Develop Capabilities T1587

Tactic: Resource Development

Adversaries may build capabilities that can be used during targeting. Rather than purchasing, freely downloading, or stealing capabilities, adversaries may develop their own capabilities in-house. This is the process of identifying development requirements and building solutions such as malware, exploits, and self-signed certificates. Adversaries may develop capabilities to support their operations throughout numerous phases of the adversary lifecycle.

Events covered

6 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 24 rules share fields, values, and exclusions.

Fields filtered most (26 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine9contains 9, ends_with 1, in 1, wildcard 1 -i -s cmd, -i -s powershell, -i -s pwsh, -p , -u
Image8ends_with 7, contains 4.exe, /aircrack-ng, /autorecon, /bloodhound-python, :\program files (x86)\
TargetFilename5contains 5, ends_with 3, starts_with 1.cab, .docb, .docm, .docx, .exe
EventType2eq 2*, intrusionevent
OriginalFileName2eq 2certutil.exe, purplesharp.exe
ParentCommandLine2contains 1, ends_with 1, starts_with 1.exe, @modelcontextprotocol, C:\Windows\SysWOW64\, C:\Windows\System32\, agentgpt
process_name2eq 2, in 1cargo, certutil.exe, cl.exe, clang
sourcetype2eq 2cisco:sfw:estreamer
Description1eq 1csexec
EventOriginalType1eq 1PowerAppPermissionEdited
ImageLoaded1eq 1c:\windows\adfs\version.dll
Impact1in 11, 2
InvitedId1is_not_null 1
Listingreason1is_not_null 1
Malware1is_not_null 1, ne 1None

Top indicator values (326 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
CommandLinecontains
accepteula
37
CommandLinecontains
-i -s cmd
22
CommandLinecontains
-i -s powershell
22
CommandLinecontains
-i -s pwsh
22
CommandLinecontains
-s -i cmd
22
CommandLinecontains
-s -i powershell
22
CommandLinecontains
-s -i pwsh
22
CommandLinecontains
-s cmd
22
CommandLinecontains
-s powershell
22
CommandLinecontains
-s pwsh
22
CommandLinecontains
c:\users\
27
CommandLinecontains
paexec
2
CommandLinecontains
psexec
2
CommandLinecontains
-p
111
CommandLinecontains
-u
18
CommandLinecontains
\\\\
18
CommandLinecontains
%windir:~-1,1%
1
CommandLinecontains
%windir:~-3,1%%public:~-9,1%
1
CommandLinecontains
-addstore
12
CommandLinecontains
-o
12
CommandLinecontains
.txt
19
CommandLinecontains
/c
115
CommandLinecontains
/e:vbscript
1
CommandLinecontains
/f
17
CommandLinecontains
/tn "security script
1
CommandLinecontains
\\\\127.
1
CommandLinecontains
\\\\localhost
1
Imageends_with
\winword.exe
217
TargetFilenamecontains
\appdata\local\temp\
28
sourcetypeeq
cisco:sfw:estreamer
232

Exclusions (81 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CommandLinecontains
\\\\127.
1
CommandLinecontains
\\\\localhost
1
CommandLinecontains
accepteula
1
CommandLinecontains
paexec
1
CommandLinecontains
psexec
1
Imagecontains
:\program files (x86)\
1
Imagecontains
:\program files (x86)\microsoft office\
1
Imagecontains
:\program files\
1
Imagecontains
:\program files\common files\microsoft shared\clicktorun\
1
Imagecontains
:\program files\microsoft office\
1
Imagecontains
:\program files\windows defender\
1
Imagecontains
:\programdata\microsoft\windows defender\
1
Imagecontains
:\windows\microsoft.net\framework
1
Imagecontains
:\windows\microsoft.net\framework64\
1
Imagecontains
:\windows\microsoft.net\framework\
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 17 rules

Elastic 1 rule

Splunk 3 rules

Kusto 2 rules

Panther 1 rule