{"id":"T1072","name":"Software Deployment Tools","url":"https://attack.mitre.org/techniques/T1072","tactics":["execution","lateral-movement"],"platforms":["Linux","macOS","Network Devices","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0223","stix_id":"x-mitre-detection-strategy--ea1f5423-64b9-44eb-824f-251aa0faccd2","name":"Detection of Adversary Abuse of Software Deployment Tools","url":"https://attack.mitre.org/detectionstrategies/DET0223","analytics":[{"id":"AN0623","stix_id":"x-mitre-analytic--39ec0aa6-935a-44d3-b206-211981dec3bd","name":"Analytic 0623","description":"Detects SCCM, Intune, or remote push execution spawning scripts or binaries from SYSTEM context or unusual consoles (e.g., cmtrace.exe launching PowerShell or cmd.exe).","url":"https://attack.mitre.org/detectionstrategies/DET0223#AN0623","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Application","channel":"SCCM, Intune logs","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"wineventlog-application"}],"mutable_elements":[{"field":"ParentImageList","description":"Allowlist of known SCCM-related binary spawners (e.g., 'CCMExec.exe')"},{"field":"UserContext","description":"Expected deployment activity from scheduled system accounts"},{"field":"TimeWindow","description":"Unusual deployment timing outside standard maintenance hours"}],"live":true,"detection_strategies":["DET0223"],"techniques":["T1072"]},{"id":"AN0624","stix_id":"x-mitre-analytic--bbb8adb2-434a-483e-af3c-4843241e2158","name":"Analytic 0624","description":"Detects remote scripts or binaries deployed via Puppet, Chef, Ansible, or shell scripts from orchestration servers executing outside maintenance windows or in unmanaged nodes.","url":"https://attack.mitre.org/detectionstrategies/DET0223#AN0624","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"DeployingHostAllowList","description":"Approved orchestration or jump box IPs"},{"field":"ScriptExecutionBaseline","description":"Expected scripts, interpreters, or package managers used"}],"live":true,"detection_strategies":["DET0223"],"techniques":["T1072"]},{"id":"AN0625","stix_id":"x-mitre-analytic--94e3c24f-01ee-45bc-89c0-7024ada7cc66","name":"Analytic 0625","description":"Detects script or binary execution initiated via JAMF, Munki, or custom MDM agents outside of baseline, or JAMF launching new Terminal or osascript processes from remote command payloads.","url":"https://attack.mitre.org/detectionstrategies/DET0223#AN0625","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process and signing chain events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:jamf","channel":"RemoteCommandExecution","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-jamf"}],"mutable_elements":[{"field":"SigningAuthorityList","description":"Expected signing authorities for JAMF and MDM scripts"},{"field":"RemoteCommandInterval","description":"Frequency of remote execution from MDM servers"}],"live":true,"detection_strategies":["DET0223"],"techniques":["T1072"]},{"id":"AN0626","stix_id":"x-mitre-analytic--2e6218d1-1f84-4dc5-8ab5-c24835aafbab","name":"Analytic 0626","description":"Detects cloud-native software deployment or management (e.g., SSM Run Command, Intune) initiating script execution on endpoints outside expected org IDs, admin groups, or maintenance windows.","url":"https://attack.mitre.org/detectionstrategies/DET0223#AN0626","platforms":["SaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"SSM RunCommand","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"IAMRoleAllowList","description":"Approved deployment administrators or service accounts"},{"field":"ExecutionTargetList","description":"Expected endpoints targeted by SaaS deployments"}],"live":true,"detection_strategies":["DET0223"],"techniques":["T1072"]},{"id":"AN0627","stix_id":"x-mitre-analytic--82acd5d4-70e1-4f3e-b059-15bdc55cf4bf","name":"Analytic 0627","description":"Detects central router or switch config management tools (e.g., FortiManager, Cisco Prime) triggering device reboots or config pushes using abnormal accounts or IPs.","url":"https://attack.mitre.org/detectionstrategies/DET0223#AN0627","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:syslog","channel":"config push events","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"networkdevice-syslog"},{"name":"NSM:Flow","channel":"Device-to-Device Deployment Flows","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"PushSourceAllowList","description":"Devices or IPs allowed to push firmware or scripts"},{"field":"AuthUserPattern","description":"Expected CLI or API user performing configuration"}],"live":true,"detection_strategies":["DET0223"],"techniques":["T1072"]}],"live":true,"version":"1.0","techniques":["T1072"]}],"sigma_rules":[{"id":"40b95d31-1afc-469e-8d34-9a3a667d058e","title":"Suspicious Csi.exe Usage","author":"Konstantin Grishchenko, oscd.community","status":"test","level":"medium","date":"2020-10-17","modified":"2022-07-11","description":"Csi.exe is a signed binary from Microsoft that comes with Visual Studio and provides C# interactive capabilities. It can be used to run C# code from a file passed as a parameter in command line. Early version of this utility provided with Microsoft “Roslyn” Community Technology Preview was named 'rcsi.exe'","references":["https://lolbas-project.github.io/lolbas/OtherMSBinaries/Csi/","https://lolbas-project.github.io/lolbas/OtherMSBinaries/Rcsi/","https://enigma0x3.net/2016/11/21/bypassing-application-whitelisting-by-using-rcsi-exe/","https://twitter.com/Z3Jpa29z/status/1317545798981324801"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.execution","attack.stealth","attack.t1072","attack.t1218"],"path":"rules/windows/process_creation/proc_creation_win_csi_execution.yml","techniques":["T1072","T1218"],"cves":[]},{"id":"5817e76f-4804-41e6-8f1d-5fa0b3ecae2d","title":"PUA - Radmin Viewer Utility Execution","author":"frack113","status":"test","level":"medium","date":"2022-01-22","modified":"2023-12-11","description":"Detects the execution of Radmin which can be abused by an adversary to remotely control Windows machines","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1072/T1072.md","https://www.radmin.fr/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.lateral-movement","attack.t1072"],"path":"rules/windows/process_creation/proc_creation_win_pua_radmin.yml","techniques":["T1072"],"cves":[]},{"id":"b4c8da4a-1c12-46b0-8a2b-0a8521d03442","title":"Restricted Software Access By SRP","author":"frack113","status":"test","level":"high","date":"2023-01-12","modified":null,"description":"Detects restricted access to applications by the Software Restriction Policies (SRP) policy","references":["https://learn.microsoft.com/en-us/windows-server/identity/software-restriction-policies/software-restriction-policies","https://github.com/nasbench/EVTX-ETW-Resources/blob/7a806a148b3d9d381193d4a80356016e6e8b1ee8/ETWEventsList/CSV/Windows11/22H2/W11_22H2_Pro_20220920_22621.382/Providers/Microsoft-Windows-AppXDeployment-Server.csv"],"logsource":{"product":"windows","service":"application"},"tags":["attack.lateral-movement","attack.execution","attack.t1072"],"path":"rules/windows/builtin/application/microsoft_windows_software_restriction_policies/win_software_restriction_policies_block.yml","techniques":["T1072"],"cves":[]},{"id":"d679950c-abb7-43a6-80fb-2a480c4fc450","title":"PDQ Deploy Remote Adminstartion Tool Execution","author":"frack113","status":"test","level":"medium","date":"2022-10-01","modified":"2023-01-30","description":"Detect use of PDQ Deploy remote admin tool","references":["https://github.com/redcanaryco/atomic-red-team/blob/9e5b12c4912c07562aec7500447b11fa3e17e254/atomics/T1072/T1072.md","https://www.pdq.com/pdq-deploy/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.lateral-movement","attack.t1072"],"path":"rules/windows/process_creation/proc_creation_win_pdqdeploy_execution.yml","techniques":["T1072"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}