Cross-source coverage

T1587.001 / ATT&CK

Develop Capabilities: Malware

16 rules across 4 sources.

From MITRE ATT&CK 19.2

Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media. Adversaries may develop malware to support their operations, creating a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.

During malware development, adversaries may intentionally include indicators aligned with other known actors in order to mislead attribution by defenders.

As with legitimate development efforts, different skill sets may be required for developing malware. The skills needed may be located in-house, or may need to be contracted out. Use of a contractor may be considered an extension of that adversary's malware development capabilities, provided the adversary plays a role in shaping requirements and maintains a degree of exclusivity to the malware.

Some aspects of malware development, such as C2 protocol development, may require adversaries to obtain additional infrastructure. For example, malware developed that will communicate with Twitter for C2, may require use of Web Services.

Platforms
PRE
Telemetry
Malware Repository

How MITRE says to detect it DET0872

Detection of Malware

PRE Analytic 2004

Consider analyzing malware for features that may be associated with the adversary and/or their developers, such as compiler used, debugging artifacts, or code similarities. Malware repositories can also be used to identify additional samples associated with the adversary and identify development patterns over time. Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle.

  • Malware Repository None
  • Malware Repository None

SigmaHQ/sigma

11 rules
Detection Severity Format
ProxyLogon MSExchange OabVirtualDirectory Critical Sigma
Conti Volume Shadow Listing High Sigma
Formbook Process Creation High Sigma
Mustang Panda Dropper High Sigma
Potential Privilege Escalation To LOCAL SYSTEM High Sigma
Potential PsExec Remote Execution High Sigma
PsExec/PAExec Escalation to LOCAL SYSTEM High Sigma
PUA - CsExec Execution High Sigma
Uncommon File Created In Office Startup Folder High Sigma
VHD Image Download Via Browser Medium Sigma

+ 1 more from SigmaHQ/sigma → showing the 10 highest-severity

Wazuh Core Ruleset

3 rules
Detection Severity Format
MS Graph message: Indicators that the system is infected with malware have been detected. Critical Wazuh XML
MS Graph message: Malware has been detected in the environment. This is a true positive alert. Critical Wazuh XML
MS Graph message: Indicators that the system is potentially infected with malware have been detected. Check the system for signs of infection. High Wazuh XML

elastic/detection-rules

1 rule
Detection Severity Format
GenAI Process Compiling or Generating Executables Medium Elastic TOML

splunk/security_content

1 rule
Detection Severity Format
Cisco Secure Firewall - Possibly Compromised Host Undefined SPL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.