{"id":"T1587","name":"Develop Capabilities","url":"https://attack.mitre.org/techniques/T1587","tactics":["resource-development"],"platforms":["PRE"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0853","stix_id":"x-mitre-detection-strategy--7ad9b54d-cd23-4ec3-a5b2-db5e58e82a02","name":"Detection of Develop Capabilities","url":"https://attack.mitre.org/detectionstrategies/DET0853","analytics":[{"id":"AN1985","stix_id":"x-mitre-analytic--97b0c549-88d2-4739-a081-a9113e25cf1a","name":"Analytic 1985","description":"Consider analyzing malware for features that may be associated with the adversary and/or their developers, such as compiler used, debugging artifacts, or code similarities. Malware repositories can also be used to identify additional samples associated with the adversary and identify development patterns over time. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control.\nMonitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control.\nConsider use of services that may aid in the tracking of capabilities, such as certificates, in use on sites across the Internet. In some cases it may be possible to pivot on known pieces of information to uncover other adversary infrastructure.(Citation: Splunk Kovar Certificates 2017) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control.","url":"https://attack.mitre.org/detectionstrategies/DET0853#AN1985","platforms":["PRE"],"log_source_references":[{"name":"Malware Repository","channel":"None","data_component":"DC0011","data_component_name":"Malware Content","log_source_slug":"malware-repository"},{"name":"Malware Repository","channel":"None","data_component":"DC0003","data_component_name":"Malware Metadata","log_source_slug":"malware-repository"},{"name":"Internet Scan","channel":"None","data_component":"DC0104","data_component_name":"Response Content","log_source_slug":"internet-scan"}],"mutable_elements":[],"live":true,"detection_strategies":["DET0853"],"techniques":["T1587"]}],"live":true,"version":"1.0","techniques":["T1587"]}],"sigma_rules":[{"id":"2131cfb3-8c12-45e8-8fa0-31f5924e9f07","title":"CVE-2021-1675 Print Spooler Exploitation Filename Pattern","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2021-06-29","modified":"2022-12-25","description":"Detects the default filename used in PoC code against print spooler vulnerability CVE-2021-1675","references":["https://web.archive.org/web/20210629055600/https://github.com/hhlxf/PrintNightmare/","https://web.archive.org/web/20210701042336/https://github.com/afwu/PrintNightmare","https://github.com/cube0x0/CVE-2021-1675"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.execution","attack.privilege-escalation","attack.resource-development","attack.t1587","cve.2021-1675","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Exploits/CVE-2021-1675/file_event_win_exploit_cve_2021_1675_printspooler.yml","techniques":["T1587"],"cves":["CVE-2021-1675"]},{"id":"60c0a111-787a-4e8a-9262-ee485f3ef9d5","title":"Suspicious Word Cab File Write CVE-2021-40444","author":"Florian Roth (Nextron Systems), Sittikorn S","status":"test","level":"high","date":"2021-09-10","modified":"2023-06-22","description":"Detects file creation patterns noticeable during the exploitation of CVE-2021-40444","references":["https://twitter.com/RonnyTNL/status/1436334640617373699?s=20","https://twitter.com/vanitasnk/status/1437329511142420483?s=21"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.resource-development","attack.t1587","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Exploits/CVE-2021-40444/file_event_win_exploit_cve_2021_40444.yml","techniques":["T1587"],"cves":[]},{"id":"640dc51c-7713-4faa-8a0e-e7c0d9d4654c","title":"FoggyWeb Backdoor DLL Loading","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2021-09-27","modified":"2022-12-09","description":"Detects DLL hijacking technique used by NOBELIUM in their FoggyWeb backdoor. Which loads a malicious version of the expected \"version.dll\" dll","references":["https://www.microsoft.com/security/blog/2021/09/27/foggyweb-targeted-nobelium-malware-leads-to-persistent-backdoor/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.resource-development","attack.t1587","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Malware/FoggyWeb/image_load_malware_foggyweb_nobelium.yml","techniques":["T1587"],"cves":[]},{"id":"a015e032-146d-4717-8944-7a1884122111","title":"Linux HackTool Execution","author":"Nasreddine Bencherchali (Nextron Systems), Georg Lauenstein (sure[secure])","status":"test","level":"high","date":"2023-01-03","modified":"2024-09-19","description":"Detects known hacktool execution based on image name.","references":["https://github.com/Gui774ume/ebpfkit","https://github.com/pathtofile/bad-bpf","https://github.com/carlospolop/PEASS-ng","https://github.com/t3l3machus/hoaxshell","https://github.com/t3l3machus/Villain","https://github.com/HavocFramework/Havoc","https://github.com/1N3/Sn1per","https://github.com/Ne0nd0g/merlin","https://github.com/Pennyw0rth/NetExec/"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.execution","attack.resource-development","attack.t1587"],"path":"rules/linux/process_creation/proc_creation_lnx_susp_hktl_execution.yml","techniques":["T1587"],"cves":[]},{"id":"a39d7fa7-3fbd-4dc2-97e1-d87f546b1bbc","title":"Program Executions in Suspicious Folders","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2018-01-23","modified":"2021-11-27","description":"Detects program executions in suspicious non-program folders related to malware or hacking activity","references":["Internal Research"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.t1587","attack.t1584","attack.resource-development"],"path":"rules/linux/auditd/syscall/lnx_auditd_susp_exe_folders.yml","techniques":["T1587","T1584"],"cves":[]},{"id":"ff23ffbc-3378-435e-992f-0624dcf93ab4","title":"HackTool - PurpleSharp Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2021-06-18","modified":"2023-02-05","description":"Detects the execution of the PurpleSharp adversary simulation tool","references":["https://github.com/mvelazc0/PurpleSharp"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.t1587","attack.resource-development"],"path":"rules/windows/process_creation/proc_creation_win_hktl_purplesharp_indicators.yml","techniques":["T1587"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}