Skip to content

Commit 5417cff

Browse files
authored
Merge pull request #35 from NetBLADE-framework/v2025-update
BLADE Framework v2025 Content Update
2 parents 8078c1f + a6c73b0 commit 5417cff

177 files changed

Lines changed: 817 additions & 317 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎CHANGELOG.md‎

Lines changed: 175 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,175 @@
1+
# v2025
2+
3+
## Phases
4+
5+
### New
6+
- None
7+
8+
### Updated
9+
- `Actions on the Objective`: Minor wording changes.
10+
11+
### Retired
12+
- None
13+
14+
## Tactics
15+
16+
### New
17+
- `TAC-25 Accessibility Options Abuse`
18+
- `TAC-26 Impersonation`
19+
- `TAC-27 Session Manipulation`
20+
- `TAC-28 Queue Bypass`
21+
- `TAC-29 Session Transfer`
22+
- `TAC-30 Bonus Farming`
23+
- `TAC-31 AI Model Training`
24+
- `TAC-32 Geo-Location Spoofing`
25+
- `TAC-33 Device Emulation`
26+
- `TAC-34 Attack Surface Identification`
27+
- `TAC-35 Fake Credibility Generation`
28+
- `TAC-36 Specific Target Scraping`
29+
- `TAC-37 Loose Target Scraping`
30+
- `TAC-38 Identity Acquisition`
31+
- `TAC-39 Inventory Manipulation`
32+
- `TAC-40 Add to Cart`
33+
- `TAC-41 Account Enumeration`
34+
- `TAC-42 Payment Card Enumeration`
35+
- `TAC-43 Information Release`
36+
37+
38+
### Updated
39+
- `TAC-02 Credential Acquisition`: Minor wording changes.
40+
- `TAC-03 Infrastructure Acquisition`: Minor wording changes.
41+
- `TAC-04 Payment Detail Acquisition`: Minor wording changes.
42+
- `TAC-08 Mitigation Bypass` -> `TAC-08 CAPTCHA Bypass`: Renamed.
43+
- `TAC-10 Proxying`: Major wording changes.
44+
- `TAC-12 Account Creation`: Minor wording changes.
45+
- `TAC-15 Stock Purchase` -> `TAC-15 Purchase`: Major wording changes. Renamed.
46+
- `TAC-20 Transaction Redirect` -> `TAC-20 Cashout`: Major wording changes. Renamed.
47+
- `TAC-21 Exfiltration` -> `TAC-21 Data Extraction`: Renamed.
48+
49+
50+
### Retired
51+
- `TAC-06 Specific Target`: Replaced by `TAC-36 Specific Target Scraping`
52+
- `TAC-07 Loose Target`: Replaced by `TAC-37 Loose Target Scraping`
53+
- `TAC-16 Spinning`
54+
- `TAC-17 Sniping`
55+
56+
## Techniques
57+
58+
### New
59+
- `TEQ-081 Accessibility Downgrade`
60+
- `TEQ-082 Session Persistence`
61+
- `TEQ-083 Session Reassumption`
62+
- `TEQ-084 Queue Flooding`
63+
- `TEQ-085 Queue Position Tracking`
64+
- `TEQ-086 Queue Jumping`
65+
- `TEQ-087 Queue Evasion`
66+
- `TEQ-088 Session Spoofing`
67+
- `TEQ-089 Queue Position Transfer`
68+
- `TEQ-090 Referral Program Exploitation`
69+
- `TEQ-091 Clickjacking`
70+
- `TEQ-092 Bonus Clipping`
71+
- `TEQ-093 LLM Training Data`
72+
- `TEQ-094 LAM Training Data`
73+
- `TEQ-095 GPS Spoofing`
74+
- `TEQ-096 Mobile Network Spoofing`
75+
- `TEQ-097 Accept-Language Manipulation`
76+
- `TEQ-098 TLS Spoofing`
77+
- `TEQ-099 Header Spoofing`
78+
- `TEQ-100 Path Enumeration`
79+
- `TEQ-101 Endpoint Enumeration`
80+
- `TEQ-102 Fake Account Creation`
81+
- `TEQ-103 Queue Exhaustion`
82+
- `TEQ-104 Queue Entry`
83+
- `TEQ-105 Account Ageing`
84+
- `TEQ-106 Fuzzing`
85+
- `TEQ-107 Synthetic Account Creation`
86+
- `TEQ-108 Impersonated Account Creation`
87+
- `TEQ-109 Inventory Exhaustion`
88+
- `TEQ-110 Mass Add to Cart`
89+
- `TEQ-111 Loyalty Points Redemption`
90+
- `TEQ-112 Deepfakes`
91+
- `TEQ-113 Credit/Debit Card Cracking`
92+
- `TEQ-114 Gift Card Cracking`
93+
- `TEQ-115 Intellectual Property Leak`
94+
- `TEQ-116 Inventory Information Extraction`
95+
- `TEQ-117 Credential Extraction`
96+
- `TEQ-118 Payment Detail Extraction`
97+
- `TEQ-119 PII Extraction`
98+
- `TEQ-120 Intellectual Property Extraction`
99+
100+
### Updated
101+
- `TEQ-002 URL Disguise`: Minor wording changes.
102+
- `TEQ-003 Data Dumps`: Added `TAC-38 Identity Acquisition` as parent.
103+
- `TEQ-004 Malware` -> `TEQ-004 Infostealer`: Major wording changes. Renamed.
104+
- `TEQ-005 Person in the Middle`: Minor wording changes.
105+
- `TEQ-008 Botnet`: Minor wording changes. Removed `TAC-10 Proxying` as parent.
106+
- `TEQ-011 Supply Chain Compromise` -> `TEQ-011 Trusted Infrastructure`: Major wording changes. Renamed.
107+
- `TEQ-015 Continual Content Scraping`: Removed `TAC-06 Specific Target` and `TAC-07 Loose Target` as parents and replaced with `TAC-36 Specific Target Scraping` and `TAC-37 Loose Target Scraping`.
108+
- `TEQ-018 CAPTCHA Farm`: Minor wording changes.
109+
- `TEQ-020 Token Bypass`: Removed `TAC-08 Mitigation Bypass` as parent and replaced with `TAC-27 Session Manipulation`.
110+
- `TEQ-021 Cookie Abuse`: Removed `TAC-08 Mitigation Bypass` as parent and replaced with `TAC-27 Session Manipulation`.
111+
- `TEQ-022 Accessibility Options Abuse` -> `TEQ-022 Accessibilty Feature Abuse`: Minor wording changes. Renamed. Removed `TAC-08 Mitigation Bypass`, `TAC-09 Human Emulation` and `TAC-14 Fake Interaction` as parents and replaced with `TAC-25 Accessibility Option Abuse`.
112+
- `TEQ-023 MFA Bypass`: Removed `TAC-08 Mitigation Bypass` as parent and replaced with `TAC-26 Impersonation`.
113+
- `TEQ-024 Credential Pinning`: Removed `TAC-08 Mitigation Bypass` as parent and replaced with `TAC-26 Impersonation`.
114+
- `TEQ-025 Certificate Abuse`: Removed `TAC-08 Mitigation Bypass` as parent and replaced with `TAC-27 Session Manipulation`.
115+
- `TEQ-027 User Agent Spoofing`: Minor wording changes. Removed `TAC-09 Human Emulation` and `TAC-10 Proxying` as parents and replaced with `TAC-33 Device Emulation`.
116+
- `TEQ-028 Device Fingerprint Emulation` -> `TEQ-028 Device Configuration Emulation`: Minor wording changes. Renamed. Removed `TAC-09 Human Emulation` as parent and replaced with `TAC-33 Device Emulation`.
117+
- `TEQ-029 Notification Hijack`: Removed `TAC-14 Fake Interaction` as parent.
118+
- `TEQ-030 IP Rotation`: Added `TAC-32 Geolocation Spoofing` as parent.
119+
- `TEQ-033 Smurfing` -> `TEQ-033 Multi-Accounting`: Renamed.
120+
- `TEQ-036 Social Media Creation`: Major wording changes. Removed `TAC-12 Account Creation` as parent and replaced with `TAC-38 Identity Acquisition`.
121+
- `TEQ-037 Email Generator`: Removed `TAC-12 Account Creation` as parent and replaced with `TAC-38 Identity Acquisition`.
122+
- `TEQ-038 Call/SMS Generator`: Removed `TAC-12 Account Creation` as parent and replaced with `TAC-38 Identity Acquisition`.
123+
- `TEQ-039 Virtual Wallet Creation`: Removed `TAC-12 Account Creation` as parent and replaced with `TAC-38 Identity Acquisition`.
124+
- `TEQ-040 Credential Cracking`: Minor wording changes.
125+
- `TEQ-041 Credential Stuffing`: Added `TAC-41 Account Enumeration` as parent.
126+
- `TEQ-045 Written Interaction` -> `TEQ-045 Content Posting`: Minor wording changes. Renamed.
127+
- `TEQ-047 Form Filling` -> `TEQ-047 Form Submission`: Major wording changes. Renamed.
128+
- `TEQ-049 Automated Add to Cart`: Removed `TAC-15 Stock Purchase`, `TAC-16 Spinning` and `TAC-10 Sniping` as parents and replaced with `TAC-40 Add to Cart`.
129+
- `TEQ-050 Automated Purchase`: Removed `TAC-16 Spinning` and `TAC-10 Sniping` as parents.
130+
- `TEQ-051 Stock Price Manipulation` -> `TEQ-051 Price Manipulation`: Minor wording changes. Renamed.
131+
- `TEQ-053 Inventory Hoarding`: Major wording changes. Removed `TAC-16 Spinning` as parent and replaced with `TAC-39 Inventory Manipulation`.
132+
- `TEQ-054 Transfer of Cart`: Removed `TAC-16 Spinning` as parent and replaced with `TAC-29 Session Transfer`.
133+
- `TEQ-055 Automated Sale`: Major wording changes. Removed `TAC-16 Spinning` and `TAC-17 Sniping` as parents.
134+
- `TEQ-056 Automated Bid`: Major wording changes. Removed `TAC-17 Sniping` as parent and replaced with `TAC-15 Purchase`.
135+
- `TEQ-061 Credit/Debit Card Abuse`: Minor wording changes.
136+
- `TEQ-062 Gift Card Abuse`: Major wording changes.
137+
- `TEQ-063 Loyalty Points Abuse`: Minor wording changes.
138+
- `TEQ-061 Buy Now Pay Later Abuse`: Major wording changes.
139+
- `TEQ-065 ATS Fraud` -> `TEQ-065 Bank Transfer`: Renamed.
140+
- `TEQ-066 Automated Advertisement of Stock` -> `TEQ-066 Inventory Information Release`: Minor wording changes. Renamed. Removed `TAC-21 Exfiltration` as parent and replaced with `TAC-43 Information Release`
141+
- `TEQ-067 Credential Dumping`: Major wording changes. Removed `TAC-21 Exfiltration` as parent and replaced with `TAC-43 Information Release`
142+
- `TEQ-069 Payment Detail Dumping`: Removed `TAC-21 Exfiltration` as parent and replaced with `TAC-43 Information Release`
143+
- `TEQ-070 PII Dumping`: Removed `TAC-21 Exfiltration` as parent and replaced with `TAC-43 Information Release`
144+
- `TEQ-072 Jigging` -> `TEQ-072 Address Manipulation`: Minor wording changes. Renamed.
145+
- `TEQ-074 Driver Intercept` -> `TEQ-074 Driver Redirect`: Major wording changes. Renamed.
146+
- `TEQ-076 Manual Sale`: Major wording changes.
147+
- `TEQ-078 Valid Accounts`: Minor wording changes.
148+
- `TEQ-079 Fund Withdrawal` -> `TEQ-079 Account Balance Withdrawal`: Renamed.
149+
150+
151+
152+
### Retired
153+
- `TEQ-007 Fake Credibility Generation`: Replaced by `TAC-35 Fake Credibility Generation`
154+
- `TEQ-009 Command & Control`
155+
- `TEQ-017 Technical Reconnaissance`: Replaced by `TAC-34 Attack Surface Identification` and `TAC-44 Vulnerability Identification`
156+
- `TEQ-043 Comment Flooding`: Merged into `TEQ-045 Content Posting`
157+
- `TEQ-048 Overlay Attack`
158+
- `TEQ-052 Distributed Stock Purchase`
159+
- `TEQ-057 Pre-Release Buying`
160+
- `TEQ-068 API Information Flow Exfiltration`
161+
162+
## Killchains
163+
164+
### New
165+
- None
166+
167+
### Updated
168+
- Updated all killchains to reflect the new and updated tactics and techniques
169+
170+
### Retired
171+
- None
172+
173+
## Website
174+
- Renamed framework from Business Logic *Attack* Definition Framework to Business Logic *Abuse* Definition Framework and updated terminology accordingly. The term attack could imply an immediate need for remediation and force a binary response, such as blocking or not blocking. In cases of business logic abuse, multiple levers could be pulled to assist companies facing these challenges. Customers often need to make a business decision, not just a security decision
175+
- Tactics and techniques in Matrix and Killchain views are now displayed in alphabetical order

‎_config.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
1-
title: "OWASP BLADE: Business Logic Attack Definition Framework"
1+
title: "OWASP BLADE: Business Logic Abuse Definition Framework"
22
locale: "en-US"
3-
description: "The OWSAP Business Logic Attack Definition (BLADE) Framework, is an open-source knowledge-base created to help cybersecurity professionals fight cyber threats."
3+
description: "The OWASP Business Logic Abuse Definition (BLADE) Framework, is an open-source knowledge-base created to help cybersecurity professionals fight cyber threats."
44
#tagline: "The BLADE framework for Bot attacks"
55
remote_theme: "mmistakes/minimal-mistakes@4.23.0"
66

‎_includes/elements/blade__matrix.html‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@
1414
</label>
1515
<div class="tab-content">
1616
<ul>
17-
{% assign tactics = site.tactics | where_exp:"p", "p.parent == phase.id" %}
17+
{% assign tactics = site.tactics | where_exp:"p", "p.parent == phase.id" | sort: "title" %}
1818
{%for tactic in tactics %}
1919
<li>
2020
<input type="checkbox" class="technique-checkbox" id="{{ tactic.slug }}-{{ forloop.index }}">
@@ -23,7 +23,7 @@
2323
</label>
2424
<div class="tab-subcontent">
2525
<ul>
26-
{% assign techniques = site.techniques | where_exp:"p", "p.parent contains tactic.id" %}
26+
{% assign techniques = site.techniques | where_exp:"p", "p.parent contains tactic.id" | sort: "title" %}
2727
{%for technique in techniques %}
2828
<li><a href="{{ technique.url }}">{{technique.title}}</a></li>
2929
{%endfor%}

‎_includes/page__kc.html‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@
4343
{% assign alltactics = site.tactics | where_exp:"p", "p.parent == phase.id" %}
4444
{% for tactictitle in page.tactics %}
4545
{% assign newkc_tactics = alltactics | where_exp:"p", "p.title == tactictitle" %}
46-
{% assign tactics = tactics | concat: newkc_tactics %}
46+
{% assign tactics = tactics | concat: newkc_tactics | sort: "title" %}
4747
{%endfor%}
4848

4949
<div class="col-12 col-lg">
@@ -57,7 +57,7 @@
5757
{% assign alltechniques = site.techniques | where_exp:"p", "p.parent contains tactic.id" %}
5858
{% for techniquetitle in page.techniques %}
5959
{% assign newkc_techniques = alltechniques | where_exp:"p", "p.title == techniquetitle" %}
60-
{% assign techniques = techniques | concat: newkc_techniques %}
60+
{% assign techniques = techniques | concat: newkc_techniques | sort: "title" %}
6161
{%endfor%}
6262

6363
<div class="tab">

‎_kill-chains/account-takeover-bot.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Account Takeover Bot
33
layout: kill-chain
44
phases: [Resource Development, Reconnaissance, Defence Bypass, Attack Execution, Actions on the Objective, Post-Attack]
5-
tactics: [Credential Acquisition, Infrastructure Acquisition, Tool Development, Specific Target, Loose Target, Mitigation Bypass, Human Emulation, Proxying, Smokescreening, Account Takeover, Fake Interaction, Exfiltration, Sale]
6-
techniques: [Data Dumps, Malware, Person in the Middle, Social Engineering, Botnet, Command & Control, Proxies, Supply Chain Compromise, Development of Tools, Testing of Tools, Campaign Reuse, Technical Reconnaissance, CAPTCHA Farm, Automated CAPTCHA Bypass, MFA Bypass, Token Bypass, Cookie Abuse, Credential Pinning, User Agent Spoofing, Device Fingerprint Emulation, IP Rotation, Volumetric Traffic Disguise, Target Diversification, Smurfing, Credential Cracking, SSO Compromise, Overlay Attack, Credential Dumping, Payment Detail Dumping, PII Dumping, Information Brokerage, Automated Sale, Manual Sale]
5+
tactics: [Credential Acquisition, Infrastructure Acquisition, Tool Development, Attack Surface Identification, Vulnerability Identification, Device Emulation, Proxying, CAPTCHA Bypass, Human Emulation, Impersonation, Session Manipulation, Geolocation Spoofing, Smokescreening, Account Takeover, Data Extraction, Information Release, Sale]
6+
techniques: [Data Dumps, Infostealer, Person in the Middle, Social Engineering, Botnet, Proxies, Trusted Infrastructure, Development of Tools, Testing of Tools, Campaign Reuse, Path Enumeration, Endpoint Enumeration, Fuzzing, CAPTCHA Farm, Automated CAPTCHA Bypass, Mouse Usage, IP Rotation, Volumetric Traffic Disguise, Target Diversification, MFA Bypass, Credential Pinning, Token Bypass, Cookie Abuse, User Agent Spoofing, Device Configuration Emulation, TLS Spoofing, Header Spoofing, Credential Cracking, Credential Stuffing, SSO Compromise, Credential Extraction, Payment Detail Extraction, PII Extraction, Automated Sale, Manual Sale, Information Brokerage, Credential Dumping, Payment Detail Dumping, PII Dumping]
77
short-desc: An account takeover bot is used by adversaries to gain unauthorised access to user accounts through automation, giving them the ability to use, manipulate, and/or extract information from the account as though they were the legitimate owner.
88
---

‎_kill-chains/ad-click-bot-own-ads.md‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Ad Click Bot (Own Ads)
33
layout: kill-chain
44
phases: [Resource Development, Defence Bypass, Attack Execution]
5-
tactics: [Website Creation, Infrastructure Acquisition, Human Emulation, Proxying, Fake Interaction]
6-
techniques: [Cloning, New Site Creation, URL Disguise, Botnet, Proxies, Command & Control, Fake Credibility Generation, Mouse Usage, User Agent Spoofing, IP Rotation, Click Interaction]
7-
short-desc: Ad click bots are used to commit digital ad fraud by automatically clicking on digital advertisements to inflate the number of clicks the advertisement recieves. With adversary owned ads, the objective for the adversary is to gain payment for clicks on these ads.
5+
tactics: [Website Creation, Infrastructure Acquisition, Device Emulation, Proxying, Human Emulation, Geolocation Spoofing, Fake Interaction]
6+
techniques: [Cloning, New Site Creation, URL Disguise, Botnet, Proxies, Mouse Usage, IP Rotation, User Agent Spoofing, Device Configuration Emulation, Click Interaction]
7+
short-desc: Ad click bots are used to commit digital ad fraud by automatically clicking on digital advertisements to inflate the number of clicks the advertisement receives. With adversary owned ads, the objective for the adversary is to gain payment for clicks on these ads.
88
---

‎_kill-chains/ad-click-bot-target-ads.md‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Ad Click Bot (Target Ads)
33
layout: kill-chain
44
phases: [Resource Development, Reconnaissance, Defence Bypass, Attack Execution]
5-
tactics: [Infrastructure Acquisition, Specific Target, Mitigation Bypass, Human Emulation, Proxying, Smokescreening, Fake Interaction]
6-
techniques: [Botnet, Proxies, Command & Control, Continual Content Scraping, CAPTCHA Farm, Automated CAPTCHA Bypass, Token Bypass, Fake Credibility Generation, Mouse Usage, User Agent Spoofing, IP Rotation, Domain Fronting, Volumetric Traffic Disguise, Click Interaction]
7-
short-desc: Ad click bots are used to commit digital ad fraud by automatically clicking on digital advertisements to inflate the number of clicks the advertisement recieves. With non-adversary owned ads, the objective for the adversary is to extinguish the advertising budget of their target.
5+
tactics: [Credential Acquisition, Infrastructure Acquisition, Attack Surface Identification, Device Emulation, Proxying, CAPTCHA Bypass, Human Emulation, Session Manipulation, Geolocation Spoofing, Smokescreening, Fake Interaction]
6+
techniques: [Botnet, Proxies, Valid Accounts, Path Enumeration, CAPTCHA Farm, Automated CAPTCHA Bypass, Mouse Usage, IP Rotation, Domain Fronting, Multi-Accounting, Volumetric Traffic Disguise, Token Bypass, User Agent Spoofing, Device Configuration Emulation, TLS Spoofing, Header Spoofing, Click Interaction]
7+
short-desc: Ad click bots are used to commit digital ad fraud by automatically clicking on digital advertisements to inflate the number of clicks the advertisement receives. With non-adversary owned ads, the objective for the adversary is to extinguish the advertising budget of their target.
88
---

‎_kill-chains/arb-betting-bot.md‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Arbitrage Betting Bot
33
layout: kill-chain
44
phases: [Resource Development, Reconnaissance, Defence Bypass, Attack Execution, Actions on the Objective, Post-Attack]
5-
tactics: [Credential Acquisition, Infrastructure Acquisition, Tool Development, Specific Target, Loose Target, Mitigation Bypass, Human Emulation, Proxying, Stock Purchase, Sniping, Policy Abuse, Transaction Redirect, Invoice Abuse]
6-
techniques: [Valid Accounts, Botnet, Proxies, Command & Control, Development of Tools, Campaign Reuse, Continual Content Scraping, Periodic Content Scraping, Technical Reconnaissance, CAPTCHA Farm, Automated CAPTCHA Bypass, Token Bypass, Cookie Abuse, Mouse Usage, User Agent Spoofing, Device Fingerprint Emulation, Botnet, IP Rotation, Domain Fronting, Automated Purchase, Terms of Use Abuse, Fund Withdrawal, Fake Identity]
5+
tactics: [Credential Acquisition, Infrastructure Acquisition, Tool Development, Attack Surface Identification, CAPTCHA Bypass, Human Emulation, Proxying, Session Manipulation, Device Emulation, Purchase, Fake Credibility Generation, Policy Abuse, Cashout, Invoice Abuse]
6+
techniques: [Valid Accounts, Botnet, Proxies, Development of Tools, Campaign Reuse, Path Enumeration, Endpoint Enumeration, CAPTCHA Farm, Automated CAPTCHA Bypass, Mouse Usage, IP Rotation, Multi-Accounting, Token Bypass, Cookie Abuse, User Agent Spoofing, Device Configuration Emulation, TLS Spoofing, Header Spoofing, Account Ageing, Automated Purchase, Terms of Use Abuse, Account Balance Withdrawal, Fake Identity]
77
short-desc: Arbitrage betting, or as it is more commonly known “arb” betting, is a form of gambling where the gambler exploits the differences in bookmakers’ opinions on certain odds, thereby ensuring that whatever the outcome of the event the gambler will always turn a profit. Arbitrage betting bots automatically bet on all possible outcomes of the same event simultaneously, placing these bets with different bookmakers who disagree on odds, to guarantee that at least a small return will be made.
8-
---
8+
---

0 commit comments

Comments
 (0)