kevmap

Techniques › T1587

T1587 Develop Capabilities

resource development — PRE · attack.mitre.org · JSON

1
MITRE detection strategy
1
analytics
6
Sigma rules tagged attack.t1587
0
KEV CVEs mapped here
<p>Adversaries may build capabilities that can be used during targeting. Rather than purchasing, freely downloading, or stealing capabilities, adversaries may develop their own capabilities in-house. This is the process of identifying development requirements and building solutions such as malware, exploits, and self-signed certificates. Adversaries may develop capabilities to support their operations throughout numerous phases of the adversary lifecycle.</p><p>As with legitimate development efforts, different skill sets may be required for developing capabilities. The skills needed may be located in-house, or may need to be contracted out. Use of a contractor may be considered an extension of that adversary's development capabilities, provided the adversary plays a role in shaping requirements and maintains a degree of exclusivity to the capability.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1587

Author: Florian Roth (Nextron Systems) · 2021-06-29 (modified 2022-12-25) · logsource: product=windows category=file_event · 2131cfb3-8c12-45e8-8fa0-31f5924e9f07
Detects the default filename used in PoC code against print spooler vulnerability CVE-2021-1675
Techniques: T1587
CVE tags: CVE-2021-1675
Author: Florian Roth (Nextron Systems), Sittikorn S · 2021-09-10 (modified 2023-06-22) · logsource: product=windows category=file_event · 60c0a111-787a-4e8a-9262-ee485f3ef9d5
Detects file creation patterns noticeable during the exploitation of CVE-2021-40444
Techniques: T1587
Author: Florian Roth (Nextron Systems) · 2021-09-27 (modified 2022-12-09) · logsource: product=windows category=image_load · 640dc51c-7713-4faa-8a0e-e7c0d9d4654c
Detects DLL hijacking technique used by NOBELIUM in their FoggyWeb backdoor. Which loads a malicious version of the expected "version.dll" dll
Techniques: T1587
Author: Nasreddine Bencherchali (Nextron Systems), Georg Lauenstein (sure[secure]) · 2023-01-03 (modified 2024-09-19) · logsource: product=linux category=process_creation · a015e032-146d-4717-8944-7a1884122111
Detects known hacktool execution based on image name.
Techniques: T1587
Author: Florian Roth (Nextron Systems) · 2018-01-23 (modified 2021-11-27) · logsource: product=linux service=auditd · a39d7fa7-3fbd-4dc2-97e1-d87f546b1bbc
Detects program executions in suspicious non-program folders related to malware or hacking activity
Techniques: T1587T1584
Author: Florian Roth (Nextron Systems) · 2021-06-18 (modified 2023-02-05) · logsource: product=windows category=process_creation · ff23ffbc-3378-435e-992f-0624dcf93ab4
Detects the execution of the PurpleSharp adversary simulation tool
Techniques: T1587

Sub-techniques

IDNameSigma rulesKEV CVEs
T1587.001Malware110
T1587.002Code Signing Certificates00
T1587.003Digital Certificates00
T1587.004Exploits00