Obtain Capabilities

T1588

Technique with 7 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may buy and/or steal capabilities that can be used during targeting. Rather than developing their own capabilities in-house, adversaries may purchase, freely download, or steal them. Activities may include the acquisition of malware, software (including licenses), exploits, certificates, and information relating to vulnerabilities. Adversaries may obtain capabilities to support their operations throughout numerous phases of the adversary lifecycle.

In addition to downloading free malware, software, and exploits from the internet, adversaries may purchase these capabilities from third-party entities. Third-party entities can include technology companies that specialize in malware and exploits, criminal marketplaces, or from individuals.

In addition to purchasing capabilities, adversaries may steal capabilities from third-party entities (including other adversaries). This can include stealing software licenses, malware, SSL/TLS and code-signing certificates, or raiding closed databases of vulnerabilities or exploits.

Detection rules17

Rules on DetectionCode tagged with T1588 or one of its sub-techniques.

Sigma12

Splunk5

RuleTypeRiskData sourceTechnique
Cisco Secure Firewall - Blacklisted SSL Certificate FingerprintTTPNULLCisco Secure Firewall Threat Defense Connection EventT1588.004
Cisco Secure Firewall - Connection to File Sharing DomainAnomalyNULLCisco Secure Firewall Threat Defense Connection EventT1588.002
Windows NirSoft AdvancedRunTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1588.002
Windows NirSoft Tool Bundle File CreatedAnomalyNULLSysmon EventID 11T1588.002
Windows NirSoft UtilitiesHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1588.002

Sub-techniques7

IDNameExamples
T1588.001Malware23
T1588.002Tool109
T1588.003Code Signing Certificates11
T1588.004Digital Certificates10
T1588.005Exploits2
T1588.006Vulnerabilities4
T1588.007Artificial Intelligence6

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples0

No procedure examples are recorded for this technique.

References3

  1. DiginotarCompromise Open source
    Fisher, D. (2012, October 31). Final Report on DigiNotar Hack Shows Total Compromise of CA Servers. Retrieved March 6, 2017.
  2. NationsBuying Open source
    Nicole Perlroth and David E. Sanger. (2013, July 12). Nations Buying as Hackers Sell Flaws in Computer Code. Retrieved March 9, 2017.
  3. PegasusCitizenLab Open source
    Bill Marczak and John Scott-Railton. (2016, August 24). The Million Dollar Dissident: NSO Group’s iPhone Zero-Days used against a UAE Human Rights Defender. Retrieved December 12, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.