kevmap

TechniquesT1584 › T1584.005

T1584.005 Botnet

resource development — PRE · attack.mitre.org · JSON

1
MITRE detection strategy
1
analytics
0
Sigma rules tagged attack.t1584.005
2
KEV CVEs mapped here
<p>Adversaries may compromise numerous third-party systems to form a botnet that can be used during targeting. A botnet is a network of compromised systems that can be instructed to perform coordinated tasks. Instead of purchasing/renting a botnet from a booter/stresser service, adversaries may build their own botnet by compromising numerous third-party systems. Adversaries may also conduct a takeover of an existing botnet, such as redirecting bots to adversary-controlled C2 servers. With a botnet at their disposal, adversaries may perform follow-on activity such as large-scale Phishing or Distributed Denial of Service (DDoS).</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2020-29557D-Link DIR-825 R1 Devices secondary impact Mapped2021-11-03
CVE-2020-25506D-Link DNS-320 Device secondary impact Mapped2021-11-03

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1584.005

No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content. 2 actively exploited CVEs map here.

Rules tagged at the parent level (attack.t1584) 4

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Windows Update Error informationalstable
Author: frack113 · 2021-12-04 (modified 2023-09-07) · logsource: product=windows service=system · 13cfeb75-9e33-4d04-b0f7-ab8faaa95a59
Detects Windows update errors including installation failures and connection issues. Defenders should observe this in case critical update KBs aren't installed.
Techniques: T1584
Author: Ahmed Farouk · 2024-05-10 · logsource: category=proxy · 1ae64f96-72b6-48b3-ad3d-e71dff6c6398
Detects executables launched from external WebDAV shares using the WebDAV Explorer integration, commonly seen in initial access campaigns.
Techniques: T1584T1566
Author: Micah Babinski · 2023-08-21 · logsource: product=windows category=file_event · 4c55738d-72d8-490e-a2db-7969654e375f
Detects the creation of WebDAV temporary files with potentially suspicious extensions
Techniques: T1584T1566
Author: Florian Roth (Nextron Systems) · 2018-01-23 (modified 2021-11-27) · logsource: product=linux service=auditd · a39d7fa7-3fbd-4dc2-97e1-d87f546b1bbc
Detects program executions in suspicious non-program folders related to malware or hacking activity
Techniques: T1587T1584