Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0585 — Behavior-chain detection strategy for T1127.003 Trusted Developer Utilities Proxy Execution: JamPlus (Windows)
DET0585

Behavior-chain detection strategy for T1127.003 Trusted Developer Utilities Proxy Execution: JamPlus (Windows)

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1610 Analytic 1610
Windows

Abuse of JamPlus.exe to launch malicious payloads via crafted .jam files, resulting in abnormal process creation, command execution, or artifact generation outside of standard development workflows.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=11 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:Microsoft-Windows-CodeIntegrity/Operational Unsigned or untrusted modules loaded during JamPlus.exe runtime
[TimeWindow] Correlation time window (e.g., 0–30 minutes) for JamPlus.exe execution, child processes, and file/network events.
[AllowedBuildHosts] Known developer systems where JamPlus.exe usage is expected; alerts are raised if executed elsewhere.
[SuspiciousChildList] Child processes considered anomalous (e.g., PowerShell, cmd, wscript) when spawned by JamPlus.exe.
[RarePathRegex] Regex patterns for non-standard or user-writable paths where JamPlus.exe drops artifacts.

Detected Techniques

1

Details

MITRE ID
DET0585
STIX ID
x-mitre-detection-strategy--680956cb-d8c6-447c-99b4-82865fb89255
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.