Techniques › T1588 › T1588.002
T1588.002 Tool
resource development — PRE · attack.mitre.org · JSON
1
MITRE detection strategy
1
analytics
9
Sigma rules tagged attack.t1588.002
0
KEV CVEs mapped here
<p>Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A tool can be used for malicious purposes by an adversary, but (unlike malware) were not intended to be used for those purposes (ex: PsExec).</p><p>Adversaries may obtain tools to support their operations, including to support execution of post-compromise behaviors. Tools may also be leveraged for testing – for example, evaluating malware against commercial antivirus or endpoint detection and response (EDR) applications.</p><p>Tool acquisition may involve the procurement of commercial software licenses, including for red teaming tools such as Cobalt Strike. In addition to freely downloading or purchasing software, adversaries may steal software and/or software licenses from third-party entities (including other adversaries). Threat actors may also crack trial versions of software.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0852 Detection of Tool v1.0
AN1984 PREMonitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. In some cases, malware repositories can also be used to identify features of tool use associated with an adversary, such as watermarks in Cobalt Strike payloads. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle.
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1588.002
Author: Florian Roth (Nextron Systems)
· 2022-03-04 (modified 2024-11-23) · logsource: product=windows category=process_creation · 24e3e58a-646b-4b50-adef-02ef935b9fc8
Detects the execution of different Windows based hacktools via their import hash (imphash) even if the files have been renamed
Author: Markus Neis
· 2017-08-28 (modified 2025-10-26) · logsource: product=windows category=registry_set · 25ffa65d-76d8-4da5-a832-3f2b0136e133
Detects the execution of a Sysinternals Tool via the creation of the "accepteula" registry key
Author: Florian Roth (Nextron Systems)
· 2019-10-12 (modified 2023-08-17) · logsource: product=windows category=registry_set · 34aa0252-6039-40ff-951f-939fd6ce47d8
Detects the keyboard preload installation with a suspicious keyboard layout, e.g. Chinese, Iranian or Vietnamese layout load in user session on systems maintained by US staff only
Author: Florian Roth (Nextron Systems)
· 2022-04-27 (modified 2024-01-15) · logsource: product=windows category=process_creation · 37c1333a-a0db-48be-b64b-7393b2386e3b
Detects the execution of different Windows based hacktools via PE metadata (company, product, etc.) even if the files have been renamed
Author: Markus Neis
· 2017-08-28 (modified 2024-03-13) · logsource: product=windows category=process_creation · 7cccd811-7ae9-4ebe-9afd-cb5c406b824b
Detects command lines that contain the 'accepteula' flag which could be a sign of execution of one of the Sysinternals tools
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-08-24 (modified 2026-06-29) · logsource: product=windows category=registry_set · 8023f872-3f1d-4301-a384-801889917ab4
Detects non-sysinternals tools setting the "accepteula" key which normally is set on sysinternals tool execution
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-08-24 (modified 2025-10-26) · logsource: product=windows category=registry_set · c7da8edc-49ae-45a2-9e61-9fd860e4e73d
Detects the execution of some potentially unwanted tools such as PsExec, Procdump, etc. (part of the Sysinternals suite) via the creation of the "accepteula" registry key.
Author: Florian Roth (Nextron Systems)
· 2020-05-28 (modified 2023-02-14) · logsource: product=windows category=process_creation · cd764533-2e07-40d6-a718-cfeec7f2da7f
Detects suspicious renamed SysInternals DebugView execution
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-08-24 (modified 2026-06-29) · logsource: product=windows category=registry_set · f50f3c09-557d-492d-81db-9064a8d4e211
Detects the creation of the "accepteula" key related to the Sysinternals tools being created from executables with the wrong name (e.g. a renamed Sysinternals tool)
Rules tagged at the parent level (attack.t1588) 2
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Florian Roth (Nextron Systems), Arnim Rupp
· 2017-02-19 (modified 2024-12-25) · logsource: product=windows service=application · 78bc5783-81d9-4d73-ac97-59f6db4f72a8
Detects potentially highly relevant antivirus events in the application log based on known virus signature names and malware keywords.
Author: Florian Roth (Nextron Systems), Arnim Rupp
· 2018-09-09 (modified 2026-06-29) · logsource: category=antivirus · c9a88268-0047-4824-ba6e-4d81ce0b907c
Detects an Antivirus alert in a highly relevant file path or with a relevant file name.
This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.