Techniques › T1072
T1072 Software Deployment Tools
execution · lateral movement — Linux, macOS, Network Devices, SaaS, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
5
analytics
4
Sigma rules tagged attack.t1072
0
KEV CVEs mapped here
<p>Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager.</p><p>Access to network-wide or enterprise-wide endpoint management software may enable an adversary to achieve remote code execution on all connected systems. The access may be used to laterally move to other systems, gather information, or cause a specific effect, such as wiping the hard drives on all endpoints.</p><p>SaaS-based configuration management services may allow for broad Cloud Administration Command on cloud-hosted instances, as well as the execution of arbitrary commands on on-premises endpoints. For example, Microsoft Configuration Manager allows Global or Intune Administrators to run scripts as SYSTEM on on-premises devices joined to Entra ID. Such services may also utilize Web Protocols to communicate back to adversary owned infrastructure.</p><p>Network infrastructure devices may also have configuration management tools that can be similarly abused by adversaries.</p><p>The permissions required for this action vary by system configuration; local credentials may be sufficient with direct access to the third-party system, or specific domain credentials may be required. However, the system may require an administrative account to log in or to access specific functionality.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0223 Detection of Adversary Abuse of Software Deployment Tools v1.0
AN0623 WindowsDetects SCCM, Intune, or remote push execution spawning scripts or binaries from SYSTEM context or unusual consoles (e.g., cmtrace.exe launching PowerShell or cmd.exe).Tunable:
ParentImageListUserContextTimeWindowAN0624 LinuxDetects remote scripts or binaries deployed via Puppet, Chef, Ansible, or shell scripts from orchestration servers executing outside maintenance windows or in unmanaged nodes.Tunable:DeployingHostAllowListScriptExecutionBaselineAN0625 macOSDetects script or binary execution initiated via JAMF, Munki, or custom MDM agents outside of baseline, or JAMF launching new Terminal or osascript processes from remote command payloads.Tunable:SigningAuthorityListRemoteCommandIntervalAN0626 SaaSDetects cloud-native software deployment or management (e.g., SSM Run Command, Intune) initiating script execution on endpoints outside expected org IDs, admin groups, or maintenance windows.Tunable:IAMRoleAllowListExecutionTargetListAN0627 Network DevicesDetects central router or switch config management tools (e.g., FortiManager, Cisco Prime) triggering device reboots or config pushes using abnormal accounts or IPs.Tunable:PushSourceAllowListAuthUserPattern
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1072
Author: Konstantin Grishchenko, oscd.community
· 2020-10-17 (modified 2022-07-11) · logsource: product=windows category=process_creation · 40b95d31-1afc-469e-8d34-9a3a667d058e
Csi.exe is a signed binary from Microsoft that comes with Visual Studio and provides C# interactive capabilities. It can be used to run C# code from a file passed as a parameter in command line. Early version of this utility provided with Microsoft “Roslyn” Community Technology Preview was named 'rcsi.exe'
Author: frack113
· 2022-01-22 (modified 2023-12-11) · logsource: product=windows category=process_creation · 5817e76f-4804-41e6-8f1d-5fa0b3ecae2d
Detects the execution of Radmin which can be abused by an adversary to remotely control Windows machines
Author: frack113
· 2023-01-12 · logsource: product=windows service=application · b4c8da4a-1c12-46b0-8a2b-0a8521d03442
Detects restricted access to applications by the Software Restriction Policies (SRP) policy
Author: frack113
· 2022-10-01 (modified 2023-01-30) · logsource: product=windows category=process_creation · d679950c-abb7-43a6-80fb-2a480c4fc450
Detect use of PDQ Deploy remote admin tool