Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0853 — Detection of Develop Capabilities
DET0853

Detection of Develop Capabilities

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1985 Analytic 1985
PRE

Consider analyzing malware for features that may be associated with the adversary and/or their developers, such as compiler used, debugging artifacts, or code similarities. Malware repositories can also be used to identify additional samples associated with the adversary and identify development patterns over time. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control. Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control. Consider use of services that may aid in the tracking of capabilities, such as certificates, in use on sites across the Internet. In some cases it may be possible to pivot on known pieces of information to uncover other adversary infrastructure.(Citation: Splunk Kovar Certificates 2017) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control.

Malware Repository None Malware Repository None Internet Scan None

Detected Techniques

1

Resource Development (1)

Details

MITRE ID
DET0853
STIX ID
x-mitre-detection-strategy--7ad9b54d-cd23-4ec3-a5b2-db5e58e82a02
Analytics
1
Techniques Detected
1
By Tactic
Resource Development
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.