T1587.001 Malware
Subtécnica de T1587 Develop Capabilities
Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media. Adversaries may develop malware to support their operations, creating a means for maintaining…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- ProxyLogon MSExchange OabVirtualDirectorycriticaltest · windows
- Conti Volume Shadow Listinghightest · windows
- Formbook Process Creationhightest · windows
- Mustang Panda Dropperhightest · windows
- PUA - CsExec Executionhightest · windows
- Potential Privilege Escalation To LOCAL SYSTEMhightest · windows
- Potential PsExec Remote Executionhightest · windows
- PsExec/PAExec Escalation to LOCAL SYSTEMhightest · windows
- Uncommon File Created In Office Startup Folderhightest · windows
- VHD Image Download Via Browsermediumtest · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.