Tool

T1588.002

Sub-technique of T1588 Obtain Capabilities.View on attack.mitre.org

About this technique

Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A tool can be used for malicious purposes by an adversary, but (unlike malware) were not intended to be used for those purposes (ex: PsExec).

Adversaries may obtain tools to support their operations, including to support execution of post-compromise behaviors. Tools may also be leveraged for testing – for example, evaluating malware against commercial antivirus or endpoint detection and response (EDR) applications.

Tool acquisition may involve the procurement of commercial software licenses, including for red teaming tools such as Cobalt Strike. In addition to freely downloading or purchasing software, adversaries may steal software and/or software licenses from third-party entities (including other adversaries). Threat actors may also crack trial versions of software.

Detection rules13

Rules on DetectionCode tagged with T1588.002.

Sigma9

RuleLevelLog source
Hacktool Execution - Imphashcriticalwindows / process_creation
Hacktool Execution - PE Metadatahighwindows / process_creation
Renamed SysInternals DebugView Executionhighwindows / process_creation
Suspicious Execution Of Renamed Sysinternals Tools - Registryhighwindows / registry_set
Usage of Renamed Sysinternals Tools - RegistrySethighwindows / registry_set
PUA - Sysinternals Tools Execution - Registrymediumwindows / registry_set
Suspicious Keyboard Layout Loadmediumwindows / registry_set
Potential Execution of Sysinternals Toolslowwindows / process_creation
PUA - Sysinternal Tool Execution - Registrylowwindows / registry_set

Splunk4

RuleTypeRiskData source
Cisco Secure Firewall - Connection to File Sharing DomainAnomalyNULLCisco Secure Firewall Threat Defense Connection Event
Windows NirSoft AdvancedRunTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows NirSoft Tool Bundle File CreatedAnomalyNULLSysmon EventID 11
Windows NirSoft UtilitiesHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups82

Show 58 more

Software1

Campaigns26

Show 2 more

Procedure examples109

Groups82

Used byProcedure example
GroupAoqin Dragon

Aoqin Dragon obtained the Heyoka open source exfiltration tool and subsequently modified it for their operations.

GroupAPT-C-36

APT-C-36 utilizes tools well known in crime communities and has obtained and used a modified variant of Imminent Monitor.

GroupAPT1

APT1 has used various open-source tools for privilege escalation purposes.

GroupAPT19

APT19 has obtained and used publicly-available tools like Empire.

GroupAPT28

APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder.

GroupAPT29

APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike.

GroupAPT32

APT32 has obtained and used tools such as Mimikatz and Cobalt Strike, and a variety of other open-source tools from GitHub.

GroupAPT33

APT33 has obtained and leveraged publicly-available tools for early intrusion activities.

View all 82 groups examples

Software1

Used byProcedure example
MalwareLizar

FIN7 has obtained and used tools such as Impacket, Mimikatz, and PsExec.

Campaigns26

Used byProcedure example
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary obtained open-source penetration testing tools including network scanners, database exploitation frameworks, password crackers, and binary analysis suites.

CampaignC0010

For C0010, UNC3890 actors obtained multiple publicly-available tools, including METASPLOIT, UNICORN, and NorthStar C2.

CampaignC0015

For C0015, the threat actors obtained a variety of tools, including AdFind, AnyDesk, and Process Hacker.

CampaignC0017

For C0017, APT41 obtained publicly available tools such as YSoSerial.NET, ConfuserEx, and BadPotato.

CampaignC0018

For C0018, the threat actors acquired a variety of open source tools, including Mimikatz, Sliver, SoftPerfect Network Scanner, AnyDesk, and PDQ Deploy.

CampaignC0021

For C0021, the threat actors used Cobalt Strike configured with a modified variation of the publicly available Pandora Malleable C2 Profile.

CampaignC0027

During C0027, Scattered Spider obtained and used multiple tools including the LINpeas privilege escalation utility, aws_consoler, rsocx reverse proxy, Level RMM tool, and RustScan port scanner.

CampaignC0032

During the C0032 campaign, TEMP.Veles obtained and used tools such as Mimikatz and PsExec.

View all 26 campaigns examples

References3

  1. Forescout Conti Leaks 2022 Open source
    Vedere Labs. (2022, March 11). Analysis of Conti Leaks. Retrieved May 22, 2025.
  2. Recorded Future Beacon 2019 Open source
    Recorded Future. (2019, June 20). Out of the Blue: How Recorded Future Identified Rogue Cobalt Strike Servers. Retrieved September 16, 2024.
  3. Sentinel Labs Top Tier Target 2025 Open source
    Tom Hegel, Aleksandar Milenkoski & Jim Walter. (2025, April 28). Top Tier Target | What It Takes to Defend a Cybersecurity Company from Today’s Adversaries. Retrieved May 22, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.