Develop Capabilities

T1587

Technique with 4 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may build capabilities that can be used during targeting. Rather than purchasing, freely downloading, or stealing capabilities, adversaries may develop their own capabilities in-house. This is the process of identifying development requirements and building solutions such as malware, exploits, and self-signed certificates. Adversaries may develop capabilities to support their operations throughout numerous phases of the adversary lifecycle.

As with legitimate development efforts, different skill sets may be required for developing capabilities. The skills needed may be located in-house, or may need to be contracted out. Use of a contractor may be considered an extension of that adversary's development capabilities, provided the adversary plays a role in shaping requirements and maintains a degree of exclusivity to the capability.

Detection rules13

Rules on DetectionCode tagged with T1587 or one of its sub-techniques.

Sigma10

RuleLevelLog sourceTechnique
HackTool - PurpleSharp Executioncriticalwindows / process_creationT1587
ProxyLogon MSExchange OabVirtualDirectorycriticalwindows / NULLT1587.001
Linux HackTool Executionhighlinux / process_creationT1587
Potential Privilege Escalation To LOCAL SYSTEMhighwindows / process_creationT1587.001
Potential PsExec Remote Executionhighwindows / process_creationT1587.001
PsExec/PAExec Escalation to LOCAL SYSTEMhighwindows / process_creationT1587.001
PUA - CsExec Executionhighwindows / process_creationT1587.001
Uncommon File Created In Office Startup Folderhighwindows / file_eventT1587.001
Program Executions in Suspicious Foldersmediumlinux / NULLT1587
VHD Image Download Via Browsermediumwindows / file_eventT1587.001

Splunk3

RuleTypeRiskData sourceTechnique
Cisco Secure Firewall - Blacklisted SSL Certificate FingerprintTTPNULLCisco Secure Firewall Threat Defense Connection EventT1587.002
Cisco Secure Firewall - Possibly Compromised HostAnomalyNULLCisco Secure Firewall Threat Defense Intrusion EventT1587.001
Windows Certutil Root Certificate AdditionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1587.003

Sub-techniques4

IDNameExamples
T1587.001Malware42
T1587.002Code Signing Certificates4
T1587.003Digital Certificates7
T1587.004Exploits5

Groups3

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

Groups3

References4

  1. Bitdefender StrongPity June 2020 Open source
    Tudorica, R. et al. (2020, June 30). StrongPity APT - Revealing Trojanized Tools, Working Hours and Infrastructure. Retrieved July 20, 2020.
  2. Kaspersky Sofacy Open source
    Kaspersky Lab's Global Research and Analysis Team. (2015, December 4). Sofacy APT hits high profile targets with updated toolset. Retrieved December 10, 2015.
  3. Mandiant APT1 Open source
    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.
  4. Talos Promethium June 2020 Open source
    Mercer, W. et al. (2020, June 29). PROMETHIUM extends global reach with StrongPity3 APT. Retrieved July 20, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.