T1587.001 Malware
Sub-technique of T1587 Develop Capabilities
Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media. Adversaries may develop malware to support their operations, creating a means for maintaining…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- ProxyLogon MSExchange OabVirtualDirectorycriticaltest · windows
- Conti Volume Shadow Listinghightest · windows
- Formbook Process Creationhightest · windows
- Mustang Panda Dropperhightest · windows
- PUA - CsExec Executionhightest · windows
- Potential Privilege Escalation To LOCAL SYSTEMhightest · windows
- Potential PsExec Remote Executionhightest · windows
- PsExec/PAExec Escalation to LOCAL SYSTEMhightest · windows
- Uncommon File Created In Office Startup Folderhightest · windows
- VHD Image Download Via Browsermediumtest · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.