T1127.003sub-technique of T1127 Trusted Developer Utilities Proxy Execution
JamPlus
Windowsnothing on this site yetT1127.003 on attack.mitre.org
Adversaries may use `JamPlus` to proxy the execution of a malicious script. `JamPlus` is a build utility tool for code and data build systems. It works with several popular compilers and can be used for generating workspaces in code editors such as Visual Studio. Adversaries may abuse the `JamPlus` build utility to execute malicious scripts via a `.jam` file, which describes the build process and required dependencies.
If this is happening now
Checklists and playbooks to open while the alert is still live.
Playbook for this stage
Suspicious execution on an endpoint
An EDR alert, an unexplained process, or a user reporting something odd.
how MITRE says to see it
Behavior-chain detection strategy for T1127.003 Trusted Developer Utilities Proxy Execution: JamPlus (Windows)
- Abuse of JamPlus.exe to launch malicious payloads via crafted.jam files, resulting in abnormal process creation, command execution, or artifact generation outside of standard development workflows.