{"id":"T1570","name":"Lateral Tool Transfer","url":"https://attack.mitre.org/techniques/T1570","tactics":["lateral-movement"],"platforms":["ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0183","stix_id":"x-mitre-detection-strategy--156ddd81-b3ae-4a79-8c4e-7a75b6fd994c","name":"Detection Strategy for Lateral Tool Transfer across OS platforms","url":"https://attack.mitre.org/detectionstrategies/DET0183","analytics":[{"id":"AN0516","stix_id":"x-mitre-analytic--ce0f284b-f8d9-4cb0-84ad-97e1e8390d0c","name":"Analytic 0516","description":"Correlate suspicious file transfers over SMB or Admin$ shares with process creation events (e.g., cmd.exe, powershell.exe, certutil.exe) that do not align with normal administrative behavior. Detect remote file writes followed by execution of transferred binaries.","url":"https://attack.mitre.org/detectionstrategies/DET0183#AN0516","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=5140","data_component":"DC0102","data_component_name":"Network Share Access","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Time period between file transfer and execution used to correlate events"},{"field":"UserContext","description":"Accounts allowed to perform legitimate administrative transfers"},{"field":"FilePathWhitelist","description":"Exclude known legitimate software update directories"}],"live":true,"detection_strategies":["DET0183"],"techniques":["T1570"]},{"id":"AN0517","stix_id":"x-mitre-analytic--24af9441-602e-4202-a2e7-04a46c008406","name":"Analytic 0517","description":"Monitor scp, rsync, curl, sftp, or ftp processes initiating transfers to internal systems combined with file creation events in unusual directories. Correlate transfer activity with subsequent execution of those binaries.","url":"https://attack.mitre.org/detectionstrategies/DET0183#AN0517","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Invocation of scp, rsync, curl, or sftp","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"auditd:FILE","channel":"create: New file created in system binaries or temp directories","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-file"}],"mutable_elements":[{"field":"AllowedTools","description":"Define legitimate transfer utilities expected in the environment"},{"field":"DestinationDirectories","description":"Restrict to suspicious or non-standard directories for transferred files"}],"live":true,"detection_strategies":["DET0183"],"techniques":["T1570"]},{"id":"AN0518","stix_id":"x-mitre-analytic--34d6af16-fe37-458c-b15c-413ff2d5b2f7","name":"Analytic 0518","description":"Detect anomalous use of scp, rsync, curl, or third-party sync apps transferring executables into user directories. Correlate new file creation with immediate execution events.","url":"https://attack.mitre.org/detectionstrategies/DET0183#AN0518","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of scp, rsync, curl with remote destination","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"File created in ~/Library/LaunchAgents or executable directories","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"SyncApplications","description":"Whitelisted apps like Dropbox or OneDrive if sanctioned"},{"field":"EntropyThreshold","description":"Adjust threshold for unusual filenames/hashes transferred internally"}],"live":true,"detection_strategies":["DET0183"],"techniques":["T1570"]},{"id":"AN0519","stix_id":"x-mitre-analytic--f8857048-181f-4883-a50b-65aca5204228","name":"Analytic 0519","description":"Identify lateral transfer via datastore file uploads or internal scp/ssh sessions that result in new VMX/VMDK or script files. Correlate transfer with VM execution or datastore modification.","url":"https://attack.mitre.org/detectionstrategies/DET0183#AN0519","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vmkernel","channel":"Upload of file to datastore","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"esxi-vmkernel"},{"name":"esxi:hostd","channel":"scp/ssh used to move file across hosts","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-hostd"}],"mutable_elements":[{"field":"DatastoreWhitelist","description":"Known authorized paths for legitimate VM operations"},{"field":"TransferProtocol","description":"Protocols allowed for intra-VM host transfers"}],"live":true,"detection_strategies":["DET0183"],"techniques":["T1570"]}],"live":true,"version":"1.0","techniques":["T1570"]}],"sigma_rules":[{"id":"2238d337-42fb-4971-9a68-63570f2aede4","title":"SMB over QUIC Via Net.EXE","author":"frack113","status":"test","level":"medium","date":"2023-07-21","modified":null,"description":"Detects the mounting of Windows SMB shares over QUIC, which can be an unexpected event in some enterprise environments.","references":["https://github.com/redcanaryco/atomic-red-team/blob/74438b0237d141ee9c99747976447dc884cb1a39/atomics/T1570/T1570.md","https://www.trustedsec.com/blog/making-smb-accessible-with-ntlmquic/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.t1570","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_net_quic.yml","techniques":["T1570"],"cves":[]},{"id":"304afd73-55a5-4bb9-8c21-0b1fc84ea9e4","title":"PSEXEC Remote Execution File Artefact","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-01-21","modified":"2023-02-23","description":"Detects creation of the PSEXEC key file. Which is created anytime a PsExec command is executed. It gets written to the file system and will be recorded in the USN Journal on the target system","references":["https://aboutdfir.com/the-key-to-identify-psexec/","https://twitter.com/davisrichardg/status/1616518800584704028"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.lateral-movement","attack.privilege-escalation","attack.execution","attack.persistence","attack.t1136.002","attack.t1543.003","attack.t1570","attack.s0029"],"path":"rules/windows/file/file_event/file_event_win_sysinternals_psexec_service_key.yml","techniques":["T1136.002","T1543.003","T1570"],"cves":[]},{"id":"5bb68627-3198-40ca-b458-49f973db8752","title":"Rundll32 Execution Without Parameters","author":"Bartlomiej Czyz, Relativity","status":"test","level":"high","date":"2021-01-31","modified":"2023-02-28","description":"Detects rundll32 execution without parameters as observed when running Metasploit windows/smb/psexec exploit module","references":["https://bczyz1.github.io/2021/01/30/psexec.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.t1021.002","attack.t1570","attack.execution","attack.t1569.002"],"path":"rules/windows/process_creation/proc_creation_win_rundll32_without_parameters.yml","techniques":["T1021.002","T1570","T1569.002"],"cves":[]},{"id":"6df07c3b-8456-4f8b-87bb-fe31ec964cae","title":"SMB over QUIC Via PowerShell Script","author":"frack113","status":"test","level":"medium","date":"2023-07-21","modified":null,"description":"Detects the mounting of Windows SMB shares over QUIC, which can be an unexpected event in some enterprise environments","references":["https://github.com/redcanaryco/atomic-red-team/blob/74438b0237d141ee9c99747976447dc884cb1a39/atomics/T1570/T1570.md","https://learn.microsoft.com/en-us/powershell/module/smbshare/new-smbmapping?view=windowsserver2022-ps","https://www.trustedsec.com/blog/making-smb-accessible-with-ntlmquic/"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.lateral-movement","attack.t1570","detection.threat-hunting"],"path":"rules-threat-hunting/windows/powershell/powershell_script/posh_ps_new_smbmapping_quic.yml","techniques":["T1570"],"cves":[]},{"id":"6fb63b40-e02a-403e-9ffd-3bcc1d749442","title":"Metasploit Or Impacket Service Installation Via SMB PsExec","author":"Bartlomiej Czyz, Relativity","status":"test","level":"high","date":"2021-01-21","modified":"2022-10-05","description":"Detects usage of Metasploit SMB PsExec (exploit/windows/smb/psexec) and Impacket psexec.py by triggering on specific service installation","references":["https://bczyz1.github.io/2021/01/30/psexec.html"],"logsource":{"product":"windows","service":"security"},"tags":["attack.lateral-movement","attack.t1021.002","attack.t1570","attack.execution","attack.t1569.002"],"path":"rules/windows/builtin/security/win_security_metasploit_or_impacket_smb_psexec_service_install.yml","techniques":["T1021.002","T1570","T1569.002"],"cves":[]},{"id":"9e4b7d3a-6f2c-4e9a-8d1b-3c5e7a9f2b4d","title":"Potentially Suspicious File Creation by OpenEDR's ITSMService","author":"@kostastsale","status":"experimental","level":"medium","date":"2026-02-19","modified":null,"description":"Detects the creation of potentially suspicious files by OpenEDR's ITSMService process.\nThe ITSMService is responsible for remote management operations and can create files on the system through the Process Explorer or file management features.\nWhile legitimate for IT operations, creation of executable or script files could indicate unauthorized file uploads, data staging, or malicious file deployment.\n","references":["https://kostas-ts.medium.com/detecting-abuse-of-openedrs-permissive-edr-trial-a-security-researcher-s-perspective-fc55bf53972c"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.command-and-control","attack.t1105","attack.lateral-movement","attack.t1570","attack.t1219"],"path":"rules/windows/file/file_event/file_event_win_comodo_itsm_potentially_suspicious_file_creation.yml","techniques":["T1105","T1570","T1219"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2024-4577","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}