Technique.View on attack.mitre.org
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
On Windows, adversaries may use various utilities to download tools, such as `copy`, `finger`, certutil, and PowerShell commands such as IEX(New-Object Net.WebClient).downloadString() and Invoke-WebRequest. On Linux and macOS systems, a variety of utilities also exist, such as `curl`, `scp`, `sftp`, `tftp`, `rsync`, `finger`, and `wget`. A number of these tools, such as `wget`, `curl`, and `scp`, also exist on ESXi. After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via `certutil -hashfile`).
Adversaries may also abuse installers and package managers, such as `yum` or `winget`, to download tools to victim hosts. Adversaries have also abused file application features, such as the Windows `search-ms` protocol handler, to deliver malicious files to victims through remote file searches invoked by User Execution (typically after interacting with Phishing lures).
Files can also be transferred using various Web Services as well as native or otherwise present tools on the victim system. In some cases, adversaries may be able to leverage services that sync between a web-based and an on-premises client, such as Dropbox or OneDrive, to transfer files onto victim systems. For example, by compromising a cloud account and logging into the service's web portal, an adversary may be able to trigger an automatic syncing process that transfers the file onto the victim's machine.
Rules on DetectionCode tagged with T1105.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Any Powershell DownloadFile | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Any Powershell DownloadString | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| BITSAdmin Download File | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| CertUtil Download With URLCache and Split Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| CertUtil Download With VerifyCtl and Split Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Cisco Isovalent - Curl Execution With Insecure Flags | Anomaly | NULL | Cisco Isovalent Process Exec |
| Cisco NVM - Suspicious File Download via Headless Browser | TTP | NULL | Cisco Network Visibility Module Flow Data |
| Cisco NVM - Webserver Download From File Sharing Website | TTP | NULL | Cisco Network Visibility Module Flow Data |
| Cisco Secure Firewall - Communication Over Suspicious Ports | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Cisco Secure Firewall - Connection to File Sharing Domain | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Cisco Secure Firewall - File Download Over Uncommon Port | Anomaly | NULL | Cisco Secure Firewall Threat Defense File Event |
| Cisco Secure Firewall - High EVE Threat Confidence | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Cisco Secure Firewall - Malware File Downloaded | Anomaly | NULL | Cisco Secure Firewall Threat Defense File Event |
| Cisco Secure Firewall - Repeated Malware Downloads | Anomaly | NULL | Cisco Secure Firewall Threat Defense File Event |
| Cisco Secure Firewall - Snort Rule Triggered Across Multiple Hosts | Anomaly | NULL | Cisco Secure Firewall Threat Defense Intrusion Event |
| Cisco Secure Firewall - Wget or Curl Download | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Curl Download and Bash Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Curl Execution with Percent Encoded URL | Anomaly | NULL | CrowdStrike ProcessRollup2, Sysmon EventID 1, Sysmon for Linux EventID 1, Windows Event Log Security 4688 |
| Detect Certify Command Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Download Files Using Telegram | TTP | NULL | Sysmon EventID 15 |
| File Download or Read to Pipe Execution | TTP | NULL | Sysmon EventID 1, Sysmon for Linux EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Juniper Networks Remote Code Execution Exploit Detection | TTP | NULL | Suricata |
| Linux Curl Upload File | TTP | NULL | Sysmon for Linux EventID 1, Cisco Isovalent Process Exec |
| Linux Ingress Tool Transfer Hunting | Hunting | NULL | Sysmon for Linux EventID 1 |
| Linux Ingress Tool Transfer with Curl | Anomaly | NULL | Sysmon for Linux EventID 1 |
| Living Off The Land Detection | Correlation | NULL | |
| Log4Shell CVE-2021-44228 Exploitation | Correlation | NULL | |
| LOLBAS Network Connection On Uncommon Port | Anomaly | NULL | Sysmon EventID 3 |
| LOLBAS Rare Network Connection | Anomaly | NULL | Sysmon EventID 3 |
| LOLBAS With Network Traffic | TTP | NULL | Sysmon EventID 3 |
| Microsoft Intune Device Health Scripts | Hunting | NULL | Azure Monitor Activity |
| Microsoft Intune Mobile Apps | Hunting | NULL | Azure Monitor Activity |
| PowerShell Script Block With URL Chain | TTP | NULL | Powershell Script Block Logging 4104 |
| PowerShell WebRequest Using Memory Stream | TTP | NULL | Powershell Script Block Logging 4104 |
| Suspicious Curl Network Connection | TTP | NULL | Sysmon EventID 1, Sysmon for Linux EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Wget Download and Bash Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Cabinet File Extraction Via Expand | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows CertUtil Download With URL Argument | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Curl Download to Suspicious Path | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data |
| Windows Curl Upload to Remote Destination | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data |
| Windows DLL Module Loaded in Temp Dir | Hunting | NULL | Sysmon EventID 7 |
| Windows DNS Query Request To TinyUrl | Anomaly | NULL | Sysmon EventID 22 |
| Windows File Download Via CertUtil | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data |
| Windows File Download Via PowerShell | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data |
| Windows Ingress Tool Transfer Using Explorer | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Ldifde Directory Object Behavior | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Process Accessing IronLanguages Repository On GitHub | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Process Execution From RDP Share | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows SQL Spawning CertUtil | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows SSH Proxy Command | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Windows Suspicious Defender Update Activity in INetCache | Anomaly | NULL | Sysmon EventID 11, Sysmon EventID 23 |
| WinRAR Spawning Shell Application | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAjax Security Team | Ajax Security Team has used Wrapper/Gholee, custom-developed malware, which downloaded additional malware to the infected system. |
| GroupAndariel | Andariel has downloaded additional tools and malware onto compromised hosts. |
| GroupAPT-C-36 | APT-C-36 has downloaded binary data from a specified domain after the malicious document is opened. |
| GroupAPT18 | APT18 can upload a file to the victim’s machine. |
| GroupAPT28 | APT28 has downloaded additional files, including by using a first-stage downloader to contact the C2 server to obtain the second-stage implant. |
| GroupAPT29 | APT29 has downloaded additional tools and malware onto compromised networks. |
| GroupAPT3 | APT3 has a tool that can copy files to remote machines. |
| GroupAPT32 | APT32 has added JavaScript to victim websites to download additional frameworks that profile and compromise website visitors. |
| Used by | Procedure example |
|---|---|
| MalwareABK | ABK has the ability to download files from C2. |
| MalwareAction RAT | Action RAT has the ability to download additional payloads onto an infected machine. |
| MalwareAgent Tesla | Agent Tesla can download additional files for execution on the victim’s machine. |
| MalwareAgent.btz | Agent.btz attempts to download an encrypted binary from a specified domain. |
| MalwareAmadey | Amadey can download and execute files to further infect a host machine with additional malware. |
| MalwareAnchor | Anchor can download additional payloads. |
| MalwareANDROMEDA | ANDROMEDA can download additional payloads from C2. |
| MalwareAria-body | Aria-body has the ability to download additional payloads from C2. |
View all 403 software examples
| Used by | Procedure example |
|---|---|
| Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team pushed additional malicious tools onto an infected system to steal user credentials, move laterally, and destroy data. |
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries downloaded malicious payloads to the victim server. |
| CampaignAPT41 DUST | APT41 DUST involved execution of `certutil.exe` via web shell to download the DUSTPAN dropper. |
| CampaignC0010 | During C0010, UNC3890 actors downloaded tools and malware onto a compromised host. |
| CampaignC0015 | During C0015, the threat actors downloaded additional tools and files onto a compromised network. |
| CampaignC0017 | During C0017, APT41 downloaded malicious payloads onto compromised systems. |
| CampaignC0018 | During C0018, the threat actors downloaded additional tools, such as Mimikatz and Sliver, as well as Cobalt Strike and AvosLocker ransomware onto the victim network. |
| CampaignC0021 | During C0021, the threat actors downloaded additional tools and files onto victim machines. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.