Files
splunk-security_content/docs/_stories/ingress_tool_transfer.md
T
2021-09-20 20:45:22 -04:00

1.7 KiB

title, last_modified_at, toc, tags
title last_modified_at toc tags
Ingress Tool Transfer 2021-03-24 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Endpoint

Description

Adversaries may transfer tools or other files from an external system into a compromised environment. Files may be copied from an external adversary controlled system through the command and control channel to bring tools into the victim network or through alternate protocols with another tool such as FTP.

  • ID: b3782036-8cbd-11eb-9d8e-acde48001122
  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Endpoint
  • Last Updated: 2021-03-24
  • Author: Michael Haag, Splunk

Detection profiles

Name Technique Type
Any Powershell DownloadFile None TTP
Any Powershell DownloadString None TTP
BITSAdmin Download File None TTP
CertUtil Download With URLCache and Split Arguments None TTP
CertUtil Download With VerifyCtl and Split Arguments None TTP
Suspicious Curl Network Connection None TTP

Reference

source | version: 1