Stage Capabilities T1608
Tactic: Resource Development
Adversaries may upload, install, or otherwise set up capabilities that can be used during targeting. To support their operations, an adversary may need to take capabilities they developed (Develop Capabilities) or obtained (Obtain Capabilities) and stage them on infrastructure under their control. These capabilities may be staged on infrastructure that was previously purchased/rented by the adversary (Acquire Infrastructure) or was otherwise compromised by them (Compromise Infrastructure). Capabilities may also be staged on web services, such as GitHub or Pastebin, or on Platform-as-a-Service (PaaS) offerings that enable users to easily provision applications.
Events covered
8 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Sysmon | Event ID 11 | FileCreate |
| Sysmon | Event ID 12 | RegistryEvent (Object create and delete) |
| Sysmon | Event ID 13 | RegistryEvent (Value Set) |
| Sysmon | Event ID 14 | RegistryEvent (Key and Value Rename) |
| Security-Auditing | Event ID 4688 | A new process has been created. |
| PowerShell | Event ID 4104 | Creating Scriptblock text (MessageNumber of MessageTotal). |
| Sysmon-for-Linux | Event ID 1 | Process Create |
Authoring guide
These 14 rules share fields, values, and exclusions.
Fields filtered most (19 distinct)
These fields appear most often in rule filters.
Top indicator values (61 distinct)
These values appear most often in rule predicates.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 3 rules
- AWS KMS Imported Key Material Usage
- HybridConnectionManager Service Installation - Registry
- Suspicious Download from Office Domain
Elastic 4 rules
- AWS SNS Topic Created by Rare User
- Azure Automation Webhook Created
- M365 OneDrive Malware File Upload
- M365 SharePoint Malware File Detected
Splunk 5 rules
- Linux Suspicious GCC Invocation Building Init Shared Object
- Windows Cobalt Strike PowerShell Loader
- Windows Metasploit Confluence Plugin Execution
- Windows NorthStar C2 Agent Execution
- Windows Unusual File Creation in Confluence Directory