MITRE ATT&CK technique
Develop Capabilities detection rulesT1587
Develop Capabilities (T1587) is a MITRE ATT&CK technique in the Resource Development tactic. This page lists the 17 community-maintained Sigma detection rules in the library mapped to T1587 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, linux.
Tactic
CVE-2021-1675 Print Spooler Exploitation Filename Pattern
criticalDetects the default filename used in PoC code against print spooler vulnerability CVE-2021-1675
windows · file_event
FoggyWeb Backdoor DLL Loading
criticalDetects DLL hijacking technique used by NOBELIUM in their FoggyWeb backdoor. Which loads a malicious version of the expected "version.dll" dll
windows · image_load
HackTool - PurpleSharp Execution
criticalDetects the execution of the PurpleSharp adversary simulation tool
windows · process_creation
ProxyLogon MSExchange OabVirtualDirectory
criticalDetects specific patterns found after a successful ProxyLogon exploitation in relation to a Commandlet invocation of Set-OabVirtualDirectory
windows
Conti Volume Shadow Listing
highDetects a command used by conti to find volume shadow backups
windows · process_creation
Formbook Process Creation
highDetects Formbook like process executions that inject code into a set of files in the System32 folder, which executes a special command command line to delete the dropper from the AppData Temp folder. We avoid false positives by excluding all parent process with command line parameters.
windows · process_creation
Linux HackTool Execution
highDetects known hacktool execution based on image name.
linux · process_creation
Mustang Panda Dropper
highDetects specific process parameters as used by Mustang Panda droppers
windows · process_creation
Potential Privilege Escalation To LOCAL SYSTEM
highDetects unknown program using commandline flags usually used by tools such as PsExec and PAExec to start programs with SYSTEM Privileges
windows · process_creation
Potential PsExec Remote Execution
highDetects potential psexec command that initiate execution on a remote systems via common commandline flags used by the utility
windows · process_creation
PsExec/PAExec Escalation to LOCAL SYSTEM
highDetects suspicious commandline flags used by PsExec and PAExec to escalate a command line to LOCAL_SYSTEM rights
windows · process_creation
PUA - CsExec Execution
highDetects the use of the lesser known remote execution tool named CsExec a PsExec alternative
windows · process_creation
Suspicious Word Cab File Write CVE-2021-40444
highDetects file creation patterns noticeable during the exploitation of CVE-2021-40444
windows · file_event
Uncommon File Created In Office Startup Folder
highDetects the creation of a file with an uncommon extension in an Office application startup folder
windows · file_event
Program Executions in Suspicious Folders
mediumDetects program executions in suspicious non-program folders related to malware or hacking activity
linux
VHD Image Download Via Browser
mediumDetects creation of ".vhd"/".vhdx" files by browser processes. Malware can use mountable Virtual Hard Disk ".vhd" files to encapsulate payloads and evade security controls.
windows · file_event
Creation of an Executable by an Executable
lowDetects the creation of an executable by another executable.
windows · file_event