{"id":"T1608","name":"Stage Capabilities","url":"https://attack.mitre.org/techniques/T1608","tactics":["resource-development"],"platforms":["PRE"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0839","stix_id":"x-mitre-detection-strategy--5a1ada5b-5729-45d5-8b3d-f6fa7d2a3352","name":"Detection of Stage Capabilities","url":"https://attack.mitre.org/detectionstrategies/DET0839","analytics":[{"id":"AN1971","stix_id":"x-mitre-analytic--1fec971d-c822-4819-9489-8c27857e3481","name":"Analytic 1971","description":"If infrastructure or patterns in malware, tooling, certificates, or malicious web content have been previously identified, internet scanning may uncover when an adversary has staged their capabilities.\nMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as initial access and post-compromise behaviors.","url":"https://attack.mitre.org/detectionstrategies/DET0839#AN1971","platforms":["PRE"],"log_source_references":[{"name":"Internet Scan","channel":"None","data_component":"DC0104","data_component_name":"Response Content","log_source_slug":"internet-scan"}],"mutable_elements":[],"live":true,"detection_strategies":["DET0839"],"techniques":["T1608"]}],"live":true,"version":"1.0","techniques":["T1608"]}],"sigma_rules":[{"id":"00d49ed5-4491-4271-a8db-650a4ef6f8c1","title":"Suspicious Download from Office Domain","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2021-12-27","modified":"2022-08-02","description":"Detects suspicious ways to download files from Microsoft domains that are used to store attachments in Emails or OneNote documents","references":["https://twitter.com/an0n_r0/status/1474698356635193346?s=12","https://twitter.com/mrd0x/status/1475085452784844803?s=12"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.resource-development","attack.t1105","attack.t1608"],"path":"rules/windows/process_creation/proc_creation_win_susp_download_office_domain.yml","techniques":["T1105","T1608"],"cves":[]},{"id":"ac8866c7-ce44-46fd-8c17-b24acff96ca8","title":"HybridConnectionManager Service Installation - Registry","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)","status":"test","level":"high","date":"2021-04-12","modified":"2022-11-27","description":"Detects the installation of the Azure Hybrid Connection Manager service to allow remote code execution from Azure function.","references":["https://twitter.com/Cyb3rWard0g/status/1381642789369286662"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.resource-development","attack.t1608"],"path":"rules/windows/registry/registry_event/registry_event_hybridconnectionmgr_svc_installation.yml","techniques":["T1608"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}