Cross-source coverage
T1072 / ATT&CK
Software Deployment Tools
33 rules across 9 sources.
1 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager.
Access to network-wide or enterprise-wide endpoint management software may enable an adversary to achieve remote code execution on all connected systems. The access may be used to laterally move to other systems, gather information, or cause a specific effect, such as wiping the hard drives on all endpoints.
SaaS-based configuration management services may allow for broad Cloud Administration Command on cloud-hosted instances, as well as the execution of arbitrary commands on on-premises endpoints. For example, Microsoft Configuration Manager allows Global or Intune Administrators to run scripts as SYSTEM on on-premises devices joined to Entra ID. Such services may also utilize Web Protocols to communicate back to adversary owned infrastructure.
Network infrastructure devices may also have configuration management tools that can be similarly abused by adversaries.
The permissions required for this action vary by system configuration; local credentials may be sufficient with direct access to the third-party system, or specific domain credentials may be required. However, the system may require an administrative account to log in or to access specific functionality.
- Tactics
- Execution · Lateral Movement
- Platforms
- Linux · macOS · Network Devices · SaaS · Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:Applicationauditd:SYSCALLmacos:unifiedlogmacos:jamfAWS:CloudTrailnetworkdevice:syslogNSM:Flow
How MITRE says to detect it DET0223
Detection of Adversary Abuse of Software Deployment Tools
Windows Analytic 0623
Detects SCCM, Intune, or remote push execution spawning scripts or binaries from SYSTEM context or unusual consoles (e.g., cmtrace.exe launching PowerShell or cmd.exe).
WinEventLog:SecurityEventCode=4688WinEventLog:ApplicationSCCM, Intune logs
Linux Analytic 0624
Detects remote scripts or binaries deployed via Puppet, Chef, Ansible, or shell scripts from orchestration servers executing outside maintenance windows or in unmanaged nodes.
auditd:SYSCALLexecve
macOS Analytic 0625
Detects script or binary execution initiated via JAMF, Munki, or custom MDM agents outside of baseline, or JAMF launching new Terminal or osascript processes from remote command payloads.
macos:unifiedlogprocess and signing chain eventsmacos:jamfRemoteCommandExecution
SaaS Analytic 0626
Detects cloud-native software deployment or management (e.g., SSM Run Command, Intune) initiating script execution on endpoints outside expected org IDs, admin groups, or maintenance windows.
AWS:CloudTrailSSM RunCommand
Network Devices Analytic 0627
Detects central router or switch config management tools (e.g., FortiManager, Cisco Prime) triggering device reboots or config pushes using abnormal accounts or IPs.
networkdevice:syslogconfig push eventsNSM:FlowDevice-to-Device Deployment Flows
panther-labs/panther-analysis
11 rules| Detection | Severity | Format |
|---|---|---|
| GitHub Malicious Pull Request Content | High | Panther Python |
| GitHub pull_request_target Workflow on Self-Hosted Runner | High | Panther Python |
| GitHub pull_request_target Workflow Usage | High | Panther Python |
| GitHub Artifact Download from Cross-Fork Workflow | Medium | Panther Python |
| GitHub Malicious Issue/Pages Content | Medium | Panther Python |
| GitHub pull_request_target Workflow with Checkout Action | Medium | Panther Python |
| Intune Create or Modify Client App | Medium | Panther Python |
| Intune New Device Management Script | Medium | Panther Python |
| GitHub Cross-Fork Workflow Run | Informational | Panther Python |
| GitHub Workflow Contains Checkout Action | Informational | Panther Python |
+ 1 more from panther-labs/panther-analysis → showing the 10 highest-severity
splunk/security_content
5 rules| Detection | Severity | Format |
|---|---|---|
| Detection of tools built by NirSoft | Undefined | SPL |
| Microsoft Intune Device Health Scripts | Undefined | SPL |
| Microsoft Intune DeviceManagementConfigurationPolicies | Undefined | SPL |
| Microsoft Intune Manual Device Management | Undefined | SPL |
| Microsoft Intune Mobile Apps | Undefined | SPL |
SigmaHQ/sigma
4 rules| Detection | Severity | Format |
|---|---|---|
| Restricted Software Access By SRP | High | Sigma |
| PDQ Deploy Remote Adminstartion Tool Execution | Medium | Sigma |
| PUA - Radmin Viewer Utility Execution | Medium | Sigma |
| Suspicious Csi.exe Usage | Medium | Sigma |
elastic/detection-rules
4 rules| Detection | Severity | Format |
|---|---|---|
| Suspicious Curl to Jamf Endpoint | High | Elastic TOML |
| New GitHub App Installed | Medium | Elastic TOML |
| Potential WSUS Abuse for Lateral Movement | Medium | Elastic TOML |
| Tool Installation Detected via Defend for Containers | Low | Elastic TOML |
Azure/Azure-Sentinel
2 rules| Detection | Severity | Format |
|---|---|---|
| New EXE deployed via Default Domain or Default Domain Controller Policies (ASIM Version) | High | KQL |
| SolarWinds Inventory (Normalized Process Events) | Undefined | KQL |
Wazuh Core Ruleset
2 rules| Detection | Severity | Format |
|---|---|---|
| Palo Alto Traffic: Session dropped on from to . Reason: . Action: . · content_type = (?:drop|deny) | Medium | Wazuh XML |
| Windows Adware/Spyware application found. | Medium | Wazuh XML |
falcosecurity/rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Write below rpm database | High | Falco YAML |
| Update Package Repository | Low | Falco YAML |
socfortress/Wazuh-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Sysmon - Event 1: Process creation · PDQ Deploy Console Execution (T1072) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Radmin Viewer Execution (T1072) | High | Wazuh XML |
Emerging Threats Open
1 rule| Detection | Severity | Format |
|---|---|---|
| ET HUNTING VibeCoded MSI Installer VBS Script Inbound | Informational | Suricata |