kevmap

Techniques › T1072

T1072 Software Deployment Tools

execution · lateral movement — Linux, macOS, Network Devices, SaaS, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
5
analytics
4
Sigma rules tagged attack.t1072
0
KEV CVEs mapped here
<p>Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager.</p><p>Access to network-wide or enterprise-wide endpoint management software may enable an adversary to achieve remote code execution on all connected systems. The access may be used to laterally move to other systems, gather information, or cause a specific effect, such as wiping the hard drives on all endpoints.</p><p>SaaS-based configuration management services may allow for broad Cloud Administration Command on cloud-hosted instances, as well as the execution of arbitrary commands on on-premises endpoints. For example, Microsoft Configuration Manager allows Global or Intune Administrators to run scripts as SYSTEM on on-premises devices joined to Entra ID. Such services may also utilize Web Protocols to communicate back to adversary owned infrastructure.</p><p>Network infrastructure devices may also have configuration management tools that can be similarly abused by adversaries.</p><p>The permissions required for this action vary by system configuration; local credentials may be sufficient with direct access to the third-party system, or specific domain credentials may be required. However, the system may require an administrative account to log in or to access specific functionality.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1072

Author: Konstantin Grishchenko, oscd.community · 2020-10-17 (modified 2022-07-11) · logsource: product=windows category=process_creation · 40b95d31-1afc-469e-8d34-9a3a667d058e
Csi.exe is a signed binary from Microsoft that comes with Visual Studio and provides C# interactive capabilities. It can be used to run C# code from a file passed as a parameter in command line. Early version of this utility provided with Microsoft “Roslyn” Community Technology Preview was named 'rcsi.exe'
Techniques: T1072T1218
Author: frack113 · 2022-01-22 (modified 2023-12-11) · logsource: product=windows category=process_creation · 5817e76f-4804-41e6-8f1d-5fa0b3ecae2d
Detects the execution of Radmin which can be abused by an adversary to remotely control Windows machines
Techniques: T1072
Author: frack113 · 2023-01-12 · logsource: product=windows service=application · b4c8da4a-1c12-46b0-8a2b-0a8521d03442
Detects restricted access to applications by the Software Restriction Policies (SRP) policy
Techniques: T1072
Author: frack113 · 2022-10-01 (modified 2023-01-30) · logsource: product=windows category=process_creation · d679950c-abb7-43a6-80fb-2a480c4fc450
Detect use of PDQ Deploy remote admin tool
Techniques: T1072