Sub-technique of T1588 Obtain Capabilities.View on attack.mitre.org
Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A tool can be used for malicious purposes by an adversary, but (unlike malware) were not intended to be used for those purposes (ex: PsExec).
Adversaries may obtain tools to support their operations, including to support execution of post-compromise behaviors. Tools may also be leveraged for testing – for example, evaluating malware against commercial antivirus or endpoint detection and response (EDR) applications.
Tool acquisition may involve the procurement of commercial software licenses, including for red teaming tools such as Cobalt Strike. In addition to freely downloading or purchasing software, adversaries may steal software and/or software licenses from third-party entities (including other adversaries). Threat actors may also crack trial versions of software.
Rules on DetectionCode tagged with T1588.002.
| Rule | Level | Log source |
|---|---|---|
| Hacktool Execution - Imphash | critical | windows / process_creation |
| Hacktool Execution - PE Metadata | high | windows / process_creation |
| Renamed SysInternals DebugView Execution | high | windows / process_creation |
| Suspicious Execution Of Renamed Sysinternals Tools - Registry | high | windows / registry_set |
| Usage of Renamed Sysinternals Tools - RegistrySet | high | windows / registry_set |
| PUA - Sysinternals Tools Execution - Registry | medium | windows / registry_set |
| Suspicious Keyboard Layout Load | medium | windows / registry_set |
| Potential Execution of Sysinternals Tools | low | windows / process_creation |
| PUA - Sysinternal Tool Execution - Registry | low | windows / registry_set |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco Secure Firewall - Connection to File Sharing Domain | Anomaly | NULL | Cisco Secure Firewall Threat Defense Connection Event |
| Windows NirSoft AdvancedRun | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows NirSoft Tool Bundle File Created | Anomaly | NULL | Sysmon EventID 11 |
| Windows NirSoft Utilities | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAoqin Dragon | Aoqin Dragon obtained the Heyoka open source exfiltration tool and subsequently modified it for their operations. |
| GroupAPT-C-36 | APT-C-36 utilizes tools well known in crime communities and has obtained and used a modified variant of Imminent Monitor. |
| GroupAPT1 | APT1 has used various open-source tools for privilege escalation purposes. |
| GroupAPT19 | APT19 has obtained and used publicly-available tools like Empire. |
| GroupAPT28 | APT28 has obtained and used open-source tools like Koadic, Mimikatz, and Responder. |
| GroupAPT29 | APT29 has obtained and used a variety of tools including Mimikatz, SDelete, Tor, meek, and Cobalt Strike. |
| GroupAPT32 | APT32 has obtained and used tools such as Mimikatz and Cobalt Strike, and a variety of other open-source tools from GitHub. |
| GroupAPT33 | APT33 has obtained and leveraged publicly-available tools for early intrusion activities. |
| Used by | Procedure example |
|---|---|
| MalwareLizar | FIN7 has obtained and used tools such as Impacket, Mimikatz, and PsExec. |
| Used by | Procedure example |
|---|---|
| CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary obtained open-source penetration testing tools including network scanners, database exploitation frameworks, password crackers, and binary analysis suites. |
| CampaignC0010 | For C0010, UNC3890 actors obtained multiple publicly-available tools, including METASPLOIT, UNICORN, and NorthStar C2. |
| CampaignC0015 | For C0015, the threat actors obtained a variety of tools, including AdFind, AnyDesk, and Process Hacker. |
| CampaignC0017 | For C0017, APT41 obtained publicly available tools such as YSoSerial.NET, ConfuserEx, and BadPotato. |
| CampaignC0018 | For C0018, the threat actors acquired a variety of open source tools, including Mimikatz, Sliver, SoftPerfect Network Scanner, AnyDesk, and PDQ Deploy. |
| CampaignC0021 | For C0021, the threat actors used Cobalt Strike configured with a modified variation of the publicly available Pandora Malleable C2 Profile. |
| CampaignC0027 | During C0027, Scattered Spider obtained and used multiple tools including the LINpeas privilege escalation utility, aws_consoler, rsocx reverse proxy, Level RMM tool, and RustScan port scanner. |
| CampaignC0032 | During the C0032 campaign, TEMP.Veles obtained and used tools such as Mimikatz and PsExec. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.