Cross-source coverage
T1587.001 / ATT&CK
Develop Capabilities: Malware
16 rules across 4 sources.
From MITRE ATT&CK 19.2
Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media. Adversaries may develop malware to support their operations, creating a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.
During malware development, adversaries may intentionally include indicators aligned with other known actors in order to mislead attribution by defenders.
As with legitimate development efforts, different skill sets may be required for developing malware. The skills needed may be located in-house, or may need to be contracted out. Use of a contractor may be considered an extension of that adversary's malware development capabilities, provided the adversary plays a role in shaping requirements and maintains a degree of exclusivity to the malware.
Some aspects of malware development, such as C2 protocol development, may require adversaries to obtain additional infrastructure. For example, malware developed that will communicate with Twitter for C2, may require use of Web Services.
- Tactics
- Resource Development
- Platforms
- PRE
- Telemetry
-
Malware Repository
How MITRE says to detect it DET0872
Detection of Malware
PRE Analytic 2004
Consider analyzing malware for features that may be associated with the adversary and/or their developers, such as compiler used, debugging artifacts, or code similarities. Malware repositories can also be used to identify additional samples associated with the adversary and identify development patterns over time. Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle.
Malware RepositoryNoneMalware RepositoryNone
SigmaHQ/sigma
11 rules| Detection | Severity | Format |
|---|---|---|
| ProxyLogon MSExchange OabVirtualDirectory | Critical | Sigma |
| Conti Volume Shadow Listing | High | Sigma |
| Formbook Process Creation | High | Sigma |
| Mustang Panda Dropper | High | Sigma |
| Potential Privilege Escalation To LOCAL SYSTEM | High | Sigma |
| Potential PsExec Remote Execution | High | Sigma |
| PsExec/PAExec Escalation to LOCAL SYSTEM | High | Sigma |
| PUA - CsExec Execution | High | Sigma |
| Uncommon File Created In Office Startup Folder | High | Sigma |
| VHD Image Download Via Browser | Medium | Sigma |
+ 1 more from SigmaHQ/sigma → showing the 10 highest-severity
Wazuh Core Ruleset
3 ruleselastic/detection-rules
1 rule| Detection | Severity | Format |
|---|---|---|
| GenAI Process Compiling or Generating Executables | Medium | Elastic TOML |
splunk/security_content
1 rule| Detection | Severity | Format |
|---|---|---|
| Cisco Secure Firewall - Possibly Compromised Host | Undefined | SPL |