1200KM / detection
T1587.001 Malware — Detection Rules
Detection workspace for T1587.001 Malware: 7 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- ProxyLogon MSExchange OabVirtualDirectory · test · critical · {"product":"windows","service":"msexchange-management"}
- Uncommon File Created In Office Startup Folder · test · high · {"product":"windows","category":"file_event"}
- VHD Image Download Via Browser · test · medium · {"category":"file_event","product":"windows"}
- PUA - CsExec Execution · test · high · {"category":"process_creation","product":"windows"}
- PsExec/PAExec Escalation to LOCAL SYSTEM · test · high · {"category":"process_creation","product":"windows"}
- Potential PsExec Remote Execution · test · high · {"category":"process_creation","product":"windows"}
- Potential Privilege Escalation To LOCAL SYSTEM · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0872 Detection of Malware
AN2004 Analytic 2004
Consider analyzing malware for features that may be associated with the adversary and/or their developers, such as compiler used, debugging artifacts, or code similarities. Malware repositories can also be used to identify additional samples associated with the adversary and identify development patterns over time. Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1587.001 simulation workspace
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Cleaver · G0003
- Ke3chang · G0004
- Turla · G0010
- APT29 · G0016
- Lazarus Group · G0032
- Sandworm Team · G0034
- FIN7 · G0046
- OilRig · G0049
- Kimsuky · G0094
- APT-C-36 · G0099
- Indrik Spider · G0119
- Mustang Panda · G0129
- TeamTNT · G0139
- Aoqin Dragon · G1007
- Moses Staff · G1009
- LuminousMoth · G1014
- FIN13 · G1016
- Moonstone Sleet · G1036
- RedCurl · G1039
- Play · G1040
- Salt Typhoon · G1045
- UNC3886 · G1048
- Contagious Interview · G1052
- MirrorFace · G1054
- VOID MANTICORE · G1055
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.