[
  {
    "instruction": "To which platforms the  MITRE ATT&CK technique T1578.001 is applicable\nA. Office 365,  Windows, Google Workspace, B. IaaS, C. Linux,  Network,  Windows,  macOS, IaaS, D. IaaS,  Linux,  Network,  Office 365,  SaaS,  Windows,  macOS, Google Workspace",
    "context": "",
    "output": "B. IaaS",
    "category": "MitreFlan",
    "instruction_type": "mitre_platform_mapping_options_technique",
    "parsed_raw_data": {
      "question": "To which platforms the  MITRE ATT&CK technique T1578.001 is applicable",
      "options": "A. Office 365,  Windows, Google Workspace, B. IaaS, C. Linux,  Network,  Windows,  macOS, IaaS, D. IaaS,  Linux,  Network,  Office 365,  SaaS,  Windows,  macOS, Google Workspace",
      "choice": "B. IaaS",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_platform_mapping_options_technique"
    }
  },
  {
    "instruction": "Question: To which platforms the  MITRE ATT&CK technique T1114.003 is applicable\nA. Google Workspace,  IaaS,  Office 365,  SaaS, Azure AD, B. Linux,  Office 365,  Windows,  macOS, Google Workspace, C. macOS, Windows, D. Windows, Linux\nAnswer:",
    "context": "",
    "output": "B. Linux,  Office 365,  Windows,  macOS, Google Workspace",
    "category": "MitreFlan",
    "instruction_type": "mitre_platform_mapping_options_technique",
    "parsed_raw_data": {
      "question": "To which platforms the  MITRE ATT&CK technique T1114.003 is applicable",
      "options": "A. Google Workspace,  IaaS,  Office 365,  SaaS, Azure AD, B. Linux,  Office 365,  Windows,  macOS, Google Workspace, C. macOS, Windows, D. Windows, Linux",
      "choice": "B. Linux,  Office 365,  Windows,  macOS, Google Workspace",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_platform_mapping_options_technique"
    }
  },
  {
    "instruction": "To which platforms the  MITRE ATT&CK technique T1571 is applicable\n\nA. Linux,  Windows, Containers, B. Google Workspace,  IaaS,  Linux,  Network,  Office 365,  SaaS,  Windows,  macOS, Azure AD, C. Google Workspace,  IaaS,  Office 365, Azure AD, D. Windows,  macOS, Linux\nAnswer:",
    "context": "",
    "output": "D. Windows,  macOS, Linux",
    "category": "MitreFlan",
    "instruction_type": "mitre_platform_mapping_options_technique",
    "parsed_raw_data": {
      "question": "To which platforms the  MITRE ATT&CK technique T1571 is applicable",
      "options": "A. Linux,  Windows, Containers, B. Google Workspace,  IaaS,  Linux,  Network,  Office 365,  SaaS,  Windows,  macOS, Azure AD, C. Google Workspace,  IaaS,  Office 365, Azure AD, D. Windows,  macOS, Linux",
      "choice": "D. Windows,  macOS, Linux",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_platform_mapping_options_technique"
    }
  },
  {
    "instruction": "To which platforms the  MITRE ATT&CK technique T1555.005 is applicable\n\nA. Google Workspace,  IaaS,  Linux,  Office 365,  Windows,  macOS, Azure AD, B. Windows,  macOS, Linux, C. IaaS,  Linux,  Network,  Office 365,  SaaS,  Windows,  macOS, Google Workspace, D. macOS\nAnswer:",
    "context": "",
    "output": "B. Windows,  macOS, Linux",
    "category": "MitreFlan",
    "instruction_type": "mitre_platform_mapping_options_technique",
    "parsed_raw_data": {
      "question": "To which platforms the  MITRE ATT&CK technique T1555.005 is applicable",
      "options": "A. Google Workspace,  IaaS,  Linux,  Office 365,  Windows,  macOS, Azure AD, B. Windows,  macOS, Linux, C. IaaS,  Linux,  Network,  Office 365,  SaaS,  Windows,  macOS, Google Workspace, D. macOS",
      "choice": "B. Windows,  macOS, Linux",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_platform_mapping_options_technique"
    }
  },
  {
    "instruction": "Question: To which platforms the  MITRE ATT&CK technique T1558.003 is applicable\nA. Windows, B. Office 365,  SaaS, Google Workspace, C. SaaS, D. IaaS\nAnswer:",
    "context": "",
    "output": "A. Windows",
    "category": "MitreFlan",
    "instruction_type": "mitre_platform_mapping_options_technique",
    "parsed_raw_data": {
      "question": "To which platforms the  MITRE ATT&CK technique T1558.003 is applicable",
      "options": "A. Windows, B. Office 365,  SaaS, Google Workspace, C. SaaS, D. IaaS",
      "choice": "A. Windows",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_platform_mapping_options_technique"
    }
  },
  {
    "instruction": "Q: To which platforms the  MITRE ATT&CK technique T1602.001 is applicable\n\nOptions:\nA. Network, B. Linux,  Windows,  macOS, Azure AD, C. Containers,  Google Workspace,  IaaS,  Linux,  Office 365,  SaaS,  Windows,  macOS, Azure AD, D. Linux,  Office 365,  SaaS,  Windows,  macOS, Google Workspace",
    "context": "",
    "output": "A. Network",
    "category": "MitreFlan",
    "instruction_type": "mitre_platform_mapping_options_technique",
    "parsed_raw_data": {
      "question": "To which platforms the  MITRE ATT&CK technique T1602.001 is applicable",
      "options": "A. Network, B. Linux,  Windows,  macOS, Azure AD, C. Containers,  Google Workspace,  IaaS,  Linux,  Office 365,  SaaS,  Windows,  macOS, Azure AD, D. Linux,  Office 365,  SaaS,  Windows,  macOS, Google Workspace",
      "choice": "A. Network",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_platform_mapping_options_technique"
    }
  },
  {
    "instruction": "On which platforms is the MITRE ATT&CK technique Archive Collected Data: Archive via Utility (T1560.001) applicable\n\nPossible answers:\nA. Windows,  macOS, Linux, B. Windows, Network, C. Linux,  Windows, Containers, D. Network,  SaaS,  Windows,  macOS, Linux",
    "context": "",
    "output": "A. Windows,  macOS, Linux",
    "category": "MitreFlan",
    "instruction_type": "mitre_platform_mapping_options_technique",
    "parsed_raw_data": {
      "question": "On which platforms is the MITRE ATT&CK technique Archive Collected Data: Archive via Utility (T1560.001) applicable",
      "options": "A. Windows,  macOS, Linux, B. Windows, Network, C. Linux,  Windows, Containers, D. Network,  SaaS,  Windows,  macOS, Linux",
      "choice": "A. Windows,  macOS, Linux",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_platform_mapping_options_technique"
    }
  },
  {
    "instruction": "On which platforms is the MITRE ATT&CK technique Container and Resource Discovery (T1613) applicable\n\nA. Network, IaaS, B. Google Workspace,  IaaS,  Office 365,  SaaS, Azure AD, C. Containers, D. Office 365,  SaaS,  Windows,  macOS, Linux\nAnswer:",
    "context": "",
    "output": "C. Containers",
    "category": "MitreFlan",
    "instruction_type": "mitre_platform_mapping_options_technique",
    "parsed_raw_data": {
      "question": "On which platforms is the MITRE ATT&CK technique Container and Resource Discovery (T1613) applicable",
      "options": "A. Network, IaaS, B. Google Workspace,  IaaS,  Office 365,  SaaS, Azure AD, C. Containers, D. Office 365,  SaaS,  Windows,  macOS, Linux",
      "choice": "C. Containers",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_platform_mapping_options_technique"
    }
  },
  {
    "instruction": "Q: To which platforms the  MITRE technique  with the following description is applicable Adversaries may use an existing, legitimate external Web service as a means for sending commands to a compromised system without receiving return output over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems may opt to send the output from those commands back over a different C2 channel, including to another distinct Web service. Alternatively, compromised systems may return no output at all in cases where adversaries want to send instructions to systems and do not want a response.\n\nPopular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.\n\nA. Containers,  Google Workspace,  Office 365,  SaaS, Azure AD, B. PRE, C. Linux,  Windows,  macOS, IaaS, D. Windows,  macOS, Linux\nA:",
    "context": "",
    "output": "D. Windows,  macOS, Linux",
    "category": "MitreFlan",
    "instruction_type": "mitre_platform_mapping_options_technique",
    "parsed_raw_data": {
      "question": "To which platforms the  MITRE technique  with the following description is applicable Adversaries may use an existing, legitimate external Web service as a means for sending commands to a compromised system without receiving return output over the Web service channel. Compromised systems may leverage popular websites and social media to host command and control (C2) instructions. Those infected systems may opt to send the output from those commands back over a different C2 channel, including to another distinct Web service. Alternatively, compromised systems may return no output at all in cases where adversaries want to send instructions to systems and do not want a response.\n\nPopular websites and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.",
      "options": "A. Containers,  Google Workspace,  Office 365,  SaaS, Azure AD, B. PRE, C. Linux,  Windows,  macOS, IaaS, D. Windows,  macOS, Linux",
      "choice": "D. Windows,  macOS, Linux",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_platform_mapping_options_technique"
    }
  },
  {
    "instruction": "To which platforms the  MITRE technique  with the following description is applicable Adversaries may bridge network boundaries by modifying a network device\u2019s Network Address Translation (NAT) configuration. Malicious modifications to NAT may enable an adversary to bypass restrictions on traffic routing that otherwise separate trusted and untrusted networks.\n\nNetwork devices such as routers and firewalls that connect multiple networks together may implement NAT during the process of passing packets between networks. When performing NAT, the network device will rewrite the source and/or destination addresses of the IP address header. Some network designs require NAT for the packets to cross the border device.  A typical example of this is environments where internal networks make use of non-Internet routable addresses.\n\nWhen an adversary gains control of a network boundary device, they can either leverage existing NAT configurations to send traffic between two separated networks, or they can implement NAT configurations of their own design.  In the case of network designs that require NAT to function, this enables the adversary to overcome inherent routing limitations that would normally prevent them from accessing protected systems behind the border device.  In the case of network designs that do not require NAT, address translation can be used by adversaries to obscure their activities, as changing the addresses of packets that traverse a network boundary device can make monitoring data transmissions more challenging for defenders.  \n\nAdversaries may use Patch System Image to change the operating system of a network device, implementing their own custom NAT mechanisms to further obscure their activities\n\nA. macOS, Windows, B. Network,  macOS, Linux, C. IaaS,  SaaS, Azure AD, D. Network\nAnswer:",
    "context": "",
    "output": "D. Network",
    "category": "MitreFlan",
    "instruction_type": "mitre_platform_mapping_options_technique",
    "parsed_raw_data": {
      "question": "To which platforms the  MITRE technique  with the following description is applicable Adversaries may bridge network boundaries by modifying a network device\u2019s Network Address Translation (NAT) configuration. Malicious modifications to NAT may enable an adversary to bypass restrictions on traffic routing that otherwise separate trusted and untrusted networks.\n\nNetwork devices such as routers and firewalls that connect multiple networks together may implement NAT during the process of passing packets between networks. When performing NAT, the network device will rewrite the source and/or destination addresses of the IP address header. Some network designs require NAT for the packets to cross the border device.  A typical example of this is environments where internal networks make use of non-Internet routable addresses.\n\nWhen an adversary gains control of a network boundary device, they can either leverage existing NAT configurations to send traffic between two separated networks, or they can implement NAT configurations of their own design.  In the case of network designs that require NAT to function, this enables the adversary to overcome inherent routing limitations that would normally prevent them from accessing protected systems behind the border device.  In the case of network designs that do not require NAT, address translation can be used by adversaries to obscure their activities, as changing the addresses of packets that traverse a network boundary device can make monitoring data transmissions more challenging for defenders.  \n\nAdversaries may use Patch System Image to change the operating system of a network device, implementing their own custom NAT mechanisms to further obscure their activities",
      "options": "A. macOS, Windows, B. Network,  macOS, Linux, C. IaaS,  SaaS, Azure AD, D. Network",
      "choice": "D. Network",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_platform_mapping_options_technique"
    }
  }
]