T1587 Develop Capabilities
Adversaries may build capabilities that can be used during targeting. Rather than purchasing, freely downloading, or stealing capabilities, adversaries may develop their own capabilities in-house. This is the process of identifying development requirements and building solutions such as malware, exploits, and self-signed certificates. Adversaries may develop capabilities to support their…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- CVE-2021-1675 Print Spooler Exploitation Filename Patterncriticaltest · windows
- FoggyWeb Backdoor DLL Loadingcriticaltest · windows
- HackTool - PurpleSharp Executioncriticaltest · windows
- ProxyLogon MSExchange OabVirtualDirectorycriticaltest · windows
- Conti Volume Shadow Listinghightest · windows
- Formbook Process Creationhightest · windows
- Linux HackTool Executionhightest · linux
- Mustang Panda Dropperhightest · windows
- PUA - CsExec Executionhightest · windows
- Potential Privilege Escalation To LOCAL SYSTEMhightest · windows
- Potential PsExec Remote Executionhightest · windows
- PsExec/PAExec Escalation to LOCAL SYSTEMhightest · windows
- Suspicious Word Cab File Write CVE-2021-40444hightest · windows
- Uncommon File Created In Office Startup Folderhightest · windows
- Program Executions in Suspicious Foldersmediumtest · linux
- VHD Image Download Via Browsermediumtest · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.