{ "namespace": "stealth_malware", "description": "Classification based on malware stealth techniques. Described in https://vxheaven.org/lib/pdf/Introducing%20Stealth%20Malware%20Taxonomy.pdf", "version": 1, "refs": [ "https://vxheaven.org/lib/pdf/Introducing%20Stealth%20Malware%20Taxonomy.pdf" ], "predicates": [ { "value": "type", "expanded": "Stealth technique type", "uuid": "8108ddbb-f2a9-595b-945e-72c9ede008cd" } ], "values": [ { "predicate": "type", "entry": [ { "value": "0", "expanded": "No OS or system compromise. The malware runs as a normal user process using only official API calls.", "uuid": "c62c6605-c7b3-51b8-a3b7-0f851ec53328" }, { "value": "I", "expanded": "The malware modifies constant sections of the kernel and/or processes such as code sections.", "uuid": "06f31bde-34ea-5fff-b120-79bf0de6f519" }, { "value": "II", "expanded": "The malware does not modify constant sections but only the dynamic sections of the kernel and/or processes such as data sections.", "uuid": "f4fa616f-e2c0-5daf-b667-858f29eb4c85" }, { "value": "III", "expanded": "The malware does not modify any sections of the kernel and/or processes but influences the system without modifying the OS. For example using hardware virtualization techniques.", "uuid": "a03bf180-772a-5872-ba5c-baed748d3bb6" } ] } ], "uuid": "27cf86e4-eb7b-510b-804d-dc78e9a53182" }