// MITRE ATT&CK
T1608 · Stage Capabilities
Adversaries may upload, install, or otherwise set up capabilities that can be used during targeting. To support their operations, an adversary may need to take capabilities they developed ([Develop Capabilities](https://attack.mitre.org/techniques/T1587)) or obtained ([Obtain Capabilities](https://a...
How to detect & mitigate it
Detecting Stage Capabilities starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (6)
T1608.001
Upload Malware T1608.002
Upload Tool T1608.003
Install Digital Certificate T1608.004
Drive-by Target T1608.005
Link Target T1608.006
SEO Poisoning
Upload Malware T1608.002
Upload Tool T1608.003
Install Digital Certificate T1608.004
Drive-by Target T1608.005
Link Target T1608.006
SEO Poisoning
Related techniques
T1583
Acquire Infrastructure T1583.007
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1588.004
Digital Certificates T1583.002
DNS Server T1587.003
Digital Certificates
Acquire Infrastructure T1583.007
Serverless T1588.007
Artificial Intelligence T1584.008
Network Devices T1583.008
Malvertising T1588.004
Digital Certificates T1583.002
DNS Server T1587.003
Digital Certificates
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.