Techniques › T1587 › T1587.001
T1587.001 Malware
resource development — PRE · attack.mitre.org · JSON
1
MITRE detection strategy
1
analytics
11
Sigma rules tagged attack.t1587.001
0
KEV CVEs mapped here
<p>Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media. Adversaries may develop malware to support their operations, creating a means for maintaining control of remote machines, evading defenses, and executing post-compromise behaviors.</p><p>During malware development, adversaries may intentionally include indicators aligned with other known actors in order to mislead attribution by defenders.</p><p>As with legitimate development efforts, different skill sets may be required for developing malware. The skills needed may be located in-house, or may need to be contracted out. Use of a contractor may be considered an extension of that adversary's malware development capabilities, provided the adversary plays a role in shaping requirements and maintains a degree of exclusivity to the malware.</p><p>Some aspects of malware development, such as C2 protocol development, may require adversaries to obtain additional infrastructure. For example, malware developed that will communicate with Twitter for C2, may require use of Web Services.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0872 Detection of Malware v1.0
AN2004 PREConsider analyzing malware for features that may be associated with the adversary and/or their developers, such as compiler used, debugging artifacts, or code similarities. Malware repositories can also be used to identify additional samples associated with the adversary and identify development patterns over time. Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle.
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1587.001
Author: Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro
· 2019-09-30 (modified 2022-10-06) · logsource: product=windows category=process_creation · 032f5fb3-d959-41a5-9263-4173c802dc2b
Detects Formbook like process executions that inject code into a set of files in the System32 folder, which executes a special command command line to delete the dropper from the AppData Temp folder. We avoid false positives by excluding all parent process with command line parameters.
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
· 2021-05-22 (modified 2024-03-05) · logsource: product=windows category=process_creation · 207b0396-3689-42d9-8399-4222658efc99
Detects unknown program using commandline flags usually used by tools such as PsExec and PAExec to start programs with SYSTEM Privileges
Author: frack113
· 2022-03-09 (modified 2025-02-24) · logsource: product=windows category=file_event · 297afac9-5d02-4138-8c58-b977bac60556
Detects the creation of an executable by another executable.
Author: Florian Roth (Nextron Systems), oscd.community
· 2019-10-30 (modified 2021-11-27) · logsource: product=windows category=process_creation · 2d87d610-d760-45ee-a7e6-7a6f2a65de00
Detects specific process parameters as used by Mustang Panda droppers
Author: Florian Roth (Nextron Systems)
· 2021-08-09 (modified 2023-01-23) · logsource: product=windows service=msexchange-management · 550d3350-bb8a-4ff3-9533-2ba533f4a1c0
Detects specific patterns found after a successful ProxyLogon exploitation in relation to a Commandlet invocation of Set-OabVirtualDirectory
Author: Max Altgelt (Nextron Systems), Tobias Michalski (Nextron Systems)
· 2021-08-09 · logsource: product=windows category=process_creation · 7b30e0a7-c675-4b24-8a46-82fa67e2433d
Detects a command used by conti to find volume shadow backups
Author: frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io'
· 2021-10-25 (modified 2023-05-05) · logsource: product=windows category=file_event · 8468111a-ef07-4654-903b-b863a80bbc95
Detects creation of ".vhd"/".vhdx" files by browser processes.
Malware can use mountable Virtual Hard Disk ".vhd" files to encapsulate payloads and evade security controls.
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
· 2021-11-23 (modified 2024-03-05) · logsource: product=windows category=process_creation · 8834e2f7-6b4b-4f09-8906-d2276470ee23
Detects suspicious commandline flags used by PsExec and PAExec to escalate a command line to LOCAL_SYSTEM rights
Author: frack113, Nasreddine Bencherchali (Nextron Systems)
· 2022-06-05 (modified 2023-12-13) · logsource: product=windows category=file_event · a10a2c40-2c4d-49f8-b557-1a946bc55d9d
Detects the creation of a file with an uncommon extension in an Office application startup folder
Author: Florian Roth (Nextron Systems)
· 2022-08-22 (modified 2023-02-21) · logsource: product=windows category=process_creation · d08a2711-ee8b-4323-bdec-b7d85e892b31
Detects the use of the lesser known remote execution tool named CsExec a PsExec alternative
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
· 2023-02-28 (modified 2025-09-01) · logsource: product=windows category=process_creation · ea011323-7045-460b-b2d7-0f7442ea6b38
Detects potential psexec command that initiate execution on a remote systems via common commandline flags used by the utility
Rules tagged at the parent level (attack.t1587) 6
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Florian Roth (Nextron Systems)
· 2021-06-29 (modified 2022-12-25) · logsource: product=windows category=file_event · 2131cfb3-8c12-45e8-8fa0-31f5924e9f07
Detects the default filename used in PoC code against print spooler vulnerability CVE-2021-1675
Author: Florian Roth (Nextron Systems), Sittikorn S
· 2021-09-10 (modified 2023-06-22) · logsource: product=windows category=file_event · 60c0a111-787a-4e8a-9262-ee485f3ef9d5
Detects file creation patterns noticeable during the exploitation of CVE-2021-40444
Author: Florian Roth (Nextron Systems)
· 2021-09-27 (modified 2022-12-09) · logsource: product=windows category=image_load · 640dc51c-7713-4faa-8a0e-e7c0d9d4654c
Detects DLL hijacking technique used by NOBELIUM in their FoggyWeb backdoor. Which loads a malicious version of the expected "version.dll" dll
Author: Nasreddine Bencherchali (Nextron Systems), Georg Lauenstein (sure[secure])
· 2023-01-03 (modified 2024-09-19) · logsource: product=linux category=process_creation · a015e032-146d-4717-8944-7a1884122111
Detects known hacktool execution based on image name.
Author: Florian Roth (Nextron Systems)
· 2018-01-23 (modified 2021-11-27) · logsource: product=linux service=auditd · a39d7fa7-3fbd-4dc2-97e1-d87f546b1bbc
Detects program executions in suspicious non-program folders related to malware or hacking activity
Author: Florian Roth (Nextron Systems)
· 2021-06-18 (modified 2023-02-05) · logsource: product=windows category=process_creation · ff23ffbc-3378-435e-992f-0624dcf93ab4
Detects the execution of the PurpleSharp adversary simulation tool