{"id":"T1127.003","name":"JamPlus","url":"https://attack.mitre.org/techniques/T1127/003","tactics":["stealth","execution"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0585","stix_id":"x-mitre-detection-strategy--680956cb-d8c6-447c-99b4-82865fb89255","name":"Behavior-chain detection strategy for T1127.003 Trusted Developer Utilities Proxy Execution: JamPlus (Windows)","url":"https://attack.mitre.org/detectionstrategies/DET0585","analytics":[{"id":"AN1610","stix_id":"x-mitre-analytic--3a5eea3b-b447-47c5-832d-6ced137b1597","name":"Analytic 1610","description":"Abuse of JamPlus.exe to launch malicious payloads via crafted .jam files, resulting in abnormal process creation, command execution, or artifact generation outside of standard development workflows.","url":"https://attack.mitre.org/detectionstrategies/DET0585#AN1610","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Microsoft-Windows-CodeIntegrity/Operational","channel":"Unsigned or untrusted modules loaded during JamPlus.exe runtime","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"wineventlog-microsoft-windows-codeintegrity-operational"}],"mutable_elements":[{"field":"TimeWindow","description":"Correlation time window (e.g., 0–30 minutes) for JamPlus.exe execution, child processes, and file/network events."},{"field":"AllowedBuildHosts","description":"Known developer systems where JamPlus.exe usage is expected; alerts are raised if executed elsewhere."},{"field":"SuspiciousChildList","description":"Child processes considered anomalous (e.g., PowerShell, cmd, wscript) when spawned by JamPlus.exe."},{"field":"RarePathRegex","description":"Regex patterns for non-standard or user-writable paths where JamPlus.exe drops artifacts."}],"live":true,"detection_strategies":["DET0585"],"techniques":["T1127.003"]}],"live":true,"version":"1.0","techniques":["T1127.003"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}