Cross-source coverage

T1587 / ATT&CK

Develop Capabilities

75 rules · 59 families across 7 sources.

79 deprecated hidden · include 43 atomic-IOC hidden · include

From MITRE ATT&CK 19.2

Adversaries may build capabilities that can be used during targeting. Rather than purchasing, freely downloading, or stealing capabilities, adversaries may develop their own capabilities in-house. This is the process of identifying development requirements and building solutions such as malware, exploits, and self-signed certificates. Adversaries may develop capabilities to support their operations throughout numerous phases of the adversary lifecycle.

As with legitimate development efforts, different skill sets may be required for developing capabilities. The skills needed may be located in-house, or may need to be contracted out. Use of a contractor may be considered an extension of that adversary's development capabilities, provided the adversary plays a role in shaping requirements and maintains a degree of exclusivity to the capability.

Platforms
PRE
Telemetry
Malware RepositoryInternet Scan

How MITRE says to detect it DET0853

Detection of Develop Capabilities

PRE Analytic 1985

Consider analyzing malware for features that may be associated with the adversary and/or their developers, such as compiler used, debugging artifacts, or code similarities. Malware repositories can also be used to identify additional samples associated with the adversary and identify development patterns over time. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control. Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control. Consider use of services that may aid in the tracking of capabilities, such as certificates, in use on sites across the Internet. In some cases it may be possible to pivot on known pieces of information to uncover other adversary infrastructure. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control.

  • Malware Repository None
  • Malware Repository None
  • Internet Scan None

Sub-techniques with coverage

Counted in the 75 above — a rule tagged a sub-technique covers this technique too.


Emerging Threats Open

44 rules · 29 families
Detection Severity Format
ET MALWARE [401TRG] Malicious SSL Cert (Dreambot CnC) 3 variants High Suricata
ET MALWARE [401TRG] Malicious SSL Cert (Dreambot CnC) 3 variants High Suricata
ET MALWARE [401TRG] Malicious SSL Cert (Dreambot CnC) 3 variants High Suricata
ET MALWARE Malicious SSL certificate detected (Possible Sinkhole) High Suricata
ET MALWARE Observed Malicious SSL Cert (ACBackdoor CnC) High Suricata
ET MALWARE Observed Malicious SSL Cert (APT32 CnC) High Suricata
ET MALWARE Observed Malicious SSL Cert (AsyncRAT CnC) High Suricata
ET MALWARE Observed Malicious SSL Cert (Baka Skimmer Staging CnC) 2 variants High Suricata
ET MALWARE Observed Malicious SSL Cert (Baka Skimmer Staging CnC) 2 variants High Suricata
ET MALWARE Observed Malicious SSL Cert (Blackrota) High Suricata

+ 34 more from Emerging Threats Open → showing the 10 highest-severity

SigmaHQ/sigma

17 rules
Detection Severity Format
CVE-2021-1675 Print Spooler Exploitation Filename Pattern Critical Sigma
FoggyWeb Backdoor DLL Loading Critical Sigma
HackTool - PurpleSharp Execution Critical Sigma
ProxyLogon MSExchange OabVirtualDirectory Critical Sigma
Conti Volume Shadow Listing High Sigma
Formbook Process Creation High Sigma
Linux HackTool Execution High Sigma
Mustang Panda Dropper High Sigma
Potential Privilege Escalation To LOCAL SYSTEM High Sigma
Potential PsExec Remote Execution High Sigma

+ 7 more from SigmaHQ/sigma → showing the 10 highest-severity

Wazuh Core Ruleset

7 rules
Detection Severity Format
MS Graph message: Indicators of vulnerability exploitation on the system have been detected. This alert is very likely to indicate an APT. Critical Wazuh XML
MS Graph message: Indicators of vulnerability exploitation on the system have been detected. This alert may be indicative of an APT. Critical Wazuh XML
MS Graph message: Indicators that the system is infected with malware have been detected. Critical Wazuh XML
MS Graph message: Malware has been detected in the environment. This is a true positive alert. Critical Wazuh XML
MS Graph message: Indicators of vulnerability exploitation on the system have been detected. However, this alert is unlikely to indciate an APT. Check the system for signs of infection. High Wazuh XML
MS Graph message: Indicators that the system is potentially infected with malware have been detected. Check the system for signs of infection. High Wazuh XML
MS Graph message: Indicators of potential vulnerability exploitation on the system have been detected. Check the system for signs of infection. Medium Wazuh XML

splunk/security_content

3 rules
Detection Severity Format
Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint Undefined SPL
Cisco Secure Firewall - Possibly Compromised Host Undefined SPL
Windows Certutil Root Certificate Addition Undefined SPL

socfortress/Wazuh-Rules

2 rules · 1 family
Detection Severity Format
Detects program executions in suspicious non-program folders related to malware or hacking activity. 2 variants High Wazuh XML
Detects program executions in suspicious non-program folders related to malware or hacking activity. 2 variants High Wazuh XML

elastic/detection-rules

1 rule
Detection Severity Format
GenAI Process Compiling or Generating Executables Medium Elastic TOML

panther-labs/panther-analysis

1 rule
Detection Severity Format
Proofpoint Active Threat Campaign Detected High Panther Python

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.