1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T0867 Lateral Tool Transfer — Detection Rules

Detection workspace for T0867 Lateral Tool Transfer: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

No reviewed association in this snapshot.

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0745 Detection of Lateral Tool Transfer

AN1878 Analytic 1878

Monitor for unexpected network share access, such as files transferred between shares within a network using protocols such as Server Message Block (SMB). Monitor for alike file hashes or characteristics (ex: filename) that are created on multiple hosts. Monitor for file creation in conjunction with other techniques (e.g., file transfers using Remote Services). Monitor for unusual processes with internal network connections creating files on-system which may be suspicious. Monitor executed commands and arguments for abnormal usage of utilities and command-line arguments that may be used in support of remote transfer of files. Monitor newly constructed processes that assist in lateral tool transfers, such as file transfer programs. Monitor for network traffic originating from unknown/unexpected hosts. Local network traffic metadata (such as source MAC addressing) as well as usage of network management protocols such as DHCP may be helpful in identifying hardware.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T0867 simulation workspace

No reviewed association in this snapshot.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.