Cross-source coverage

T1072 / ATT&CK

Software Deployment Tools

34 rules across 10 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager.

Access to network-wide or enterprise-wide endpoint management software may enable an adversary to achieve remote code execution on all connected systems. The access may be used to laterally move to other systems, gather information, or cause a specific effect, such as wiping the hard drives on all endpoints.

SaaS-based configuration management services may allow for broad Cloud Administration Command on cloud-hosted instances, as well as the execution of arbitrary commands on on-premises endpoints. For example, Microsoft Configuration Manager allows Global or Intune Administrators to run scripts as SYSTEM on on-premises devices joined to Entra ID. Such services may also utilize Web Protocols to communicate back to adversary owned infrastructure.

Network infrastructure devices may also have configuration management tools that can be similarly abused by adversaries.

The permissions required for this action vary by system configuration; local credentials may be sufficient with direct access to the third-party system, or specific domain credentials may be required. However, the system may require an administrative account to log in or to access specific functionality.

Platforms
Linux · macOS · Network Devices · SaaS · Windows
Telemetry
WinEventLog:SecurityWinEventLog:Applicationauditd:SYSCALLmacos:unifiedlogmacos:jamfAWS:CloudTrailnetworkdevice:syslogNSM:Flow

How MITRE says to detect it DET0223

Detection of Adversary Abuse of Software Deployment Tools

Windows Analytic 0623

Detects SCCM, Intune, or remote push execution spawning scripts or binaries from SYSTEM context or unusual consoles (e.g., cmtrace.exe launching PowerShell or cmd.exe).

  • WinEventLog:Security EventCode=4688
  • WinEventLog:Application SCCM, Intune logs

Linux Analytic 0624

Detects remote scripts or binaries deployed via Puppet, Chef, Ansible, or shell scripts from orchestration servers executing outside maintenance windows or in unmanaged nodes.

  • auditd:SYSCALL execve

macOS Analytic 0625

Detects script or binary execution initiated via JAMF, Munki, or custom MDM agents outside of baseline, or JAMF launching new Terminal or osascript processes from remote command payloads.

  • macos:unifiedlog process and signing chain events
  • macos:jamf RemoteCommandExecution

SaaS Analytic 0626

Detects cloud-native software deployment or management (e.g., SSM Run Command, Intune) initiating script execution on endpoints outside expected org IDs, admin groups, or maintenance windows.

  • AWS:CloudTrail SSM RunCommand

Network Devices Analytic 0627

Detects central router or switch config management tools (e.g., FortiManager, Cisco Prime) triggering device reboots or config pushes using abnormal accounts or IPs.

  • networkdevice:syslog config push events
  • NSM:Flow Device-to-Device Deployment Flows

panther-labs/panther-analysis

11 rules
Detection Severity Format
GitHub Malicious Pull Request Content High Panther Python
GitHub pull_request_target Workflow on Self-Hosted Runner High Panther Python
GitHub pull_request_target Workflow Usage High Panther Python
GitHub Artifact Download from Cross-Fork Workflow Medium Panther Python
GitHub Malicious Issue/Pages Content Medium Panther Python
GitHub pull_request_target Workflow with Checkout Action Medium Panther Python
Intune Create or Modify Client App Medium Panther Python
Intune New Device Management Script Medium Panther Python
GitHub Cross-Fork Workflow Run Informational Panther Python
GitHub Workflow Contains Checkout Action Informational Panther Python

+ 1 more from panther-labs/panther-analysis → showing the 10 highest-severity

splunk/security_content

5 rules
Detection Severity Format
Detection of tools built by NirSoft Undefined SPL
Microsoft Intune Device Health Scripts Undefined SPL
Microsoft Intune DeviceManagementConfigurationPolicies Undefined SPL
Microsoft Intune Manual Device Management Undefined SPL
Microsoft Intune Mobile Apps Undefined SPL

SigmaHQ/sigma

4 rules
Detection Severity Format
Restricted Software Access By SRP High Sigma
PDQ Deploy Remote Adminstartion Tool Execution Medium Sigma
PUA - Radmin Viewer Utility Execution Medium Sigma
Suspicious Csi.exe Usage Medium Sigma

elastic/detection-rules

4 rules
Detection Severity Format
Suspicious Curl to Jamf Endpoint High Elastic TOML
New GitHub App Installed Medium Elastic TOML
Potential WSUS Abuse for Lateral Movement Medium Elastic TOML
Tool Installation Detected via Defend for Containers Low Elastic TOML

Azure/Azure-Sentinel

2 rules
Detection Severity Format
New EXE deployed via Default Domain or Default Domain Controller Policies (ASIM Version) High KQL
SolarWinds Inventory (Normalized Process Events) Undefined KQL

Wazuh Core Ruleset

2 rules
Detection Severity Format
Palo Alto Traffic: Session dropped on from to . Reason: . Action: . · content_type = (?:drop|deny) Medium Wazuh XML
Windows Adware/Spyware application found. Medium Wazuh XML

falcosecurity/rules

2 rules
Detection Severity Format
Write below rpm database High Falco YAML
Update Package Repository Low Falco YAML

socfortress/Wazuh-Rules

2 rules
Detection Severity Format
Sysmon - Event 1: Process creation · PDQ Deploy Console Execution (T1072) High Wazuh XML
Sysmon - Event 1: Process creation · Radmin Viewer Execution (T1072) High Wazuh XML

Emerging Threats Open

1 rule
Detection Severity Format
ET HUNTING VibeCoded MSI Installer VBS Script Inbound Informational Suricata

chronicle/detection-rules

1 rule
Detection Severity Format
possible_bind_or_reverse_shell_via_netcat_auditbeat_for_linux Undefined YARA-L

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.