Ingress Tool Transfer T1105

Tactic: Command & Control

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Events covered

31 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 339 rules share fields, values, and exclusions.

Fields filtered most (147 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine146contains 92, regex_match 39, in 13, wildcard 9, ends_with 3, eq 2, match 2, is_not_null 1, is_null 1, starts_with 1http, /create , %appdata%, -o, /addfile
process_name146eq 70, in 58, regex_match 15, wildcard 10, starts_with 8, ends_with 1curl, nscurl, bash, certutil.exe, wget
EventType102eq 87, in 16, ne 6exec, start, modification, deletion, creation
Image94ends_with 64, starts_with 13, eq 10, contains 9, regex_match 8, wildcard 7, in 1\curl.exe, /curl, \bitsadmin.exe, \certutil.exe, \brave.exe
event.type88eq 87, in 1start, creation, process_started
process.args63eq 33, starts_with 17, wildcard 14, in 12, contains 6, is_not_null 4, regex_match 3, ends_with 2-c, --output, curl, http, nscurl
EventID61eq 60, in 14688, 1, 4104, 4103, 11
host.os.type49eq 48, in 1
parent_process_name46eq 27, in 14, wildcard 4, regex_match 2, starts_with 2bash, cmd.exe, explorer.exe, osascript, conhost.exe
OriginalFileName41eq 41certutil.exe, bitsadmin.exe, powershell.exe, certreq.exe, powershell_ise.exe
TargetFilename27starts_with 9, wildcard 6, contains 5, ends_with 4, eq 2, regex_match 1/tmp/, /private/tmp/, /private/var/tmp/, /dev/shm/, /dev/shm/*
file.Ext.header_bytes18starts_with 18, wildcard 1cafebabe, cffaedfe, 4d5a, 3c736372697074206c616e6775616765, 406563686F
Type16eq 16
file.extension15eq 10, in 5cmd, bat, cpl, scpt, com
process.args_count15eq 10, le 52, 3, 1, 10, 4

Top indicator values (2601 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
831078
EventTypeeq
exec
48576
EventTypeeq
start
14391
EventTypeeq
modification
1372
process_namein
curl
4389
process_namein
nscurl
2741
process_namein
bash
16202
process_namein
sh
16197
process_namein
zsh
16196
process_namein
wget
1346
CommandLinecontains
http
2052
CommandLinecontains
curl
817
EventIDeq
4688
20317
EventIDeq
1
16241
EventIDeq
4104
15269
EventIDeq
4103
10105
process.argseq
-c
13107
EventTypein
exec
11201
EventTypein
start
8163
process_nameeq
curl
1129
process_nameeq
certutil.exe
1044
process_nameeq
curl.exe
834
file.Ext.header_bytesstarts_with
cafebabe
1019
file.Ext.header_bytesstarts_with
cffaedfe
1019
file.Ext.header_bytesstarts_with
4d5a
846
Initiatedeq
true
850
OriginalFileNameeq
certutil.exe
830
parent_process_nameeq
explorer.exe
851
process.argsin
--output
811
process.argsin
-o
817

Exclusions (893 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
dest_ipcidr_match
10.0.0.0/8
11
dest_ipcidr_match
127.0.0.0/8
11
dest_ipcidr_match
169.254.0.0/16
11
dest_ipcidr_match
172.16.0.0/12
11
dest_ipcidr_match
192.168.0.0/16
11
dest_ipcidr_match
100.64.0.0/10
10
dest_ipcidr_match
192.0.0.0/24
10
dest_ipcidr_match
192.0.2.0/24
10
dest_ipcidr_match
192.175.48.0/24
10
dest_ipcidr_match
192.31.196.0/24
10
dest_ipcidr_match
192.52.193.0/24
10
dest_ipcidr_match
192.88.99.0/24
10
dest_ipcidr_match
198.18.0.0/15
10
dest_ipcidr_match
198.51.100.0/24
10
dest_ipcidr_match
203.0.113.0/24
10

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 93 rules

Elastic 132 rules

Splunk 96 rules

Kusto 10 rules

YARA-L 8 rules