T1588.002sub-technique of T1588 Obtain Capabilities
Tool
PREnothing on this site yetT1588.002 on attack.mitre.org
Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A tool can be used for malicious purposes by an adversary, but (unlike malware) were not intended to be used for those purposes (ex: PsExec). Adversaries may obtain tools to support their operations, including to support execution of post-compromise behaviors.
how MITRE says to see it
Detection of Tool
- Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information.
what reduces it
- M1056 Pre-compromise. This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls.