T1588.002 Tool
Sub-technique of T1588 Obtain Capabilities
Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A tool can be used for malicious purposes by an adversary, but (unlike malware) were not intended to be used for those purposes (ex: [PsExec](https://attack.mitre.org/software/S0029)). Adversaries may obtain tools to support their operations, including…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Hacktool Execution - Imphashcriticaltest · windows
- Hacktool Execution - PE Metadatahightest · windows
- Renamed SysInternals DebugView Executionhightest · windows
- Suspicious Execution Of Renamed Sysinternals Tools - Registryhightest · windows
- Usage of Renamed Sysinternals Tools - RegistrySethightest · windows
- PUA - Sysinternals Tools Execution - Registrymediumtest · windows
- Suspicious Keyboard Layout Loadmediumtest · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.