Technique with 4 sub-techniques.View on attack.mitre.org
Adversaries may build capabilities that can be used during targeting. Rather than purchasing, freely downloading, or stealing capabilities, adversaries may develop their own capabilities in-house. This is the process of identifying development requirements and building solutions such as malware, exploits, and self-signed certificates. Adversaries may develop capabilities to support their operations throughout numerous phases of the adversary lifecycle.
As with legitimate development efforts, different skill sets may be required for developing capabilities. The skills needed may be located in-house, or may need to be contracted out. Use of a contractor may be considered an extension of that adversary's development capabilities, provided the adversary plays a role in shaping requirements and maintains a degree of exclusivity to the capability.
Rules on DetectionCode tagged with T1587 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| HackTool - PurpleSharp Execution | critical | windows / process_creation | T1587 |
| ProxyLogon MSExchange OabVirtualDirectory | critical | windows / NULL | T1587.001 |
| Linux HackTool Execution | high | linux / process_creation | T1587 |
| Potential Privilege Escalation To LOCAL SYSTEM | high | windows / process_creation | T1587.001 |
| Potential PsExec Remote Execution | high | windows / process_creation | T1587.001 |
| PsExec/PAExec Escalation to LOCAL SYSTEM | high | windows / process_creation | T1587.001 |
| PUA - CsExec Execution | high | windows / process_creation | T1587.001 |
| Uncommon File Created In Office Startup Folder | high | windows / file_event | T1587.001 |
| Program Executions in Suspicious Folders | medium | linux / NULL | T1587 |
| VHD Image Download Via Browser | medium | windows / file_event | T1587.001 |
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint | TTP | NULL | Cisco Secure Firewall Threat Defense Connection Event | T1587.002 |
| Cisco Secure Firewall - Possibly Compromised Host | Anomaly | NULL | Cisco Secure Firewall Threat Defense Intrusion Event | T1587.001 |
| Windows Certutil Root Certificate Addition | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1587.003 |
None recorded.
None recorded.
| Used by | Procedure example |
|---|---|
| GroupContagious Interview | Contagious Interview developed malicious NPM packages for delivery to or retrieval by victims. Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023Sentinel One Contagious Interview ClickFix September 2025Socket BeaverTail XORIndex HexEval Contagious Interview July 2025Socket Contagious Interview NPM April 2025Socket HexEval BeaverTail Contagious Interview June 2025Validin Contagious Interview North Korea ClickFix January 2025 |
| GroupKimsuky | Kimsuky created and used a mailing toolkit to use in spearphishing attacks. |
| GroupMoonstone Sleet | Moonstone Sleet developed malicious npm packages for delivery to or retrieval by victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.