kevmap

TechniquesT1584 › T1584.004

T1584.004 Server

resource development — PRE · attack.mitre.org · JSON

1
MITRE detection strategy
1
analytics
0
Sigma rules tagged attack.t1584.004
0
KEV CVEs mapped here
<p>Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, including for Command and Control. Instead of purchasing a Server or Virtual Private Server, adversaries may compromise third-party servers in support of operations.</p><p>Adversaries may also compromise web servers to support watering hole operations, as in Drive-by Compromise, or email servers to support Phishing operations.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1584.004

No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.

Rules tagged at the parent level (attack.t1584) 4

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Windows Update Error informationalstable
Author: frack113 · 2021-12-04 (modified 2023-09-07) · logsource: product=windows service=system · 13cfeb75-9e33-4d04-b0f7-ab8faaa95a59
Detects Windows update errors including installation failures and connection issues. Defenders should observe this in case critical update KBs aren't installed.
Techniques: T1584
Author: Ahmed Farouk · 2024-05-10 · logsource: category=proxy · 1ae64f96-72b6-48b3-ad3d-e71dff6c6398
Detects executables launched from external WebDAV shares using the WebDAV Explorer integration, commonly seen in initial access campaigns.
Techniques: T1584T1566
Author: Micah Babinski · 2023-08-21 · logsource: product=windows category=file_event · 4c55738d-72d8-490e-a2db-7969654e375f
Detects the creation of WebDAV temporary files with potentially suspicious extensions
Techniques: T1584T1566
Author: Florian Roth (Nextron Systems) · 2018-01-23 (modified 2021-11-27) · logsource: product=linux service=auditd · a39d7fa7-3fbd-4dc2-97e1-d87f546b1bbc
Detects program executions in suspicious non-program folders related to malware or hacking activity
Techniques: T1587T1584