T1588.001 Malware
Sub-technique of T1588 Obtain Capabilities
Adversaries may buy, steal, or download malware that can be used during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, packers, and C2 protocols. Adversaries may acquire malware to support their operations, obtaining a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors. In addition to…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Relevant ClamAV Messagehighstable · linux
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.