T1588 Obtain Capabilities
Adversaries may buy and/or steal capabilities that can be used during targeting. Rather than developing their own capabilities in-house, adversaries may purchase, freely download, or steal them. Activities may include the acquisition of malware, software (including licenses), exploits, certificates, and information relating to vulnerabilities. Adversaries may obtain capabilities to support their…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Hacktool Execution - Imphashcriticaltest · windows
- Relevant ClamAV Messagehighstable · linux
- Antivirus - Relevant File Paths Alerts Signaturehightest · antivirus
- Hacktool Execution - PE Metadatahightest · windows
- Relevant Anti-Virus Signature Keywords In Application Loghightest · windows
- Renamed SysInternals DebugView Executionhightest · windows
- Suspicious Execution Of Renamed Sysinternals Tools - Registryhightest · windows
- Usage of Renamed Sysinternals Tools - RegistrySethightest · windows
- PUA - Sysinternals Tools Execution - Registrymediumtest · windows
- Suspicious Keyboard Layout Loadmediumtest · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.