FORENSIA

ATT&CK · T1588.002 · sub-technique

Tool

Tactics: resource-development

About

Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A tool can be used for malicious purposes by an adversary, but (unlike malware) were not intended to be used for those purposes (ex: PsExec). Adversaries may obtain tools to support their operations, including to support execution of post-compromise behaviors. Tools may also be leveraged for testing – for example, evaluating malware against commercial antivirus or endpoint detection and response (EDR) applications. Tool acquisition may involve the procurement of commercial software licenses, including for red teaming tools such as Cobalt Strike. In addition to freely downloading or purchasing software, adversaries may steal software and/or software licenses from third-party entities (including other adversaries). Threat actors may also crack trial versions of software.

Corpus indicators tagged with this technique

579 indicators in the corpus carry T1588.002.

IndicatorTypeFamilySevSrc
293814692f1c814205e99a50162d8db36b8b69378c1e56309bdca87ae41c6d07sha256phishing801
223785a6fdd9d77758ee9c28874419ac3289f830b8c57ba3b361b5b868f8fba6sha256phishing801
25d305f969d02d6e4317edef3e59aa3d9dba14eb054dfe5de6b2d101bb5331c1sha256phishing801
288f7170251fed0c67e17ea3f865e95e2ef8829512d4e90606977266fb911a7dsha256phishing801
19c2f1069f50a390d18b873b2a8c267014131ab945724836cda470d1aad714a2sha256phishing801
21cad6385ffe3d0981a9ac73a83d605e20331a3d1b7649c1dc5daa401da55bc7sha256phishing801
189a3fe5085f5426107ec0d7395719bc3c974217e591c01728529377fa7982a9sha256phishing801
24fa269ad2f8cc2eb9b71465a80a0856ed5d0ceb43d7c2a341d2e45fb3fed51esha256phishing801
0683b208fa3cf96e355ded36455491e3664bf2d4523253ee6dee2476dd6e774asha256phishing801
0528706a4e2fbcc58dfe476c4fa1b863e054b7af46ceb309c340a45140f7be14sha256phishing801
151f9d488e1479d67e5e1561aa79b1cdf29e2cd6626b04ed897fbf5bc4d2150fsha256phishing801
0c2edbcf0aca28290cea238fe9c11d2174aa567c5b085cae43e94c2747c2fd49sha256phishing801
1a5276bafbf007f33daf93d5272df25214607bd6407906408c8e308165a6b61esha256phishing801
2052302dca8ec7c594d898a4dc56dd1735816db88dc323b3235fe1436b431dfasha256phishing801
11d838bf89f0c6b803455daa94888100a53d605f563bb6f853a049abadc5085fsha256phishing801
0713b460e85c28d59078e00317dff192d2976c41692cbc46e240c038dae0d67esha256phishing801
1900068a5188a239af2a4319700b1642041ab3d7b3ee9865abe73059164c4431sha256phishing801
2409b8faf363e25fda6c8a165d396225b2937a45ca11a6ec806dd4a8bb986959sha256phishing801
238df253ffd9f45faf5f503210116abad556fbbfd27c7584e9ad040201acb553sha256phishing801
01ecb631280cbfaaac33f9cb829d0d93f58aeb5b33513e3a320e4d1cd0e10a03sha256phishing801
0274104d21dfb3f035b980d03f9d750924f6c24367177c9b20c863c2ffd777f1sha256phishing801
0fed75220d0d5eb4e98c4962734fd9acc2df1e3d328874915a2161a59fccef45sha256phishing801
08c73750aa50c53174613e70ff17fdbd9b1e2965490f871141a085f365f7acd6sha256phishing801
0d6b8bfcd5017927e511329f2abad2a944ea59c9074771c1f73ca84c2e558347sha256phishing801
0a2c3bf5422867f5204b8853f3b4d8383b014dbaedb624d7f774d9191f641697sha256phishing801
11891ddcf6e2f14ab9bda83da5cbad5e401c69b9e88810efeafa65d6f9e1d88bsha256phishing801
0f49587d33d8090f097418ceb0361c9351714c599b3acd7d98603dcfcfef37d1sha256phishing801
128fdd44526c4e3102421425c23e3c5a5bf49f38eb13a98eea8b08817df2a47esha256phishing801
1c36f24ca62a4165d9ed531bc95f3556f39a3e543034cb8ad0f10a0595a3fd14sha256phishing801
2a546dc2a96b73aeeec9fef036c620291e480251d3735707ff87a3baf164b86esha256phishing801

Showing the top 30 by severity of 579.