Tool
Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A tool can be used for malicious purposes by an adversary, but (unlike malware) were not intended to be used for those purposes (ex: PsExec). Tool acquisition can involve the procurement of commercial software licenses, including for red teaming tools such as Cobalt Strike. Commercial software may be obtained through purchase, stealing licenses (or licensed copies of the software), or cracking trial versions. Adversaries may obtain tools to support their operations, including to support execution of post-compromise behaviors. In addition to freely downloading or purchasing software, adversaries may steal software and/or software licenses from third-party entities (including other adversaries).
Open detection, hunting, mitigation, and evidence workspace
Detection logic
In some cases, malware repositories can also be used to identify features of tool use associated with an adversary, such as watermarks in Cobalt Strike payloads. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle.
Observed actors
G0082GALLIUM
G0093Kimsuky
G0094Volt Typhoon
G1017Patchwork
G0040APT41
G0096Dragonfly
G0035Gorgon Group
G0078menuPass
G0045APT32
G0050MuddyWater
G0069FIN6
G0037Gamaredon Group
G0047Leafminer
G0077FIN7
G0046Sandworm Team
G0034APT39
G0087TA2541
G1018Moses Staff
G1009Carbanak
G0008POLONIUM
G1005Aquatic Panda
G0143Aoqin Dragon
G1007Ferocious Kitten
G0137Ke3chang
G0004APT1
G0006DarkHydrus
G0079BlackTech
G0098Blue Mockingbird
G0108Turla
G0010TA505
G0092BITTER
G1002DarkVishnya
G0105FIN5
G0053APT29
G0016Cinnamon Tempest
G1021Chimera
G0114Cleaver
G0003Silent Librarian
G0122BRONZE BUTLER
G0060TEMP.Veles
G0088BackdoorDiplomacy
G0135Star Blizzard
G1033Ember Bear
G1003Whitefly
G0107LuminousMoth
G1014APT28
G0007Metador
G1013APT-C-36
G0099Lazarus Group
G0032INC Ransom
G1032Earth Lusca
G1006Silence
G0091Thrip
G0076LAPSUS$
G1004Cobalt Group
G0080CopyKittens
G0052Wizard Spider
G0102IndigoZebra
G0136Inception
G0100Play
G1040HEXANE
G1001WIRTE
G0090Magic Hound
G0059Threat Group-3390
G0027APT33
G0064FIN10
G0051FIN8
G0061FIN13
G1016APT19
G0073PittyTiger
G0011