kevmap

TechniquesT1587 › T1587.004

T1587.004 Exploits

resource development — PRE · attack.mitre.org · JSON

1
MITRE detection strategy
1
analytics
0
Sigma rules tagged attack.t1587.004
0
KEV CVEs mapped here
<p>Adversaries may develop exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur on computer hardware or software. Rather than finding/modifying exploits from online or purchasing them from exploit vendors, an adversary may develop their own exploits. Adversaries may use information acquired via Vulnerabilities to focus exploit development efforts. As part of the exploit development process, adversaries may uncover exploitable vulnerabilities through methods such as fuzzing and patch analysis.</p><p>As with legitimate development efforts, different skill sets may be required for developing exploits. The skills needed may be located in-house, or may need to be contracted out. Use of a contractor may be considered an extension of that adversary's exploit development capabilities, provided the adversary plays a role in shaping requirements and maintains an initial degree of exclusivity to the exploit.</p><p>Adversaries may use exploits during various phases of the adversary lifecycle (i.e. Exploit Public-Facing Application, Exploitation for Client Execution, Exploitation for Privilege Escalation, Exploitation for Stealth, Exploitation for Credential Access, Exploitation of Remote Services, and Application or System Exploitation).</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1587.004

No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.

Rules tagged at the parent level (attack.t1587) 6

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Florian Roth (Nextron Systems) · 2021-06-29 (modified 2022-12-25) · logsource: product=windows category=file_event · 2131cfb3-8c12-45e8-8fa0-31f5924e9f07
Detects the default filename used in PoC code against print spooler vulnerability CVE-2021-1675
Techniques: T1587
CVE tags: CVE-2021-1675
Author: Florian Roth (Nextron Systems), Sittikorn S · 2021-09-10 (modified 2023-06-22) · logsource: product=windows category=file_event · 60c0a111-787a-4e8a-9262-ee485f3ef9d5
Detects file creation patterns noticeable during the exploitation of CVE-2021-40444
Techniques: T1587
Author: Florian Roth (Nextron Systems) · 2021-09-27 (modified 2022-12-09) · logsource: product=windows category=image_load · 640dc51c-7713-4faa-8a0e-e7c0d9d4654c
Detects DLL hijacking technique used by NOBELIUM in their FoggyWeb backdoor. Which loads a malicious version of the expected "version.dll" dll
Techniques: T1587
Author: Nasreddine Bencherchali (Nextron Systems), Georg Lauenstein (sure[secure]) · 2023-01-03 (modified 2024-09-19) · logsource: product=linux category=process_creation · a015e032-146d-4717-8944-7a1884122111
Detects known hacktool execution based on image name.
Techniques: T1587
Author: Florian Roth (Nextron Systems) · 2018-01-23 (modified 2021-11-27) · logsource: product=linux service=auditd · a39d7fa7-3fbd-4dc2-97e1-d87f546b1bbc
Detects program executions in suspicious non-program folders related to malware or hacking activity
Techniques: T1587T1584
Author: Florian Roth (Nextron Systems) · 2021-06-18 (modified 2023-02-05) · logsource: product=windows category=process_creation · ff23ffbc-3378-435e-992f-0624dcf93ab4
Detects the execution of the PurpleSharp adversary simulation tool
Techniques: T1587