Software Deployment Tools T1072

Tactics: Execution, Lateral Movement

Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager.

Events covered

10 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 30 rules share fields, values, and exclusions.

Fields filtered most (33 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
action6eq 4, in 2completed, assigned, closed, converted_to_draft, edited
operationName6contains 5, in 1 devicemanagementconfigurationpolicy, DeviceComplianceScript, DeviceManagementScript, create mobileapp, devicehealthscript
process_name5eq 2, in 2, regex_match 2(?i)radmin, apk, apt, apt-get, curl
CommandLine4contains 2, regex_match 2(?i)\/connect\:.*?\:, /scomma , /stext , https://jamf.
OriginalFileName4eq 4csi.exe, pdqdeployconsole.exe, psexec.c, radmin.exe, rcsi.exe
sourcetype4eq 4azure:monitor:activity
EventID3eq 34688, 1
EventType3eq 3exec, integration_installation.create
Image3contains 1, ends_with 1, starts_with 1?:\windows\softwaredistribution\download\install\, \csi.exe, \device\harddiskvolume?\windows\softwaredistribution\down..., \rcsi.exe, policies\{31b2f340-016d-11d2-945f-00c04fb984f9}
event.type3eq 3start
host.os.type3eq 3
Company2eq 2microsoft corporation, pdq.com
Description2eq 2pdq deploy console, radmin viewer
Product2eq 2pdq deploy, radmin viewer
parent_process_name2eq 1, in 1, starts_with 1node, osascript, perl, wuauclt.exe

Top indicator values (113 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
sourcetypeeq
azure:monitor:activity
45
actioneq
completed
34
event.typeeq
start
31078
CommandLineregex_match
(?i)\/connect\:.*?\:
22
EventIDeq
4688
2317
EventIDeq
1
1241
EventTypeeq
exec
2576
EventTypeeq
integration_installation.create
1
actionin
edited
23
actionin
opened
22
process_nameregex_match
(?i)radmin
22
CommandLinecontains
/scomma
1
CommandLinecontains
/stext
1
CommandLinecontains
https://jamf.
1
Companyeq
microsoft corporation
12
Companyeq
pdq.com
1
Descriptioneq
pdq deploy console
1
Descriptioneq
radmin viewer
1
Imagecontains
policies\{31b2f340-016d-11d2-945f-00c04fb984f9}
1
Imagecontains
policies\{6ac1786c-016f-11d2-945f-00c04fb984f9}
1
Imageends_with
\csi.exe
12
Imageends_with
\rcsi.exe
1
Imagestarts_with
?:\windows\softwaredistribution\download\install\
1
Imagestarts_with
\device\harddiskvolume?\windows\softwaredistribution\download\install\
1
Messagecontains
malware
1
OperationNameeq
release.releasepipelinecreated
1
OperationNameeq
release.releasepipelinedeleted
1
OriginalFileNameeq
csi.exe
12
OriginalFileNameeq
pdqdeployconsole.exe
1
OriginalFileNameeq
psexec.c
17

Exclusions (3 distinct)

These values appear most often in top-level exclusions.

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 4 rules

Elastic 4 rules

Splunk 7 rules

Kusto 4 rules

Panther 11 rules