Cross-source coverage

T1587.004 / ATT&CK

Develop Capabilities: Exploits

4 rules across 1 source.

From MITRE ATT&CK 19.2

Adversaries may develop exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur on computer hardware or software. Rather than finding/modifying exploits from online or purchasing them from exploit vendors, an adversary may develop their own exploits. Adversaries may use information acquired via Vulnerabilities to focus exploit development efforts. As part of the exploit development process, adversaries may uncover exploitable vulnerabilities through methods such as fuzzing and patch analysis.

As with legitimate development efforts, different skill sets may be required for developing exploits. The skills needed may be located in-house, or may need to be contracted out. Use of a contractor may be considered an extension of that adversary's exploit development capabilities, provided the adversary plays a role in shaping requirements and maintains an initial degree of exclusivity to the exploit.

Adversaries may use exploits during various phases of the adversary lifecycle (i.e. Exploit Public-Facing Application, Exploitation for Client Execution, Exploitation for Privilege Escalation, Exploitation for Stealth, Exploitation for Credential Access, Exploitation of Remote Services, and Application or System Exploitation).

Platforms
PRE
Telemetry

How MITRE says to detect it DET0894

Detection of Exploits

PRE Analytic 2026

Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004)).


Wazuh Core Ruleset

4 rules
Detection Severity Format
MS Graph message: Indicators of vulnerability exploitation on the system have been detected. This alert is very likely to indicate an APT. Critical Wazuh XML
MS Graph message: Indicators of vulnerability exploitation on the system have been detected. This alert may be indicative of an APT. Critical Wazuh XML
MS Graph message: Indicators of vulnerability exploitation on the system have been detected. However, this alert is unlikely to indciate an APT. Check the system for signs of infection. High Wazuh XML
MS Graph message: Indicators of potential vulnerability exploitation on the system have been detected. Check the system for signs of infection. Medium Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.