1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / simulation

T1105 Ingress Tool Transfer — Attack Simulation

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer). On Windows, adversaries…

Complete technique description

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

On Windows, adversaries may use various utilities to download tools, such as `copy`, `finger`, certutil, and PowerShell commands such as <code>IEX(New-Object Net.WebClient).downloadString()</code> and <code>Invoke-WebRequest</code>. On Linux and macOS systems, a variety of utilities also exist, such as `curl`, `scp`, `sftp`, `tftp`, `rsync`, `finger`, and `wget`.[t1105_lolbas] A number of these tools, such as `wget`, `curl`, and `scp`, also exist on ESXi. After downloading a file, a threat actor may attempt to verify its integrity by checking its hash value (e.g., via `certutil -hashfile`).[Google Cloud Threat Intelligence COSCMICENERGY 2023]

Adversaries may also abuse installers and package managers, such as `yum` or `winget`, to download tools to victim hosts. Adversaries have also abused file application features, such as the Windows `search-ms` protocol handler, to deliver malicious files to victims through remote file searches invoked by User Execution (typically after interacting with Phishing lures).[T1105: Trellix_search-ms]

Files can also be transferred using various Web Services as well as native or otherwise present tools on the victim system.[PTSecurity Cobalt Dec 2016] In some cases, adversaries may be able to leverage services that sync between a web-based and an on-premises client, such as Dropbox or OneDrive, to transfer files onto victim systems. For example, by compromising a cloud account and logging into the service's web portal, an adversary may be able to trigger an automatic syncing process that transfers the file onto the victim's machine.[Dropbox Malware Sync]

Official technique definition · Open in the interactive matrix

Detection telemetry and configuration

These contracts are selected through exact technique-to-data-component relationships or explicitly labelled planning overrides. Configure a collector at the relevant observation point; a telemetry name alone is not coverage.

Command Execution · source-mapped

DC0064 collection page — Collect process command lines and relevant shell/interpreter audit; shell history alone is neither complete nor tamper-resistant.

Providers and collection configuration

  • Enable Script Block Logging through the policy/configuration for the installed edition. Forward Microsoft-Windows-PowerShell/Operational for Windows PowerShell, or PowerShellCore/Operational for PowerShell 7.
  • Retain script-block ID and fragment ordering alongside process creation. Protect access to collected script text; secrets may be included.
  • On Linux, use narrowly scoped Audit execution rules for the lab account and supported architectures, and retain joined SYSCALL/EXECVE/PATH records.

Required normalized fields: interpreter, command_line, actor_uid, session_id.

Illustrative collection event

Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.

{
  "schema": "1200km.telemetry.example.v1",
  "synthetic": true,
  "timestamp": "2026-09-27T12:00:00Z",
  "telemetry_id": "DC0064",
  "collector": "illustrative-lab-collector",
  "observation": {
    "interpreter": "/bin/sh",
    "command_line": "printf LAB_TELEMETRY_CHECK",
    "actor_uid": 1000,
    "session_id": "lab-session-1"
  }
}

Visibility limits: Script content and process command lines are different signals. Logging may be partial, fragmented, filtered or disabled; never assume a command line reveals everything executed.

File Creation · source-mapped

DC0039 collection page — Scope Sysmon FileCreate (11) to the lab directory; retain the process and file path. Differentiate creation/overwrite if the sensor can.

Providers and collection configuration

  • Microsoft Sysmon: Windows event-based collection; enable the event types needed below.
  • Linux Audit: Linux alternative for supported system-call and file events; different semantics and fields.
  • Apple Endpoint Security clients: macOS alternative where the subscribed event exists; requires an entitled, approved client, not an iOS collector.
  • On a disposable Windows host, review the installed Sysmon schema and current configuration; merge scoped event filters into the existing policy rather than replacing it.
  • Forward Microsoft-Windows-Sysmon/Operational to the lab collector. Preserve event ID, timestamp, computer, process identifiers and the original event.
  • For Linux or macOS, select the equivalent sensor separately and test its emitted fields; a Windows event ID does not transfer across platforms.

Required normalized fields: process_id, path, action, size_bytes.

Illustrative collection event

Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.

{
  "schema": "1200km.telemetry.example.v1",
  "synthetic": true,
  "timestamp": "2026-09-27T12:00:00Z",
  "telemetry_id": "DC0039",
  "collector": "illustrative-lab-collector",
  "observation": {
    "process_id": 4200,
    "path": "C:\\Lab\\demo.txt",
    "action": "create",
    "size_bytes": 64
  }
}

Visibility limits: Event filtering and sensor versions change coverage. High-volume image-load and process-access collection needs tuning; endpoint events alone do not establish intent.

Network Connection Creation · source-mapped

DC0082 collection page — Enable scoped Sysmon NetworkConnect (3), disabled by default, or a platform-equivalent process-aware network sensor.

Providers and collection configuration

  • Microsoft Sysmon: Windows event-based collection; enable the event types needed below.
  • Linux Audit: Linux alternative for supported system-call and file events; different semantics and fields.
  • Apple Endpoint Security clients: macOS alternative where the subscribed event exists; requires an entitled, approved client, not an iOS collector.
  • On a disposable Windows host, review the installed Sysmon schema and current configuration; merge scoped event filters into the existing policy rather than replacing it.
  • Forward Microsoft-Windows-Sysmon/Operational to the lab collector. Preserve event ID, timestamp, computer, process identifiers and the original event.
  • For Linux or macOS, select the equivalent sensor separately and test its emitted fields; a Windows event ID does not transfer across platforms.

Required normalized fields: process_guid, destination_ip, destination_port, protocol, initiated.

Illustrative collection event

Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.

{
  "schema": "1200km.telemetry.example.v1",
  "synthetic": true,
  "timestamp": "2026-09-27T12:00:00Z",
  "telemetry_id": "DC0082",
  "collector": "illustrative-lab-collector",
  "observation": {
    "process_guid": "lab-process-001",
    "destination_ip": "198.51.100.20",
    "destination_port": 443,
    "protocol": "tcp",
    "initiated": true
  }
}

Visibility limits: Event filtering and sensor versions change coverage. High-volume image-load and process-access collection needs tuning; endpoint events alone do not establish intent.

Network Traffic Flow · source-mapped

DC0078 collection page — Collect Zeek conn.log, Suricata flow events or exporter equivalents, including observation point and sampling settings.

Providers and collection configuration

  • Zeek: Connection and protocol metadata from traffic visible to the sensor.
  • Suricata EVE: Configured flow, alert, DNS, HTTP, TLS and protocol records.
  • AWS VPC Flow Logs: IP traffic metadata alternative; no packet payload or DNS answer history, and some traffic is not logged.
  • Use an authorized lab TAP/SPAN, virtual mirror or gateway interface. Define which traffic crosses it; avoid assuming visibility into every segment.
  • Enable the required Zeek analyzers or Suricata EVE event types. Export logs with sensor identity, clock synchronization and flow correlation identifiers.
  • Monitor capture loss, truncation and exporter sampling. Capture payload only with approval and restrictive retention; encryption normally prevents plaintext inspection.

Required normalized fields: source_ip, destination_ip, destination_port, protocol, bytes_sent, bytes_received.

Illustrative collection event

Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.

{
  "schema": "1200km.telemetry.example.v1",
  "synthetic": true,
  "timestamp": "2026-09-27T12:00:00Z",
  "telemetry_id": "DC0078",
  "collector": "illustrative-lab-collector",
  "observation": {
    "source_ip": "192.0.2.10",
    "destination_ip": "198.51.100.20",
    "destination_port": 443,
    "protocol": "tcp",
    "bytes_sent": 128,
    "bytes_received": 512
  }
}

Visibility limits: Flows are not packet payloads. NAT, asymmetric routes, encryption, missing mirrors and sampling can hide attribution or content. A destination connection alone does not prove malicious intent.

Process Creation · source-mapped

DC0032 collection page — Collect Sysmon ProcessCreate (1); preserve ProcessGuid and parent identifiers. Security 4688 is an alternative with separate audit/command-line settings.

Providers and collection configuration

  • Microsoft Sysmon: Windows event-based collection; enable the event types needed below.
  • Linux Audit: Linux alternative for supported system-call and file events; different semantics and fields.
  • Apple Endpoint Security clients: macOS alternative where the subscribed event exists; requires an entitled, approved client, not an iOS collector.
  • On a disposable Windows host, review the installed Sysmon schema and current configuration; merge scoped event filters into the existing policy rather than replacing it.
  • Forward Microsoft-Windows-Sysmon/Operational to the lab collector. Preserve event ID, timestamp, computer, process identifiers and the original event.
  • For Linux or macOS, select the equivalent sensor separately and test its emitted fields; a Windows event ID does not transfer across platforms.

Required normalized fields: process_guid, image, parent_image, command_line, user.

<EventFiltering>
  <ProcessCreate onmatch="include">
    <Image condition="is">C:\Windows\System32\whoami.exe</Image>
  </ProcessCreate>
</EventFiltering>

This fragment only selects the named process. It is not a complete production policy. Inspect the installed schema with sysmon64 -s; preserve existing rules, then apply the reviewed complete configuration with sysmon64 -c <configuration-file>.

Illustrative collection event

Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.

{
  "schema": "1200km.telemetry.example.v1",
  "synthetic": true,
  "timestamp": "2026-09-27T12:00:00Z",
  "telemetry_id": "DC0032",
  "collector": "illustrative-lab-collector",
  "observation": {
    "process_guid": "lab-process-001",
    "image": "C:\\Windows\\System32\\whoami.exe",
    "parent_image": "C:\\Windows\\System32\\cmd.exe",
    "command_line": "whoami",
    "user": "LAB\\analyst"
  }
}

Visibility limits: Event filtering and sensor versions change coverage. High-volume image-load and process-access collection needs tuning; endpoint events alone do not establish intent.

Detection rules and analytic guidance

Open the dedicated detection workspace · Existing query engineering

DET0060 Detect Ingress Tool Transfers via Behavioral Chain

MITRE detection strategy

AN0166 Analytic 0166

Shell-based tools (curl, wget, scp) initiate connections to external domains followed by creation of executable files on disk.

Platforms: Linux.

AN0167 Analytic 0167

Process execution of curl or wget followed by a network connection and a file created in temporary or user-specific directories.

Platforms: macOS.

AN0168 Analytic 0168

Command line interface or vCLI triggers remote transfer using wget or curl, writing files into datastore paths or local tmp directories.

Platforms: ESXi.

AN0169 Analytic 0169

Network device logs show anomalous inbound file transfers or uncharacteristic flows with high payload volume to network devices with storage or automation hooks.

Platforms: Network Devices.

Source rule directory and observation requirements

70 exact-tagged source rules. A source tag is a discovery aid, not a relevance verdict. Check the observation point and actual condition of each rule.

Before treating a rule as coverage

  1. Read the actual condition and logsource; identify attacker-side, victim-side or third-party visibility.
  2. Map native sensor fields, parse times and identities, then compile for the selected backend.
  3. Replay a behavior-positive case, a normal control, an authorized look-alike and a missing-telemetry case.
  4. Record matches and misses with rule version and source events. No match is inconclusive when required telemetry is absent.

Anomaly-based detection

No exact technique-specific Atlas model is present for T1105 in the selected source snapshot. The following is a design worksheet, not a newly validated model.

Anomaly engineering worksheet

Start from the exact analytic above. The collection-specific lenses below are analyst recommendations; they do not assert that an arbitrary statistical deviation detects this technique.

  • Script and command execution: Per host role and principal: rare interpreters, command argument patterns and parent-child sequences. Normalize scripts carefully; obfuscation, administrative automation and missing command lines change visibility.
  • Endpoint activity: Per host role and user: rare process/object combinations, bursts of object access or modification, and ordered parent/action sequences. Compare maintenance windows and signed software rollout activity.
  • Network and protocol telemetry: Per source and observation point: connection rate, destination-host/port fan-out, response/failure ratio and previously unseen destinations. Compare equivalent time windows; separate authorized scanners, NAT and sampling effects.
  1. Define an entity/peer group and feature; exclude the evaluation period from baseline training.
  2. Use representative normal and maintenance activity. Do not invent a production threshold from a synthetic example.
  3. Evaluate held-out behavior-positive and benign cases; measure false positives, misses and telemetry loss separately.
  4. Keep abnormality separate from maliciousness. Correlate with the behavior-specific source evidence.

Anomaly Detection Atlas · Baseline, validation and blind spots

Attack tools and documented software

Software observed in source procedures

These are exact ATT&CK software-use relationships, including malware. They provide behavior context, not recommendations to download or execute malware. No safety or detector claim is inherited.

403 source-documented software associations

Simulation design and documented procedures

Atomic evidence: 38 compatible documented candidates. Live lab status: not run for these imported procedures.

Use disposable lab hosts and test accounts, explicit target allowlists, a clean snapshot, bounded egress and a restore plan. Review every candidate and dependency before any execution.

sftp remote file copy (pull)

Utilize sftp to perform a remote file copy (pull)

Pinned Atomic procedure · 0139dba1-f391-405e-a4f5-f3989f2c88ef · linux, macos · sh.

Elevation: not declared required. Cleanup: not declared. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_host: Remote host to copy from (type string; source default adversary-host)
  • local_path: Local path to receive sftp (type path; source default /tmp/victim-files/)
  • remote_file: Path of file to copy (type path; source default /tmp/adversary-sftp)
  • username: User account to authenticate on remote host (type string; source default adversary)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

rsync remote file copy (push)

Utilize rsync to perform a remote file copy (push)

Pinned Atomic procedure · 0fc6e977-cb12-44f6-b263-2824ba917409 · linux, macos · sh.

Elevation: required. Cleanup: not declared. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_path: Remote path to receive rsync (type path; source default /tmp/victim-files)
  • remote_host: Remote host to copy toward (type string; source default victim-host)
  • local_path: Path of folder to copy (type path; source default /tmp/adversary-rsync/)
  • username: User account to authenticate on remote host (type string; source default victim)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

1 prerequisite definitions:

  • rsync must be installed on the machine
Download a file with IMEWDBLD.exe

Use IMEWDBLD.exe (built-in to windows) to download a file. This will throw an error for an invalid dictionary file.
Downloaded files can be found in "%LocalAppData%\Microsoft\Windows\INetCache\<8_RANDOM_ALNUM_CHARS>/<FILENAME>[1].<EXTENSION>" or `%LocalAppData%\Microsoft\Windows\INetCache\IE\<8_RANDOM_ALNUM_CHARS>/<FILENAME>[1].<EXTENSION>.
Run "Get-ChildItem -Path C:\Users\<USERNAME>\AppData\Local\Microsoft\Windows\INetCache\ -Include <FILENAME>* -Recurse -Force -File -ErrorAction SilentlyContinue" without quotes and adding the correct username and file name to locate the file.

Pinned Atomic procedure · 1a02df58-09af-4064-a765-0babe1a0d1e2 · windows · powershell.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_url: Location of file to be downloaded. (type url; source default https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1105/T1105.yaml)
  • file_name: Name of the file to be downloaded without extension. (type string; source default T1105)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

Windows push file using sftp.exe

This test simulates pushing files using SFTP on a Windows environment.

Pinned Atomic procedure · 205e676e-0401-4bae-83a5-94b8c5daeb22 · windows · powershell.

Elevation: required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_path: Path of folder to copy (type path; source default /tmp)
  • remote_host: Remote host to send (type string; source default adversary-host)
  • local_path: Local path to receive sftp (type path; source default C:\temp)
  • file_name: Name of the file to transfer (type string; source default T1105.txt)
  • username: User account to authenticate on remote host (type string; source default adversary)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

1 prerequisite definitions:

  • This test requires the `sftp` command to be available on the system.
Windows push file using scp.exe

This test simulates pushing files using SCP on a Windows environment.

Pinned Atomic procedure · 2a4b0d29-e5dd-4b66-b729-07423ba1cd9d · windows · powershell.

Elevation: required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_path: Path of folder to copy (type path; source default /tmp/)
  • remote_host: Remote host to send (type string; source default adversary-host)
  • local_path: Local path to copy from (type path; source default C:\temp)
  • file_name: Name of the file to transfer (type string; source default T1105.txt)
  • username: User account to authenticate on remote host (type string; source default adversary)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

1 prerequisite definitions:

  • This test requires the `scp` command to be available on the system.
Curl Download File

The following Atomic utilizes native curl.exe, or downloads it if not installed, to download a remote DLL and output to a number of directories to simulate malicious behavior.
Expected output will include whether the file downloaded successfully or not.

Pinned Atomic procedure · 2b080b99-0deb-4d51-af0f-833d37c4ca6a · windows · command_prompt.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • file_download: File to download (type string; source default https://github.com/redcanaryco/atomic-red-team/raw/058b5c2423c4a6e9e226f4e5ffa1a6fd9bb1a90e/atomics/T1218.010/bin/AllTheThingsx64.dll)
  • curl_path: path to curl.exe (type path; source default C:\Windows\System32\Curl.exe)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

1 prerequisite definitions:

  • Curl must be installed on system.
OSTAP Worming Activity

OSTap copies itself in a specfic way to shares and secondary drives. This emulates the activity.

Pinned Atomic procedure · 2ca61766-b456-4fcf-a35a-1233685e1cad · windows · command_prompt.

Elevation: required. Cleanup: not declared. This is source documentation, not an execution approval.

Source-defined inputs

  • destination_path: Path to create remote file at. Default is local admin share. (type string; source default \\localhost\C$)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

rsync remote file copy (pull)

Utilize rsync to perform a remote file copy (pull)

Pinned Atomic procedure · 3180f7d5-52c0-4493-9ea0-e3431a84773f · linux, macos · sh.

Elevation: not declared required. Cleanup: not declared. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_path: Path of folder to copy (type path; source default /tmp/adversary-rsync/)
  • remote_host: Remote host to copy from (type string; source default adversary-host)
  • local_path: Local path to receive rsync (type path; source default /tmp/victim-files)
  • username: User account to authenticate on remote host (type string; source default adversary)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

1 prerequisite definitions:

  • rsync must be installed on the machine
Windows pull file using sftp.exe

This test simulates pulling files using SFTP on a Windows environment.

Pinned Atomic procedure · 3d25f1f2-55cb-4a41-a523-d17ad4cfba19 · windows · powershell.

Elevation: required. Cleanup: not declared. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_path: Path of file to pull (type path; source default /tmp/T1105.txt)
  • remote_host: Remote host to pull from (type string; source default adversary-host)
  • local_path: Local path to receive files (type path; source default C:\temp)
  • username: User account to authenticate on remote host (type string; source default adversary)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

1 prerequisite definitions:

  • This test requires the `sftp` command to be available on the system.
Download a file with OneDrive Standalone Updater

Uses OneDrive Standalone Updater to download a file from a specified URL by setting up the required registry keys.
This technique can be used to download files without executing anomalous executables.
Reference: https://lolbas-project.github.io/lolbas/Binaries/OneDriveStandaloneUpdater/

Pinned Atomic procedure · 3dd6a6cf-9c78-462c-bd75-e9b54fc8925b · windows · powershell.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_url: URL to download file from (type url; source default https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt)
  • onedrive_path: Path to OneDrive Standalone Updater executable (type path; source default C:\Users\$env:USERNAME\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

1 prerequisite definitions:

  • OneDriveStandaloneUpdater.exe must exist on disk at specified location
Windows pull file using scp.exe

This test simulates pulling files using SCP on a Windows environment.

Pinned Atomic procedure · 401667dc-05a6-4da0-a2a7-acfe4819559c · windows · powershell.

Elevation: required. Cleanup: not declared. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_path: Path of folder to pull (type path; source default /tmp/T1105.txt)
  • remote_host: Remote host to pull from (type string; source default adversary-host)
  • local_path: Local path to receive files (type path; source default C:\temp)
  • username: User account to authenticate on remote host (type string; source default adversary)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

1 prerequisite definitions:

  • This test requires the `scp` command to be available on the system.
Windows - PowerShell Download

This test uses PowerShell to download a payload.
This technique is used by multiple adversaries and malware families.

Pinned Atomic procedure · 42dc4460-9aa6-45d3-b1a6-3955d34e1fe8 · windows · powershell.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_file: URL of file to copy (type url; source default https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt)
  • destination_path: Destination path to file (type path; source default $env:TEMP\Atomic-license.txt)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

Printer Migration Command-Line Tool UNC share folder into a zip file

Create a ZIP file from a folder in a remote drive

Pinned Atomic procedure · 49845fc1-7961-4590-a0f0-3dbcf065ae7e · windows · command_prompt.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • Path_unc: Path to the UNC folder (type path; source default \\127.0.0.1\c$\AtomicRedTeam\atomics\T1105\src\)
  • Path_PrintBrm: Path to PrintBrm.exe (type path; source default C:\Windows\System32\spool\tools\PrintBrm.exe)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

Lolbas replace.exe use to copy file

Copy file.cab to destination
Reference: https://lolbas-project.github.io/lolbas/Binaries/Replace/

Pinned Atomic procedure · 54782d65-12f0-47a5-b4c1-b70ee23de6df · windows · command_prompt.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • replace_cab: Path to the cab file (type path; source default PathToAtomicsFolder\T1105\src\redcanary.cab)
  • Path_replace: Path to replace.exe (type path; source default C:\Windows\System32\replace.exe)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

1 prerequisite definitions:

  • #{replace_cab} must exist on system.
File Download via PowerShell

Use PowerShell to download and write an arbitrary file from the internet. Example is from the 2021 Threat Detection Report by Red Canary.

Pinned Atomic procedure · 54a4daf1-71df-4383-9ba7-f1a295d8b6d2 · windows · powershell.

Elevation: not declared required. Cleanup: not declared. This is source documentation, not an execution approval.

Source-defined inputs

  • target_remote_file: File to download (type url; source default https://raw.githubusercontent.com/redcanaryco/atomic-red-team/4042cb3433bce024e304500dcfe3c5590571573a/LICENSE.txt)
  • output_file: File to write to (type string; source default LICENSE.txt)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

File download via nscurl

Use nscurl to download and write a file/payload from the internet.
-k = Disable certificate checking
-o = Output destination

Pinned Atomic procedure · 5bcefe5f-3f30-4f1c-a61a-8d7db3f4450c · macos · sh.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_file: URL of remote file to download (type url; source default https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt)
  • destination_path: Local path to place remote file (type path; source default license.txt)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

File download with finger.exe on Windows

Simulate a file download using finger.exe. Connect to localhost by default, use custom input argument to test finger connecting to an external server.
Because this is being tested on the localhost, you should not be expecting a successful connection
https://www.exploit-db.com/exploits/48815
https://www.bleepingcomputer.com/news/security/windows-10-finger-command-can-be-abused-to-download-or-steal-files/

Pinned Atomic procedure · 5f507e45-8411-4f99-84e7-e38530c45d01 · windows · command_prompt.

Elevation: not declared required. Cleanup: not declared. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_host: Remote hostname or IP address (type string; source default localhost)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

Curl Upload File

The following Atomic utilizes native curl.exe, or downloads it if not installed, to upload a txt file to simulate data exfiltration
Expected output will include whether the file uploaded successfully or not.

Pinned Atomic procedure · 635c9a38-6cbf-47dc-8615-3810bc1167cf · windows · command_prompt.

Elevation: not declared required. Cleanup: not declared. This is source documentation, not an execution approval.

Source-defined inputs

  • curl_path: path to curl.exe (type path; source default C:\Windows\System32\Curl.exe)
  • remote_destination: Remote destination (type string; source default www.example.com)
  • file_path: File to upload (type string; source default c:\temp\atomictestfile.txt)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

2 prerequisite definitions:

  • Curl must be installed on system.
  • A file must be created to upload
Arbitrary file download using the Notepad++ GUP.exe binary

GUP is an open source signed binary used by Notepad++ for software updates, and can be used to download arbitrary files(.zip) from internet/github. Reference
Upon execution, a sample zip file will be downloaded to C:\Temp\Sample folder

Pinned Atomic procedure · 66ee226e-64cb-4dae-80e3-5bf5763e4a51 · windows · command_prompt.

Elevation: required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • target_file_url: URL of the target ZIP file (Eg: https://example.com/test.zip) (type url; source default https://getsamplefiles.com/download/zip/sample-2.zip)
  • working_dir: The directory where GUP.exe & it's dependecies exists (type path; source default PathToAtomicsFolder\T1105\bin\)
  • gup_executable: GUP is an open source signed binary used by Notepad++ for software updates (type String; source default PathToAtomicsFolder\T1105\bin\GUP.exe)
  • target_file_sha256: SHA256 value of target ZIP file (type string; source default CAC4D26F32CA629DFB10FE614ED00EB1066A0C0011386290D3426C3DE2E53AC6)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

1 prerequisite definitions:

  • Gup.exe binary must exist on disk at specified location (#{gup_executable})
File Download with Sqlcmd.exe

One of the windows packages 'Sqlcmd.exe' can be abused to download malicious files from C2 servers
This Atomic will exhibit the similar behavior by downloading a sample zip file from src directory of this Technique folder via GitHub URL

Pinned Atomic procedure · 6934c16e-0b3a-4e7f-ab8c-c414acd32181 · windows · powershell.

Elevation: required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_url: URL of the C2 Server from where file/s need to be downloaded (type url; source default https://github.com/redcanaryco/atomic-red-team/raw/master/atomics/T1105/src/T1105.zip)
  • local_file_path: The local file path along with filename to where the file needs to be downloaded and placed. (type path; source default C:\T1105.zip)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

1 prerequisite definitions:

  • Windows package 'Sqlcmd' need to be available in the machine to execute this atomic successfully
certreq download

Use certreq to download a file from the web

Pinned Atomic procedure · 6fdaae87-c05b-42f8-842e-991a74e8376b · windows · command_prompt.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • local_path: Local path to place file (type string; source default %temp%\Atomic-license.txt)
  • remote_file: URL of file to copy (type url; source default https://example.com)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

MAZE Propagation Script

This test simulates MAZE ransomware's propogation script that searches through a list of computers, tests connectivity to them, and copies a binary file to the Windows\Temp directory of each one.
Upon successful execution, a specified binary file will attempt to be copied to each online machine, a list of the online machines, as well as a list of offline machines will be output to a specified location.
Reference: https://www.fireeye.com/blog/threat-research/2020/05/tactics-techniques-procedures-associated-with-maze-ransomware-incidents.html

Pinned Atomic procedure · 70f4d07c-5c3e-4d53-bb0a-cdf3ada14baf · windows · powershell.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • binary_file: Binary file to copy to remote machines (type string; source default $env:comspec)
  • exe_remote_folder: Path to store executable on remote machine (no drive letter) (type string; source default \Windows\Temp\T1105.exe)
  • remote_drive_letter: Remote drive letter (type string; source default C)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

2 prerequisite definitions:

  • Binary file must exist at specified location (#{binary_file})
  • Machine list must exist at specified location ("PathToAtomicsFolder\..\ExternalPayloads\T1105MachineList.txt")
Download a File with Windows Defender MpCmdRun.exe

Uses Windows Defender MpCmdRun.exe to download a file from the internet (must have version 4.18 installed).
The input arguments "remote_file" and "local_path" can be used to specify the download URL and the name of the output file.
By default, the test downloads the Atomic Red Team license file to the temp directory.

More info and how to find your version can be found here https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/

Pinned Atomic procedure · 815bef8b-bf91-4b67-be4c-abe4c2a94ccc · windows · command_prompt.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_file: URL of file to download (type url; source default https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt)
  • local_path: Location to save downloaded file (type path; source default %temp%\Atomic-license.txt)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

1 prerequisite definitions:

  • Must have a Windows Defender version with MpCmdRun.exe installed
scp remote file copy (push)

Utilize scp to perform a remote file copy (push)

Pinned Atomic procedure · 83a49600-222b-4866-80a0-37736ad29344 · linux, macos · sh.

Elevation: not declared required. Cleanup: not declared. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_path: Remote path to receive scp (type path; source default /tmp/victim-files/)
  • local_file: Path of file to copy (type path; source default /tmp/adversary-scp)
  • remote_host: Remote host to copy toward (type string; source default victim-host)
  • username: User account to authenticate on remote host (type string; source default victim)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

Download a file using wscript

Use wscript to run a local VisualBasic file to download a remote file

Pinned Atomic procedure · 97116a3f-efac-4b26-8336-b9cb18c45188 · windows · command_prompt.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • vbscript_file: Full path to the VisualBasic downloading the file (type string; source default PathToAtomicsFolder\T1105\src\T1105-download-file.vbs)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

1 prerequisite definitions:

  • #{vbscript_file} must be exist on system.
Windows - BITSAdmin BITS Download

This test uses BITSAdmin.exe to schedule a BITS job for the download of a file.
This technique is used by Qbot malware to download payloads.

Pinned Atomic procedure · a1921cd3-9a2d-47d5-a891-f1d0f2a7a31b · windows · command_prompt.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • bits_job_name: Name of the created BITS job (type string; source default qcxjb7)
  • local_path: Local path to place file (type path; source default %temp%\Atomic-license.txt)
  • remote_file: URL of file to copy (type url; source default https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

Nimgrab - Transfer Files

Use nimgrab.exe to download a file from the web.

Pinned Atomic procedure · b1729c57-9384-4d1c-9b99-9b220afb384e · windows · command_prompt.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_file: URL of file to copy (type url; source default https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt)
  • destination_path: Destination path to file (type path; source default $env:TEMP\Atomic-license.txt)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

1 prerequisite definitions:

  • NimGrab must be installed on system.
scp remote file copy (pull)

Utilize scp to perform a remote file copy (pull)

Pinned Atomic procedure · b9d22b9a-9778-4426-abf0-568ea64e9c33 · linux, macos · sh.

Elevation: not declared required. Cleanup: not declared. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_host: Remote host to copy from (type string; source default adversary-host)
  • local_path: Local path to receive scp (type path; source default /tmp/victim-files/)
  • remote_file: Path of file to copy (type path; source default /tmp/adversary-scp)
  • username: User account to authenticate on remote host (type string; source default adversary)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

Linux Download File and Run

Utilize linux Curl to download a remote file, chmod +x it and run it.

Pinned Atomic procedure · bdc373c5-e9cf-4563-8a7b-a9ba720a90f3 · linux · sh.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_url: url of remote payload (type string; source default https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1105/src/atomic.sh)
  • payload_name: payload name (type string; source default atomic.sh)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

iwr or Invoke Web-Request download

Use 'iwr' or "Invoke-WebRequest" -URI argument to download a file from the web. Note: without -URI also works in some versions.

Pinned Atomic procedure · c01cad7f-7a4c-49df-985e-b190dcf6a279 · windows · command_prompt.

Elevation: required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_file: URL of file to copy (type url; source default https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt)
  • local_path: Local path to place file (type path; source default %temp%\Atomic-license.txt)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

Remote File Copy using PSCP

Copy a staged file using PSCP.exe to a public target location.

Pinned Atomic procedure · c82b1e60-c549-406f-9b00-0a8ae31c9cfe · windows · command_prompt.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • pscp_url: pscp.exe download path (type string; source default https://the.earth.li/~sgtatham/putty/latest/w64/pscp.exe)
  • pscp_binary: PSCP binary location (type string; source default PathToAtomicsFolder\..\ExternalPayloads\pscp.exe)
  • scp_user: Username of the SCP user (type string; source default atomic)
  • scp_password: Password for the SCP User (type string; source default atomic)
  • scp_port: port for the remote server (type string; source default 22)
  • exfil_package: path to exfil package (type path; source default C:\Temp\T1105_scp.zip)
  • target_location: Remote location where the data will be copied to. (type string; source default 127.0.0.1)
  • target_filename: Filename on the destination. (type string; source default T1105_scp.zip)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

1 prerequisite definitions:

  • pscp.exe must be available on the system.
whois file download

Download a remote file using the whois utility

Pinned Atomic procedure · c99a829f-0bb8-4187-b2c6-d47d1df74cab · linux, macos · sh.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_host: Remote hostname or IP address (type string; source default localhost)
  • remote_port: Remote port to connect to (type integer; source default 8443)
  • output_file: Path of file to save output to (type path; source default /tmp/T1105.whois.out)
  • query: Query to send to remote server (type string; source default Hello from Atomic Red Team test T1105)
  • timeout: Timeout period before ending process (seconds) (type integer; source default 1)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

1 prerequisite definitions:

  • The whois and timeout commands must be present
Download a file with Microsoft Connection Manager Auto-Download

Uses the cmdl32 to download arbitrary file from the internet. The cmdl32 package is allowed to install the profile used to launch the VPN connection. However, the config is modified to download the arbitary file.
The issue of cmdl32.exe detecting and deleting the payload by identifying it as not a VPN Servers profile is avoided by setting a temporary TMP folder and denying the delete permission to all files for the user.
Upon successful execution the test will open calculator and Notepad executable for 10 seconds.
reference:
https://twitter.com/ElliotKillick/status/1455897435063074824
https://github.com/LOLBAS-Project/LOLBAS/pull/151
https://lolbas-project.github.io/lolbas/Binaries/Cmdl32/
https://strontic.github.io/xcyclopedia/library/cmdl32.exe-FA1D5B8802FFF4A85B6F52A52C871BBB.html

Pinned Atomic procedure · d239772b-88e2-4a2e-8473-897503401bcc · windows · command_prompt.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • Path_to_file: Path to the Batch script (type path; source default PathToAtomicsFolder\T1105\src\T1105.bat)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

1 prerequisite definitions:

  • #{Path_to_file} must exist on system.
certutil download (urlcache)

Use certutil -urlcache argument to download a file from the web. Note - /urlcache also works!

Pinned Atomic procedure · dd3b61dd-7bbc-48cd-ab51-49ad1a776df0 · windows · command_prompt.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_file: URL of file to copy (type url; source default https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt)
  • local_path: Local path to place file (type path; source default Atomic-license.txt)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

Lolbas replace.exe use to copy UNC file

Copy UNC file to destination
Reference: https://lolbas-project.github.io/lolbas/Binaries/Replace/

Pinned Atomic procedure · ed0335ac-0354-400c-8148-f6151d20035a · windows · command_prompt.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • replace_cab: UNC Path to the cab file (type path; source default \\127.0.0.1\c$\AtomicRedTeam\atomics\T1105\src\redcanary.cab)
  • Path_replace: Path to replace.exe (type path; source default C:\Windows\System32\replace.exe)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

sftp remote file copy (push)

Utilize sftp to perform a remote file copy (push)

Pinned Atomic procedure · f564c297-7978-4aa9-b37a-d90477feea4e · linux, macos · bash.

Elevation: not declared required. Cleanup: not declared. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_path: Remote path to receive sftp (type path; source default /tmp/victim-files/)
  • local_file: Path of file to copy (type path; source default /tmp/adversary-sftp)
  • remote_host: Remote host to copy toward (type string; source default victim-host)
  • username: User account to authenticate on remote host (type string; source default victim)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

svchost writing a file to a UNC path

svchost.exe writing a non-Microsoft Office file to a file with a UNC path.
Upon successful execution, this will rename cmd.exe as svchost.exe and move it to `c:\`, then execute svchost.exe with output to a txt file.

Pinned Atomic procedure · fa5a2759-41d7-4e13-a19c-e8f28a53566f · windows · command_prompt.

Elevation: required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

No input arguments declared.

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

certutil download (verifyctl)

Use certutil -verifyctl argument to download a file from the web. Note - /verifyctl also works!

Pinned Atomic procedure · ffd492e3-0455-4518-9fb1-46527c9f241b · windows · powershell.

Elevation: not declared required. Cleanup: defined upstream; review required. This is source documentation, not an execution approval.

Source-defined inputs

  • remote_file: URL of file to copy (type url; source default https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/LICENSE.txt)
  • local_path: Local path to place file (type path; source default Atomic-license.txt)

Review the upstream command, dependencies and cleanup at the source link. Source defaults may refer to real infrastructure or destructive actions; they are not authorized targets. No automatic install, prerequisite download or command execution is provided.

Technique-specific experiment contract

  1. Choose one procedure implementing T1105 Ingress Tool Transfer; identify the observable behavior in the source definition, not just its tactic.
  2. Record exact target, tool/version, inputs, privileges, network limits and approval. Never run an imported default target automatically.
  3. Enable the collection sources above and verify a benign baseline reaches the detector.
  4. Run only the approved isolated scenario; capture native events and an independent behavior observable.
  5. Evaluate the exact rule/model, restore the lab, and preserve configuration, event hashes, alerts, controls and misses.

Synthetic logs and offline contract check

Download synthetic collection fixture (JSON) · Download the complete engineering workbook

This fixture exercises the listed collection fields. It does not reproduce Ingress Tool Transfer, label its example events as malicious, or measure detection effectiveness. Use the exact analytic and selected procedure to build an independently labelled behavior-positive dataset.

Not run in this browser. No network scan or attack command is executed by this control.

Validation status and remaining work

Source identity
Joined by exact technique/object IDs against hash-pinned sources.
Collection fixture
Available for offline schema exercises; not attack emulation.
Native telemetry / backend / real attack
Not validated for these imported procedures. Source fidelity and page tests cannot establish sensor or detector effectiveness.

All-page audit and evidence inventory · This page’s machine-readable workbook

Sources and evidence boundaries

Pinned MITRE STIX source · SHA-256 dc1639caa5501d720e280cf1cbd8fbe009884a0c9b3e6e9ed9d0c25166c3d8f4. Definition and procedure context are reproduced from this snapshot, not independently re-investigated incidents.

Source-linked mitigations
  • M1031 Network Intrusion Prevention

    Network intrusion detection and prevention systems that use network signatures to identify traffic for specific adversary malware or unusual data transfer over known protocols like FTP can be used to mitigate activity at the network level. Signatures are often for unique indicators within protocols and may be based on the specific obfuscation technique used by a particular adversary or tool, and will likely be different across various malware families and versions. Adversaries will likely change tool C2 signatures over time or construct protocols in such a way as to avoid detection by common defensive tools.[University of Birmingham C2]

  • M1037 Filter Network Traffic

    Use network filtering to block outbound traffic from compromised systems to unapproved external destinations. Restricting access to known, trusted IP addresses and protocols can prevent attackers from downloading malicious tools or payloads onto compromised servers after gaining initial access.

Connected ecosystem references

Linked tags

Source procedure platform / method / executor tags:

Detection and collection

T1105 detection workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing research

Threat Matrix: knowledge routes, evidence and actor context

Pinned research references. No browser attack runner or production-validated detector is asserted. Imported procedures remain unvalidated; any bounded lab evidence has its own scope. ATT&CK / Atomic provenance · Detection provenance.