Lateral Tool Transfer T1570

Tactic: Lateral Movement

Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.

Events covered

19 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 47 rules share fields, values, and exclusions.

Fields filtered most (60 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine14contains 6, regex_match 5, wildcard 3, eq 1(?i)((\.exe(")?(\s+|\s+\/c)\s+)|(psexec.{1,}))|("{1,})?\x..., (?i)(esentutl|\.exe)"?\s.*\/y\s.*\/d\s, copy, cp , move
EventID12eq 11, in 14688, 1, 4103, 4104, 4625
host.os.type11eq 11
event.type9eq 8, in 3start, creation, change
process_name8eq 4, in 4, starts_with 1cmd.exe, ftp, scp, bash, bitsadmin.exe
EventType6eq 5, in 1creation, exec, ProcessRollup2, exec_event
Image6ends_with 4, contains 1, wildcard 1/rsync, /scp, /sftp, \bitsadmin.exe, \comodo\endpoint manager\itsmservice.exe
TargetFilename6starts_with 3, ends_with 2, contains 1, wildcard 1/dev/shm/, .7z, .bat, .cmd, .key
process_id4eq 44
Authorization3contains 3virtualmachines
Type3eq 3
azure_ad::operation_name_value3eq 3microsoft.compute/virtualmachines/runcommand/action
event.category3eq 3file
file.extension3eq 2, in 1com, bat, bmp, cmd, exe
list_ActivityStatusValue3contains 3succeeded, success

Top indicator values (231 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
81078
EventIDeq
4688
5317
EventIDeq
1
3241
EventIDeq
4103
2105
EventIDeq
4104
2269
process_ideq
4
419
Authorizationcontains
virtualmachines
33
EventTypeeq
creation
358
EventTypeeq
exec
2576
azure_ad::operation_name_valueeq
microsoft.compute/virtualmachines/runcommand/action
34
event.categoryeq
file
343
event.typein
change
320
event.typein
creation
319
list_ActivityStatusValuecontains
succeeded
33
list_ActivityStatusValuecontains
success
33
ActionUncommonlyPerformedByUsereq
True
22
CommandLineregex_match
(?i)((\.exe(")?(\s+|\s+\/c)\s+)|(psexec.{1,}))|("{1,})?\x5c\x5c.{2,}
22
CommandLineregex_match
(?i)(esentutl|\.exe)"?\s.*\/y\s.*\/d\s
22
StartTimege
UEBAWindowStart
22
StartTimele
UEBAWindowEnd
22
TargetFilenamestarts_with
/dev/shm/
211
aws::eventSourceeq
Azure AD
22
file.Ext.header_bytesstarts_with
4d5a
246
file.extensioneq
com
216
file.extensioneq
exe
232
file.extensioneq
pif
218
file.extensioneq
scr
217
process_nameeq
cmd.exe
2121
process_nameeq
powershell.exe
2184
process_namein
ftp
25

Exclusions (68 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Processeq
known_processes
2
TargetFilenamestarts_with
/var/tmp/ansible-tmp-
2
CommandLinecontains
127.0.0.1
1
CommandLinecontains
auditpol
1
CommandLinecontains
batch
1
CommandLinecontains
illusive
1
CommandLinecontains
localhost
1
CommandLinecontains
rebootrequired
1
CommandLinecontains
script
1
CommandLinecontains
scripts
1
Imageeq
?:\docusnap 11\bin\psexec.exe
1
Imageeq
?:\program files\docusnap x\bin\psexec.exe
1
Imageeq
?:\program files\docusnap x\tools\dsdns.exe
1
Imageeq
?:\programdata\docusnap\discovery\discovery\plugins\17\bin\psexec.exe
1
Imagewildcard
?:\sms_*\srvboot.exe
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 10 rules

Elastic 17 rules

Splunk 10 rules

Kusto 9 rules

YARA-L 1 rule