{"id":"T1587.001","name":"Malware","url":"https://attack.mitre.org/techniques/T1587/001","tactics":["resource-development"],"platforms":["PRE"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0872","stix_id":"x-mitre-detection-strategy--04f78d17-4599-4ecd-9a8f-f221ab2759cc","name":"Detection of Malware","url":"https://attack.mitre.org/detectionstrategies/DET0872","analytics":[{"id":"AN2004","stix_id":"x-mitre-analytic--2a3b0030-05b4-4b85-a33c-dda07472f31f","name":"Analytic 2004","description":"Consider analyzing malware for features that may be associated with the adversary and/or their developers, such as compiler used, debugging artifacts, or code similarities. Malware repositories can also be used to identify additional samples associated with the adversary and identify development patterns over time.\nMonitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle.","url":"https://attack.mitre.org/detectionstrategies/DET0872#AN2004","platforms":["PRE"],"log_source_references":[{"name":"Malware Repository","channel":"None","data_component":"DC0011","data_component_name":"Malware Content","log_source_slug":"malware-repository"},{"name":"Malware Repository","channel":"None","data_component":"DC0003","data_component_name":"Malware Metadata","log_source_slug":"malware-repository"}],"mutable_elements":[],"live":true,"detection_strategies":["DET0872"],"techniques":["T1587.001"]}],"live":true,"version":"1.0","techniques":["T1587.001"]}],"sigma_rules":[{"id":"032f5fb3-d959-41a5-9263-4173c802dc2b","title":"Formbook Process Creation","author":"Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro","status":"test","level":"high","date":"2019-09-30","modified":"2022-10-06","description":"Detects Formbook like process executions that inject code into a set of files in the System32 folder, which executes a special command command line to delete the dropper from the AppData Temp folder. We avoid false positives by excluding all parent process with command line parameters.","references":["https://inquest.net/blog/2018/06/22/a-look-at-formbook-stealer","https://app.any.run/tasks/388d5802-aa48-4826-b069-250420504758/","https://app.any.run/tasks/8e22486b-5edc-4cef-821c-373e945f296c/","https://app.any.run/tasks/62bb01ae-25a4-4180-b278-8e464a90b8d7/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.resource-development","attack.t1587.001","detection.emerging-threats"],"path":"rules-emerging-threats/2019/Malware/Formbook/proc_creation_win_malware_formbook.yml","techniques":["T1587.001"],"cves":[]},{"id":"207b0396-3689-42d9-8399-4222658efc99","title":"Potential Privilege Escalation To LOCAL SYSTEM","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2021-05-22","modified":"2024-03-05","description":"Detects unknown program using commandline flags usually used by tools such as PsExec and PAExec to start programs with SYSTEM Privileges","references":["https://learn.microsoft.com/en-us/sysinternals/downloads/psexec","https://www.poweradmin.com/paexec/","https://www.fireeye.com/blog/threat-research/2020/10/kegtap-and-singlemalt-with-a-ransomware-chaser.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.resource-development","attack.t1587.001"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_susp_psexec_paexec_flags.yml","techniques":["T1587.001"],"cves":[]},{"id":"297afac9-5d02-4138-8c58-b977bac60556","title":"Creation of an Executable by an Executable","author":"frack113","status":"test","level":"low","date":"2022-03-09","modified":"2025-02-24","description":"Detects the creation of an executable by another executable.","references":["Internal Research"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.resource-development","attack.t1587.001","detection.threat-hunting"],"path":"rules-threat-hunting/windows/file/file_event/file_event_win_susp_binary_dropper.yml","techniques":["T1587.001"],"cves":[]},{"id":"2d87d610-d760-45ee-a7e6-7a6f2a65de00","title":"Mustang Panda Dropper","author":"Florian Roth (Nextron Systems), oscd.community","status":"test","level":"high","date":"2019-10-30","modified":"2021-11-27","description":"Detects specific process parameters as used by Mustang Panda droppers","references":["https://app.any.run/tasks/7ca5661d-a67b-43ec-98c1-dd7a8103c256/","https://app.any.run/tasks/b12cccf3-1c22-4e28-9d3e-c7a6062f3914/","https://www.anomali.com/blog/china-based-apt-mustang-panda-targets-minority-groups-public-and-private-sector-organizations"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.t1587.001","attack.resource-development","detection.emerging-threats"],"path":"rules-emerging-threats/2019/TA/MustangPanda/proc_creation_win_apt_mustangpanda.yml","techniques":["T1587.001"],"cves":[]},{"id":"550d3350-bb8a-4ff3-9533-2ba533f4a1c0","title":"ProxyLogon MSExchange OabVirtualDirectory","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2021-08-09","modified":"2023-01-23","description":"Detects specific patterns found after a successful ProxyLogon exploitation in relation to a Commandlet invocation of Set-OabVirtualDirectory","references":["https://bi-zone.medium.com/hunting-down-ms-exchange-attacks-part-1-proxylogon-cve-2021-26855-26858-27065-26857-6e885c5f197c"],"logsource":{"product":"windows","service":"msexchange-management"},"tags":["attack.t1587.001","attack.resource-development"],"path":"rules/windows/builtin/msexchange/win_exchange_proxylogon_oabvirtualdir.yml","techniques":["T1587.001"],"cves":[]},{"id":"7b30e0a7-c675-4b24-8a46-82fa67e2433d","title":"Conti Volume Shadow Listing","author":"Max Altgelt (Nextron Systems), Tobias Michalski (Nextron Systems)","status":"test","level":"high","date":"2021-08-09","modified":null,"description":"Detects a command used by conti to find volume shadow backups","references":["https://twitter.com/vxunderground/status/1423336151860002816?s=20","https://www.virustotal.com/gui/file/03e9b8c2e86d6db450e5eceec057d7e369ee2389b9daecaf06331a95410aa5f8/detection"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.t1587.001","attack.resource-development","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Malware/Conti/proc_creation_win_malware_conti.yml","techniques":["T1587.001"],"cves":[]},{"id":"8468111a-ef07-4654-903b-b863a80bbc95","title":"VHD Image Download Via Browser","author":"frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io'","status":"test","level":"medium","date":"2021-10-25","modified":"2023-05-05","description":"Detects creation of \".vhd\"/\".vhdx\" files by browser processes.\nMalware can use mountable Virtual Hard Disk \".vhd\" files to encapsulate payloads and evade security controls.\n","references":["https://redcanary.com/blog/intelligence-insights-october-2021/","https://www.kaspersky.com/blog/lazarus-vhd-ransomware/36559/","https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.resource-development","attack.t1587.001"],"path":"rules/windows/file/file_event/file_event_win_vhd_download_via_browsers.yml","techniques":["T1587.001"],"cves":[]},{"id":"8834e2f7-6b4b-4f09-8906-d2276470ee23","title":"PsExec/PAExec Escalation to LOCAL SYSTEM","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2021-11-23","modified":"2024-03-05","description":"Detects suspicious commandline flags used by PsExec and PAExec to escalate a command line to LOCAL_SYSTEM rights","references":["https://learn.microsoft.com/en-us/sysinternals/downloads/psexec","https://www.poweradmin.com/paexec/","https://www.fireeye.com/blog/threat-research/2020/10/kegtap-and-singlemalt-with-a-ransomware-chaser.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.resource-development","attack.t1587.001"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_psexec_paexec_escalate_system.yml","techniques":["T1587.001"],"cves":[]},{"id":"a10a2c40-2c4d-49f8-b557-1a946bc55d9d","title":"Uncommon File Created In Office Startup Folder","author":"frack113, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-06-05","modified":"2023-12-13","description":"Detects the creation of a file with an uncommon extension in an Office application startup folder","references":["https://app.any.run/tasks/d6fe6624-6ef8-485d-aa75-3d1bdda2a08c/","http://addbalance.com/word/startup.htm","https://answers.microsoft.com/en-us/msoffice/forum/all/document-in-word-startup-folder-doesnt-open-when/44ab0932-2917-4150-8cdc-2f2cf39e86f3","https://en.wikipedia.org/wiki/List_of_Microsoft_Office_filename_extensions"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.resource-development","attack.t1587.001"],"path":"rules/windows/file/file_event/file_event_win_office_uncommon_file_startup.yml","techniques":["T1587.001"],"cves":[]},{"id":"d08a2711-ee8b-4323-bdec-b7d85e892b31","title":"PUA - CsExec Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-08-22","modified":"2023-02-21","description":"Detects the use of the lesser known remote execution tool named CsExec a PsExec alternative","references":["https://github.com/malcomvetter/CSExec","https://www.microsoft.com/security/blog/2022/05/09/ransomware-as-a-service-understanding-the-cybercrime-gig-economy-and-how-to-protect-yourself/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.resource-development","attack.t1587.001","attack.execution","attack.t1569.002"],"path":"rules/windows/process_creation/proc_creation_win_pua_csexec.yml","techniques":["T1587.001","T1569.002"],"cves":[]},{"id":"ea011323-7045-460b-b2d7-0f7442ea6b38","title":"Potential PsExec Remote Execution","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-02-28","modified":"2025-09-01","description":"Detects potential psexec command that initiate execution on a remote systems via common commandline flags used by the utility","references":["https://learn.microsoft.com/en-us/sysinternals/downloads/psexec","https://www.poweradmin.com/paexec/","https://www.fireeye.com/blog/threat-research/2020/10/kegtap-and-singlemalt-with-a-ransomware-chaser.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.resource-development","attack.t1587.001"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_psexec_remote_execution.yml","techniques":["T1587.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}