Pisloader (S0124)'",
    "category": "MitreFlan",
    "instruction_type": "mitre_mapping_software",
    "parsed_raw_data": {
      "question": "Consider the following description: The software is a malware family that is notable due to its use of DNS as a C2 protocol as well as its use of anti-analysis tactics. It has been used by APT18 and is similar to another malware family, HTTPBrowser, that has been used by the group.\n\nTo which MITRE software the given description refers",
      "answer": "The MITRE ATT&CK software that is related to the given description is: 'Pisloader (S0124)'",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mapping_software"
    }
  },
  {
    "instruction": "Consider the following description: The software is Linux malware that compromises systems by brute force attacks against SSH services. Once installed, it provides a reverse shell to its controllers, triggered by unsolicited packets.\n\nTo which MITRE software the given description refers?",
    "context": "",
    "output": "The MITRE ATT&CK software that is related to the given description is: 'Chaos (S0220)'",
    "category": "MitreFlan",
    "instruction_type": "mitre_mapping_software",
    "parsed_raw_data": {
      "question": "Consider the following description: The software is Linux malware that compromises systems by brute force attacks against SSH services. Once installed, it provides a reverse shell to its controllers, triggered by unsolicited packets.\n\nTo which MITRE software the given description refers",
      "answer": "The MITRE ATT&CK software that is related to the given description is: 'Chaos (S0220)'",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mapping_software"
    }
  },
  {
    "instruction": "Which Mitre software meets the following description: The software is a backdoor that appears to be a version of commercial software FinFisher. It is reportedly used to attack individual computers instead of networks. It was used by NEODYMIUM in a May 2016 campaign.?",
    "context": "",
    "output": "The software that meets the above description is Wingbird (S0176)",
    "category": "MitreFlan",
    "instruction_type": "mitre_mapping_software",
    "parsed_raw_data": {
      "question": "Which Mitre software meets the following description: The software is a backdoor that appears to be a version of commercial software FinFisher. It is reportedly used to attack individual computers instead of networks. It was used by NEODYMIUM in a May 2016 campaign.",
      "answer": "The software that meets the above description is Wingbird (S0176)",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mapping_software"
    }
  },
  {
    "instruction": "Which Mitre software meets the following description: The software is a backdoor that has been utilized by FIN8 since at least 2019. The software has been used to target the insurance, retail, technology, and chemical industries in the United States, Canada, South Africa, Panama, and Italy.?",
    "context": "",
    "output": "The software that meets the above description is BADHATCH (S1081)",
    "category": "MitreFlan",
    "instruction_type": "mitre_mapping_software",
    "parsed_raw_data": {
      "question": "Which Mitre software meets the following description: The software is a backdoor that has been utilized by FIN8 since at least 2019. The software has been used to target the insurance, retail, technology, and chemical industries in the United States, Canada, South Africa, Panama, and Italy.",
      "answer": "The software that meets the above description is BADHATCH (S1081)",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mapping_software"
    }
  },
  {
    "instruction": "To which Mitre software does the following description refers: The software is a command-line utility that can be used to query Active Directory for information from a system within a domain.  It is typically installed only on Windows Server versions but can be installed on non-server variants through the Microsoft-provided Remote Server Administration Tools bundle.?",
    "context": "",
    "output": "The software that refer to the above description is dsquery (S0105)",
    "category": "MitreFlan",
    "instruction_type": "mitre_mapping_software",
    "parsed_raw_data": {
      "question": "To which Mitre software does the following description refers: The software is a command-line utility that can be used to query Active Directory for information from a system within a domain.  It is typically installed only on Windows Server versions but can be installed on non-server variants through the Microsoft-provided Remote Server Administration Tools bundle.",
      "answer": "The software that refer to the above description is dsquery (S0105)",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mapping_software"
    }
  },
  {
    "instruction": "Which Mitre software meets the following description: The software is a first stage implant composed of VBS and PowerShell scripts that has been used by WIRTE since at least 2021.?",
    "context": "",
    "output": "The software that meets the above description is Ferocious (S0679)",
    "category": "MitreFlan",
    "instruction_type": "mitre_mapping_software",
    "parsed_raw_data": {
      "question": "Which Mitre software meets the following description: The software is a first stage implant composed of VBS and PowerShell scripts that has been used by WIRTE since at least 2021.",
      "answer": "The software that meets the above description is Ferocious (S0679)",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mapping_software"
    }
  },
  {
    "instruction": "Which Mitre software meets the following description: The software is a legitimate remote administration tool that has been used since at least 2016 by threat actors including MuddyWater and GOLD SOUTHFIELD to connect to and conduct lateral movement in target environments.?",
    "context": "",
    "output": "The software that meets the above description is ConnectWise (S0591)",
    "category": "MitreFlan",
    "instruction_type": "mitre_mapping_software",
    "parsed_raw_data": {
      "question": "Which Mitre software meets the following description: The software is a legitimate remote administration tool that has been used since at least 2016 by threat actors including MuddyWater and GOLD SOUTHFIELD to connect to and conduct lateral movement in target environments.",
      "answer": "The software that meets the above description is ConnectWise (S0591)",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mapping_software"
    }
  },
  {
    "instruction": "Which Mitre ATT&CK software meets the following description: The software is a publicly available, multiplatform remote administration tool (RAT) that has been used by criminal and APT groups since at least 2012.",
    "context": "",
    "output": "The software that meets the above description is NETWIRE (S0198)",
    "category": "MitreFlan",
    "instruction_type": "mitre_mapping_software",
    "parsed_raw_data": {
      "question": "Which Mitre ATT&CK software meets the following description: The software is a publicly available, multiplatform remote administration tool (RAT) that has been used by criminal and APT groups since at least 2012.",
      "answer": "The software that meets the above description is NETWIRE (S0198)",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_mapping_software"
    }
  }
]