Compromise Host Software Binary T1554
Tactic: Persistence
Adversaries may modify host software binaries to establish persistent access to systems. Software binaries/executables provide a wide range of system commands or services, programs, and libraries. Common software binaries are SSH clients, FTP clients, email clients, web browsers, and many other user or server applications.
Events covered
21 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 39 rules share fields, values, and exclusions.
Fields filtered most (52 distinct)
These fields appear most often in rule filters.
Top indicator values (3825 distinct)
These values appear most often in rule predicates.
Exclusions (365 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 6 rules
- DNS HybridConnectionManager Service Bus
- HybridConnectionManager Service Installation
- HybridConnectionManager Service Running
- Linux Setgid Capability Set on a Binary via Setcap Utility
- Linux Setuid Capability Set on a Binary via Setcap Utility
- TanStack Supply-Chain Attack File Creation Indicators - Windows
Elastic 20 rules
- Application Javascript Injection via Nodejs
- Deprecated - Adobe Hijack Persistence
- Potential Masquerading as Browser Process
- Potential Masquerading as Communication Apps
- Potential Masquerading as System32 DLL
- Potential Masquerading as System32 Executable
- Potential Masquerading as VLC DLL
- Potential OpenSSH Backdoor Logging Activity
- Potential Remote Code Execution via Database Server
- Potential Remote Code Execution via Mail Server
- Potential Remote Code Execution via URL Encoded Payload
- Potential SSH Password Grabbing via strace
- Renaming of OpenSSH Binaries
- Sublime Plugin or Application Script Modification
- Suspicious Communication App Child Process
- Suspicious Outlook Child Process
- Unusual Exim4 Child Process
- Unusual Process Modifying GenAI Configuration File
- Unusual SSH Parent/Child Execution
- VScode Project File Infection via Osascript
Splunk 4 rules
- Circle CI Disable Security Job
- Circle CI Disable Security Step
- GitHub Workflow File Creation or Modification
- Shai-Hulud Workflow File Creation or Modification
Kusto 9 rules
- Dynatrace - Problem detection
- Dynatrace Application Security - Code-Level runtime vulnerability detection
- Dynatrace Application Security - Non-critical runtime vulnerability detection
- Dynatrace Application Security - Third-Party runtime vulnerability detection
- GWorkspace - Unexpected OS update
- Potential Build Process Compromise
- Potential Build Process Compromise - MDE
- RecordedFuture Threat Hunting Hash All Actors
- SUNSPOT malware hashes