I am new to Linux and Ubuntu. I am slowly familiarising myself with simple commands and functioning primarily on a cut and paste as per instructions.I have managed to generate json files using the mvt-ios instructions. I now have to use STIX2 for analysis of files. Any suggestions on how to setup and run STIX2 on Ubuntu 21.04.
Following is a basic usage of check-backup:
mvt-ios check-backup –output /path/to/output/ /path/to/backup/udid/
This command will create a few JSON files containing the results from the extraction. If you do not specify a –output option, mvt-ios will just process the data without storing results on disk.
Through the –iocs argument you can specify a STIX2 file defining a list of malicious indicators to check against the records extracted from the backup by mvt. Any matches will be highlighted in the terminal output as well as saved in the output folder using a “_detected” suffix to the JSON file name.