Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0223 — Detection of Adversary Abuse of Software Deployment Tools
DET0223

Detection of Adversary Abuse of Software Deployment Tools

5 analytic(s) · 1 technique(s) detected

Analytics

5
AN0623 Analytic 0623
Windows

Detects SCCM, Intune, or remote push execution spawning scripts or binaries from SYSTEM context or unusual consoles (e.g., cmtrace.exe launching PowerShell or cmd.exe).

WinEventLog:Security EventCode=4688 WinEventLog:Application SCCM, Intune logs
[ParentImageList] Allowlist of known SCCM-related binary spawners (e.g., 'CCMExec.exe')
[UserContext] Expected deployment activity from scheduled system accounts
[TimeWindow] Unusual deployment timing outside standard maintenance hours
AN0624 Analytic 0624
Linux

Detects remote scripts or binaries deployed via Puppet, Chef, Ansible, or shell scripts from orchestration servers executing outside maintenance windows or in unmanaged nodes.

auditd:SYSCALL execve
[DeployingHostAllowList] Approved orchestration or jump box IPs
[ScriptExecutionBaseline] Expected scripts, interpreters, or package managers used
AN0625 Analytic 0625
macOS

Detects script or binary execution initiated via JAMF, Munki, or custom MDM agents outside of baseline, or JAMF launching new Terminal or osascript processes from remote command payloads.

macos:unifiedlog process and signing chain events macos:jamf RemoteCommandExecution
[SigningAuthorityList] Expected signing authorities for JAMF and MDM scripts
[RemoteCommandInterval] Frequency of remote execution from MDM servers
AN0626 Analytic 0626
SaaS

Detects cloud-native software deployment or management (e.g., SSM Run Command, Intune) initiating script execution on endpoints outside expected org IDs, admin groups, or maintenance windows.

AWS:CloudTrail SSM RunCommand
[IAMRoleAllowList] Approved deployment administrators or service accounts
[ExecutionTargetList] Expected endpoints targeted by SaaS deployments
AN0627 Analytic 0627
Network Devices

Detects central router or switch config management tools (e.g., FortiManager, Cisco Prime) triggering device reboots or config pushes using abnormal accounts or IPs.

networkdevice:syslog config push events NSM:Flow Device-to-Device Deployment Flows
[PushSourceAllowList] Devices or IPs allowed to push firmware or scripts
[AuthUserPattern] Expected CLI or API user performing configuration

Detected Techniques

1

Details

MITRE ID
DET0223
STIX ID
x-mitre-detection-strategy--ea1f5423-64b9-44eb-824f-251aa0faccd2
Analytics
5
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.