Resource Development Detection Rules
The adversary is trying to establish resources they can use to support operations. Resource Development consists of techniques that involve adversaries creating, purchasing, or compromising/stealing resources that can be used to support targeting. Such resources include infrastructure, accounts, or capabilities. These resources can be leveraged by the adversary to aid in other phases of the adversary lifecycle, such as using purchased domains to support Command and Control, email accounts for phishing as a part of Initial Access, or stealing code signing certificates to help with Defense Evasion.
df00tech ships 47 production-ready detection rules mapped to the Resource Development tactic (TA0042). Each rule below includes copy-paste queries for Microsoft Sentinel (KQL), Splunk (SPL), Elastic (EQL), QRadar, Sumo Logic, Chronicle and LogScale, with data-source requirements, severity and false-positive guidance — free to use.
Resource Development detections (47)
- T1583 Acquire Infrastructure
- T1583.001 Domains
- T1583.002 DNS Server
- T1583.003 Virtual Private Server
- T1583.004 Server
- T1583.005 Botnet
- T1583.006 Web Services
- T1583.007 Serverless
- T1583.008 Malvertising
- T1584 Compromise Infrastructure
- T1584.001 Compromise Infrastructure: Domains
- T1584.002 DNS Server
- T1584.003 Virtual Private Server
- T1584.004 Compromise Infrastructure: Server
- T1584.005 Botnet
- T1584.006 Web Services
- T1584.007 Serverless
- T1584.008 Network Devices
- T1585 Establish Accounts
- T1585.001 Social Media Accounts
- T1585.002 Email Accounts
- T1585.003 Cloud Accounts
- T1586 Compromise Accounts
- T1586.001 Social Media Accounts
- T1586.002 Email Accounts
- T1586.003 Cloud Accounts
- T1587 Develop Capabilities
- T1587.001 Malware
- T1587.002 Code Signing Certificates
- T1587.003 Digital Certificates
- T1587.004 Exploits
- T1588 Obtain Capabilities
- T1588.001 Malware
- T1588.002 Tool
- T1588.003 Code Signing Certificates
- T1588.004 Digital Certificates
- T1588.005 Exploits
- T1588.006 Vulnerabilities
- T1588.007 Artificial Intelligence
- T1608 Stage Capabilities
- T1608.001 Upload Malware
- T1608.002 Upload Tool
- T1608.003 Install Digital Certificate
- T1608.004 Drive-by Target
- T1608.005 Link Target
- T1608.006 SEO Poisoning
- T1650 Acquire Access