T1105 Ingress Tool Transfer
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as [ftp](https://attack.mitre.org/software/S0095). Once present, adversaries may also transfer/spread tools between victim…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Greenbug Espionage Group Indicatorscriticaltest · windows
- Pandemic Registry Keycriticaltest · windows
- Curl Download And Execute Combinationhightest · windows
- File Download And Execution Via IEExec.EXEhightest · windows
- File Download From IP Based URL Via CertOC.EXEhightest · windows
- File Download Using Notepad++ GUP Utilityhightest · windows
- File Download Via Bitsadmin To A Suspicious Target Folderhightest · windows
- File Download Via Windows Defender MpCmpRun.EXEhightest · windows
- File Download with Headless Browserhightest · windows
- File With Suspicious Extension Downloaded Via Bitsadminhightest · windows
- Finger.EXE Executionhightest · windows
- Lolbas OneDriveStandaloneUpdater.exe Proxy Downloadhightest · windows
- Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folderhightest · windows
- Network Connection Initiated By IMEWDBLD.EXEhightest · windows
- Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Locationhightest · windows
- Outbound Network Connection Initiated By Script Interpreterhightest · windows
- PUA - Nimgrab Executionhightest · windows
- Password Protected ZIP File Opened (Suspicious Filenames)hightest · windows
- PrintBrm ZIP Creation of Extractionhightest · windows
- Suspicious Curl.EXE Downloadhightest · windows
- Suspicious Desktopimgdownldr Commandhightest · windows
- Suspicious Desktopimgdownldr Target Filehightest · windows
- Suspicious Download From File-Sharing Website Via Bitsadminhightest · windows
- Suspicious Download from Office Domainhightest · windows
- Suspicious Dropbox API Usagehightest · windows
Showing 25 of 40.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.