Cross-source coverage
T1587 / ATT&CK
Develop Capabilities
262 rules · 141 families across 7 sources.
Showing deprecated and atomic-IOC rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may build capabilities that can be used during targeting. Rather than purchasing, freely downloading, or stealing capabilities, adversaries may develop their own capabilities in-house. This is the process of identifying development requirements and building solutions such as malware, exploits, and self-signed certificates. Adversaries may develop capabilities to support their operations throughout numerous phases of the adversary lifecycle.
As with legitimate development efforts, different skill sets may be required for developing capabilities. The skills needed may be located in-house, or may need to be contracted out. Use of a contractor may be considered an extension of that adversary's development capabilities, provided the adversary plays a role in shaping requirements and maintains a degree of exclusivity to the capability.
- Tactics
- Resource Development
- Platforms
- PRE
- Telemetry
-
Malware RepositoryInternet Scan
How MITRE says to detect it DET0853
Detection of Develop Capabilities
PRE Analytic 1985
Consider analyzing malware for features that may be associated with the adversary and/or their developers, such as compiler used, debugging artifacts, or code similarities. Malware repositories can also be used to identify additional samples associated with the adversary and identify development patterns over time. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control. Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control. Consider use of services that may aid in the tracking of capabilities, such as certificates, in use on sites across the Internet. In some cases it may be possible to pivot on known pieces of information to uncover other adversary infrastructure. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control.
Malware RepositoryNoneMalware RepositoryNoneInternet ScanNone
Sub-techniques with coverage
Counted in the 262 above — a rule tagged a sub-technique covers this technique too.
Emerging Threats Open
231 rules · 111 families+ 221 more from Emerging Threats Open → showing the 10 highest-severity
SigmaHQ/sigma
17 rules| Detection | Severity | Format |
|---|---|---|
| CVE-2021-1675 Print Spooler Exploitation Filename Pattern | Critical | Sigma |
| FoggyWeb Backdoor DLL Loading | Critical | Sigma |
| HackTool - PurpleSharp Execution | Critical | Sigma |
| ProxyLogon MSExchange OabVirtualDirectory | Critical | Sigma |
| Conti Volume Shadow Listing | High | Sigma |
| Formbook Process Creation | High | Sigma |
| Linux HackTool Execution | High | Sigma |
| Mustang Panda Dropper | High | Sigma |
| Potential Privilege Escalation To LOCAL SYSTEM | High | Sigma |
| Potential PsExec Remote Execution | High | Sigma |
+ 7 more from SigmaHQ/sigma → showing the 10 highest-severity
Wazuh Core Ruleset
7 rulessplunk/security_content
3 rules| Detection | Severity | Format |
|---|---|---|
| Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint | Undefined | SPL |
| Cisco Secure Firewall - Possibly Compromised Host | Undefined | SPL |
| Windows Certutil Root Certificate Addition | Undefined | SPL |
socfortress/Wazuh-Rules
2 rules · 1 family| Detection | Severity | Format |
|---|---|---|
| Detects program executions in suspicious non-program folders related to malware or hacking activity. 2 variants | High | Wazuh XML |
| Detects program executions in suspicious non-program folders related to malware or hacking activity. 2 variants | High | Wazuh XML |
elastic/detection-rules
1 rule| Detection | Severity | Format |
|---|---|---|
| GenAI Process Compiling or Generating Executables | Medium | Elastic TOML |
panther-labs/panther-analysis
1 rule| Detection | Severity | Format |
|---|---|---|
| Proofpoint Active Threat Campaign Detected | High | Panther Python |