Techniques › T1588 › T1588.006
T1588.006 Vulnerabilities
resource development — PRE · attack.mitre.org · JSON
1
MITRE detection strategy
1
analytics
0
Sigma rules tagged attack.t1588.006
1
KEV CVEs mapped here
<p>Adversaries may acquire information about vulnerabilities that can be used during targeting. A vulnerability is a weakness in computer hardware or software that can, potentially, be exploited by an adversary to cause unintended or unanticipated behavior to occur. Adversaries may find vulnerability information by searching open databases or gaining access to closed vulnerability databases.</p><p>An adversary may monitor vulnerability disclosures/databases to understand the state of existing, as well as newly discovered, vulnerabilities. There is usually a delay between when a vulnerability is discovered and when it is made public. An adversary may target the systems of those known to conduct vulnerability research (including commercial vendors). Knowledge of a vulnerability may cause an adversary to search for an existing exploit (i.e. Exploits) or to attempt to develop one themselves (i.e. Exploits).</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2025-42599 | Qualitia Active! Mail | exploitation technique | Mapped | 2025-04-28 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0808 Detection of Vulnerabilities v1.0
AN1940 PREMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the potential use of exploits for vulnerabilities (i.e. Exploit Public-Facing Application, Exploitation for Client Execution, Exploitation for Privilege Escalation, Exploitation for Stealth, Exploitation for Credential Access, Exploitation of Remote Services, and Application or System Exploitation).
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1588.006
No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content. 1 actively exploited CVE maps here.
Rules tagged at the parent level (attack.t1588) 2
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Florian Roth (Nextron Systems), Arnim Rupp
· 2017-02-19 (modified 2024-12-25) · logsource: product=windows service=application · 78bc5783-81d9-4d73-ac97-59f6db4f72a8
Detects potentially highly relevant antivirus events in the application log based on known virus signature names and malware keywords.
Author: Florian Roth (Nextron Systems), Arnim Rupp
· 2018-09-09 (modified 2026-06-29) · logsource: category=antivirus · c9a88268-0047-4824-ba6e-4d81ce0b907c
Detects an Antivirus alert in a highly relevant file path or with a relevant file name.
This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.