Technique.View on attack.mitre.org
Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager.
Access to network-wide or enterprise-wide endpoint management software may enable an adversary to achieve remote code execution on all connected systems. The access may be used to laterally move to other systems, gather information, or cause a specific effect, such as wiping the hard drives on all endpoints.
SaaS-based configuration management services may allow for broad Cloud Administration Command on cloud-hosted instances, as well as the execution of arbitrary commands on on-premises endpoints. For example, Microsoft Configuration Manager allows Global or Intune Administrators to run scripts as SYSTEM on on-premises devices joined to Entra ID. Such services may also utilize Web Protocols to communicate back to adversary owned infrastructure.
Network infrastructure devices may also have configuration management tools that can be similarly abused by adversaries.
The permissions required for this action vary by system configuration; local credentials may be sufficient with direct access to the third-party system, or specific domain credentials may be required. However, the system may require an administrative account to log in or to access specific functionality.
Rules on DetectionCode tagged with T1072.
| Rule | Level | Log source |
|---|---|---|
| Restricted Software Access By SRP | high | windows / NULL |
| PDQ Deploy Remote Adminstartion Tool Execution | medium | windows / process_creation |
| PUA - Radmin Viewer Utility Execution | medium | windows / process_creation |
| Suspicious Csi.exe Usage | medium | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Detection of tools built by NirSoft | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Microsoft Intune Device Health Scripts | Hunting | NULL | Azure Monitor Activity |
| Microsoft Intune DeviceManagementConfigurationPolicies | Hunting | NULL | Azure Monitor Activity |
| Microsoft Intune Manual Device Management | Hunting | NULL | Azure Monitor Activity |
| Microsoft Intune Mobile Apps | Hunting | NULL | Azure Monitor Activity |
| Used by | Procedure example |
|---|---|
| GroupAPT32 | APT32 compromised McAfee ePO to move laterally by distributing malware as a software deployment task. |
| GroupMedusa Group | Medusa Group has utilized software deployment and management solutions to deploy their encryption payload to include BigFix and PDQ Deploy. |
| GroupMustang Panda | Mustang Panda has leveraged legitimate software tools such as AntiVirus Agents, Security Services, and App Development tools to execute scripts and to side-load dlls. |
| GroupSandworm Team | Sandworm Team has used the commercially available tool RemoteExec for agentless remote code execution. |
| GroupShinyHunters | ShinyHunters has abused software deployment tools for lateral movement. |
| GroupSilence | Silence has used RAdmin, a remote software tool used to remotely control workstations and ATMs. |
| GroupThreat Group-1314 | Threat Group-1314 actors used a victim's endpoint management platform, Altiris, for lateral movement. |
| GroupVOID MANTICORE | VOID MANTICORE has leveraged legitimate built-in features of cloud-based management platforms to include mobile device management (MDM) and Remote Monitoring and Management (RMM) solutions. VOID MANTICORE has also initiated built-in remote wipe instructions using a privileged account within Microsoft Intune. |
| Used by | Procedure example |
|---|---|
| MalwareWiper | It is believed that a patch management system for an anti-virus product commonly installed among targeted companies was used to distribute the Wiper malware. |
| Used by | Procedure example |
|---|---|
| CampaignC0018 | During C0018, the threat actors used PDQ Deploy to move AvosLocker and tools across the network. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.