mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
1.7 KiB
1.7 KiB
title, last_modified_at, toc, tags
| title | last_modified_at | toc | tags | ||||
|---|---|---|---|---|---|---|---|
| Ingress Tool Transfer | 2021-03-24 | true |
|
Description
Adversaries may transfer tools or other files from an external system into a compromised environment. Files may be copied from an external adversary controlled system through the command and control channel to bring tools into the victim network or through alternate protocols with another tool such as FTP.
- ID: b3782036-8cbd-11eb-9d8e-acde48001122
- Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel: Endpoint
- Last Updated: 2021-03-24
- Author: Michael Haag, Splunk
Detection profiles
| Name | Technique | Type |
|---|---|---|
| Any Powershell DownloadFile | None | TTP |
| Any Powershell DownloadString | None | TTP |
| BITSAdmin Download File | None | TTP |
| CertUtil Download With URLCache and Split Arguments | None | TTP |
| CertUtil Download With VerifyCtl and Split Arguments | None | TTP |
| Suspicious Curl Network Connection | None | TTP |
Reference
source | version: 1