1200KM / detection
T1105 Ingress Tool Transfer — Detection Rules
Detection workspace for T1105 Ingress Tool Transfer: 70 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Remote File Copy · stable · low · {"product":"linux"}
- Wget Creating Files in Tmp Directory · test · medium · {"product":"linux","category":"file_event"}
- Curl Usage on Linux · test · low · {"category":"process_creation","product":"linux"}
- Suspicious Curl File Upload - Linux · test · medium · {"category":"process_creation","product":"linux"}
- Download File To Potentially Suspicious Directory Via Wget · test · medium · {"category":"process_creation","product":"linux"}
- Hidden Flag Set On File/Directory Via Chflags - MacOS · test · medium · {"product":"macos","category":"process_creation"}
- File Download Via Nscurl - MacOS · test · medium · {"category":"process_creation","product":"macos"}
- Potential In-Memory Download And Compile Of Payloads · test · medium · {"category":"process_creation","product":"macos"}
- Cisco Stage Data · test · low · {"product":"cisco","service":"aaa"}
- Executable from Webdav · test · medium · {"product":"zeek","service":"http"}
- Download from Suspicious Dyndns Hosts · test · medium · {"category":"proxy"}
- Password Protected ZIP File Opened (Suspicious Filenames) · test · high · {"product":"windows","service":"security"}
- AppX Package Installation Attempts Via AppInstaller.EXE · test · medium · {"product":"windows","category":"dns_query"}
- Suspicious File Created by ArcSOC.exe · experimental · high · {"category":"file_event","product":"windows"}
- Potentially Suspicious File Creation by OpenEDR's ITSMService · experimental · medium · {"product":"windows","category":"file_event"}
- Suspicious Deno File Written from Remote Source · experimental · low · {"category":"file_event","product":"windows"}
- Suspicious Desktopimgdownldr Target File · test · high · {"product":"windows","category":"file_event"}
- Legitimate Application Writing Files In Uncommon Location · experimental · high · {"product":"windows","category":"file_event"}
- Uncommon Network Connection Initiated By Certutil.EXE · test · high · {"category":"network_connection","product":"windows"}
- Suspicious Dropbox API Usage · test · high · {"category":"network_connection","product":"windows"}
- Suspicious Non-Browser Network Communication With Telegram API · test · medium · {"product":"windows","category":"network_connection"}
- Network Connection Initiated By IMEWDBLD.EXE · test · high · {"category":"network_connection","product":"windows"}
- Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder · test · high · {"category":"network_connection","product":"windows"}
- Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location · test · high · {"category":"network_connection","product":"windows"}
- Local Network Connection Initiated By Script Interpreter · test · medium · {"category":"network_connection","product":"windows"}
- Outbound Network Connection Initiated By Script Interpreter · test · high · {"category":"network_connection","product":"windows"}
- PowerShell Download Via Net.WebClient - PowerShell Classic · test · low · {"product":"windows","category":"ps_classic_start"}
- Potential COM Objects Download Cradles Usage - PS Script · test · medium · {"product":"windows","category":"ps_script","definition":"Script Block Logging must be enable"}
- File Download Via Bitsadmin · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Download From File-Sharing Website Via Bitsadmin · test · high · {"category":"process_creation","product":"windows"}
- File With Suspicious Extension Downloaded Via Bitsadmin · test · high · {"category":"process_creation","product":"windows"}
- File Download Via Bitsadmin To A Suspicious Target Folder · test · high · {"category":"process_creation","product":"windows"}
- Browser Execution In Headless Mode · test · low · {"category":"process_creation","product":"windows"}
- File Download with Headless Browser · test · high · {"category":"process_creation","product":"windows"}
- File Download From Browser Process Via Inline URL · test · medium · {"category":"process_creation","product":"windows"}
- File Download via CertOC.EXE · test · medium · {"category":"process_creation","product":"windows"}
- File Download From IP Based URL Via CertOC.EXE · test · high · {"category":"process_creation","product":"windows"}
- Suspicious CertReq Command to Download · experimental · high · {"category":"process_creation","product":"windows"}
- Suspicious Download Via Certutil.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious File Downloaded From Direct IP Via Certutil.EXE · test · high · {"category":"process_creation","product":"windows"}
- Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE · test · high · {"category":"process_creation","product":"windows"}
- Curl Download And Execute Combination · test · high · {"category":"process_creation","product":"windows"}
- Command Line Execution with Suspicious URL and AppData Strings · test · medium · {"category":"process_creation","product":"windows"}
- Potential Download/Upload Activity Using Type Command · test · medium · {"product":"windows","category":"process_creation"}
- Suspicious Curl.EXE Download · test · high · {"category":"process_creation","product":"windows"}
- Remote File Download Via Desktopimgdownldr Utility · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Desktopimgdownldr Command · test · high · {"category":"process_creation","product":"windows"}
- Remote File Download Via Findstr.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Insensitive Subfolder Search Via Findstr.EXE · test · low · {"category":"process_creation","product":"windows"}
- Finger.EXE Execution · test · high · {"category":"process_creation","product":"windows"}
- Arbitrary File Download Via GfxDownloadWrapper.EXE · test · medium · {"category":"process_creation","product":"windows"}
- File Download Using Notepad++ GUP Utility · test · high · {"category":"process_creation","product":"windows"}
- File Download And Execution Via IEExec.EXE · test · high · {"category":"process_creation","product":"windows"}
- Import LDAP Data Interchange Format File Via Ldifde.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Diantz Download and Compress Into a CAB File · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Extrac32 Execution · test · medium · {"category":"process_creation","product":"windows"}
- PrintBrm ZIP Creation of Extraction · test · high · {"product":"windows","category":"process_creation"}
- Replace.exe Usage · test · medium · {"category":"process_creation","product":"windows"}
- File Download Via Windows Defender MpCmpRun.EXE · test · high · {"category":"process_creation","product":"windows"}
- MsiExec Web Install · test · medium · {"category":"process_creation","product":"windows"}
- PowerShell MSI Install via WindowsInstaller COM From Remote Location · experimental · medium · {"category":"process_creation","product":"windows"}
- Potential COM Objects Download Cradles Usage - Process Creation · test · medium · {"product":"windows","category":"process_creation"}
- Potential DLL File Download Via PowerShell Invoke-WebRequest · test · medium · {"product":"windows","category":"process_creation"}
- Suspicious Invoke-WebRequest Execution With DirectIP · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Invoke-WebRequest Execution · test · high · {"category":"process_creation","product":"windows"}
- PUA - Nimgrab Execution · test · high · {"category":"process_creation","product":"windows"}
- Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server · experimental · medium · {"category":"process_creation","product":"windows"}
- Scheduled Task Creation with Curl and PowerShell Execution Combo · experimental · medium · {"category":"process_creation","product":"windows"}
- Suspicious Download from Office Domain · test · high · {"product":"windows","category":"process_creation"}
- Lolbas OneDriveStandaloneUpdater.exe Proxy Download · test · high · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
T1105 Ingress Tool Transfer
MATCH(download_hash_or_url IN denylist) OR SEQUENCE(network_download, executable_file_creation) WITHIN 2m -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0060 Detect Ingress Tool Transfers via Behavioral Chain
AN0165 Analytic 0165
Unusual or uncommon processes initiate network connections to external destinations followed by file creation (tools downloaded).
AN0166 Analytic 0166
Shell-based tools (curl, wget, scp) initiate connections to external domains followed by creation of executable files on disk.
AN0167 Analytic 0167
Process execution of curl or wget followed by a network connection and a file created in temporary or user-specific directories.
AN0168 Analytic 0168
Command line interface or vCLI triggers remote transfer using wget or curl, writing files into datastore paths or local tmp directories.
AN0169 Analytic 0169
Network device logs show anomalous inbound file transfers or uncharacteristic flows with high payload volume to network devices with storage or automation hooks.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Command Execution · DC0064
- File Creation · DC0039
- Network Connection Creation · DC0082
- Network Traffic Flow · DC0078
- Process Creation · DC0032
- AsyncRAT · S1087
- BITSAdmin · S0190
- Brute Ratel C4 · S1063
- CARROTBALL · S0465
- certutil · S0160
- cmd · S0106
- Cobalt Strike · S0154
- CSPY Downloader · S0527
- Donut · S0695
- Empire · S0363
- esentutl · S0404
- ftp · S0095
- Koadic · S0250
- MCMD · S0500
- Pupy · S0192
- QuasarRAT · S0262
- Remcos · S0332
- RemoteUtilities · S0592
- ShimRatReporter · S0445
- SILENTTRINITY · S0692
- Sliver · S0633
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT28 · G0007
- Turla · G0010
- Darkhotel · G0012
- APT29 · G0016
- Molerats · G0021
- APT3 · G0022
- APT18 · G0026
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Sandworm Team · G0034
- Dragonfly · G0035
- Patchwork · G0040
- Winnti Group · G0044
- menuPass · G0045
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- FIN8 · G0061
- APT33 · G0064
- Leviathan · G0065
- Elderwood · G0066
- APT37 · G0067
- PLATINUM · G0068
- MuddyWater · G0069
- Rancor · G0075
- Gorgon Group · G0078
- Cobalt Group · G0080
- Tropic Trooper · G0081
- APT38 · G0082
- APT39 · G0087
- WIRTE · G0090
- Silence · G0091
- TA505 · G0092
- GALLIUM · G0093
- Kimsuky · G0094
- APT41 · G0096
- APT-C-36 · G0099
- Wizard Spider · G0102
- Rocke · G0106
- Whitefly · G0107
- Windshift · G0112
- Chimera · G0114
- Fox Kitten · G0117
- Indrik Spider · G0119
- Evilnum · G0120
- Sidewinder · G0121
- Volatile Cedar · G0123
- HAFNIUM · G0125
- TA551 · G0127
- ZIRCONIUM · G0128
- Mustang Panda · G0129
- Ajax Security Team · G0130
- Tonto Team · G0131
- Nomadic Octopus · G0133
- BackdoorDiplomacy · G0135
- IndigoZebra · G0136
- Andariel · G0138
- TeamTNT · G0139
- LazyScripter · G0140
- Confucius · G0142
- Aquatic Panda · G0143
- HEXANE · G1001
- BITTER · G1002
- SideCopy · G1008
- Moses Staff · G1009
- Metador · G1013
- LuminousMoth · G1014
- Scattered Spider · G1015
- FIN13 · G1016
- Volt Typhoon · G1017
- TA2541 · G1018
- Mustard Tempest · G1020
- Cinnamon Tempest · G1021
- INC Ransom · G1032
- Daggerfly · G1034
- Winter Vivern · G1035
- Moonstone Sleet · G1036
- Play · G1040
- BlackByte · G1043
- Storm-1811 · G1046
- Medusa Group · G1051
- VOID MANTICORE · G1055
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.