T1588.002sub-technique of T1588 Obtain Capabilities

Tool

PREnothing on this site yetT1588.002 on attack.mitre.org

Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A tool can be used for malicious purposes by an adversary, but (unlike malware) were not intended to be used for those purposes (ex: PsExec). Adversaries may obtain tools to support their operations, including to support execution of post-compromise behaviors.

MITRE ATT&CK 19.2, retrieved 2026-09-12

how MITRE says to see it

Detection of Tool

  • Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information.

what reduces it

  • M1056 Pre-compromise. This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.

the rest of T1588

The description, detection analytics and mitigations are reproduced from MITRE ATT&CK, version 19.2, under its terms of use. The checklists, hunts, labs and everything else linked here are this site’s.