{"id":"T1587.004","name":"Exploits","url":"https://attack.mitre.org/techniques/T1587/004","tactics":["resource-development"],"platforms":["PRE"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0894","stix_id":"x-mitre-detection-strategy--4b8278b5-5749-4a2d-94b1-5129e43a7455","name":"Detection of Exploits","url":"https://attack.mitre.org/detectionstrategies/DET0894","analytics":[{"id":"AN2026","stix_id":"x-mitre-analytic--1762aa55-010b-4a26-b439-7afcfcc5613d","name":"Analytic 2026","description":"Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)).","url":"https://attack.mitre.org/detectionstrategies/DET0894#AN2026","platforms":["PRE"],"log_source_references":[],"mutable_elements":[],"live":true,"detection_strategies":["DET0894"],"techniques":["T1587.004"]}],"live":true,"version":"1.0","techniques":["T1587.004"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}