// MITRE ATT&CK
T1588 · Obtain Capabilities
Adversaries may buy and/or steal capabilities that can be used during targeting. Rather than developing their own capabilities in-house, adversaries may purchase, freely download, or steal them. Activities may include the acquisition of malware, software (including licenses), exploits, certificates,...
How to detect & mitigate it
Detecting Obtain Capabilities starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (7)
T1588.001
Malware T1588.002
Tool T1588.003
Code Signing Certificates T1588.004
Digital Certificates T1588.005
Exploits T1588.006
Vulnerabilities T1588.007
Artificial Intelligence
Malware T1588.002
Tool T1588.003
Code Signing Certificates T1588.004
Digital Certificates T1588.005
Exploits T1588.006
Vulnerabilities T1588.007
Artificial Intelligence
Related techniques
T1583
Acquire Infrastructure T1583.007
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1588.004
Digital Certificates T1583.002
DNS Server T1587.003
Digital Certificates
Acquire Infrastructure T1583.007
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1588.004
Digital Certificates T1583.002
DNS Server T1587.003
Digital Certificates
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.