Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1588/T1588.002
MITRE ATT&CK Sub-Technique

T1588.002: Tool

ShareXLinkedInRedditHN

Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A tool can be used for malicious purposes by an adversary, but (unlike malware) were not intended to be used for those purposes (ex: [PsExec](https://attack.mitre.org/software/S0029)). Adversaries may obtain tools to support their operations, including to support execution of post-compromise behaviors. Tools may also be leveraged for testing – for example, evaluating malware against commercial antivirus or endpoint detection and response (EDR) applications.(Citation: Forescout Conti Leaks 2022)(Citation: Sentinel Labs Top Tier Target 2025) Tool acquisition may involve the procurement of commercial software licenses, including for red teaming tools such as Cobalt Strike. In addition to freely downloading or purchasing software, adversaries may steal software and/or software licenses from third-party entities (including other adversaries). Threat actors may also crack trial versions of software.(Citation: Recorded Future Beacon 2019)

Tactics
Resource Development
Platforms
PRE

▪Parent technique

T1588: Obtain Capabilities

▪Mitigations (1)

M1056Pre-compromise

Pre-compromise mitigations involve proactive measures and defenses implemented to prevent adversaries from successfully identifying and exploiting weaknesses during the Reconnaissance and Resource Development phases of an attack. These activities focus on reducing an organization's attack surface, identify adversarial preparation efforts, and increase the difficulty for attackers to conduct successful operations. This mitigation can be implemented through the following measures: Limit Information Exposure: - Regularly audit and sanitize publicly available data, including job posts, websites, and social media. - Use tools like OSINT monitoring platforms (e.g., SpiderFoot, Recon-ng) to identify leaked information. Protect Domain and DNS Infrastructure: - Enable DNSSEC and use WHOIS privacy protection. - Monitor for domain hijacking or lookalike domains using services like RiskIQ or DomainTools. External Monitoring: - Use tools like Shodan, Censys to monitor your external attack surface. - Deploy external vulnerability scanners to proactively address weaknesses. Threat Intelligence: - Leverage platforms like MISP, Recorded Future, or Anomali to track adversarial infrastructure, tools, and activity. Content and Email Protections: - Use email security solutions like Proofpoint, Microsoft Defender for Office 365, or Mimecast. - Enforce SPF/DKIM/DMARC policies to protect against email spoofing. Training and Awareness: - Educate employees on identifying phishing attempts, securing their social media, and avoiding information leaks.

▪Used by groups (81)

G0003CleaverG0004Ke3changG0006APT1G0007APT28G0008CarbanakG0010TurlaG0011PittyTigerG0016APT29G0027Threat Group-3390G0030Lotus BlossomG0032Lazarus GroupG0034Sandworm TeamG0035DragonflyG0037FIN6G0040PatchworkG0045menuPassG0046FIN7G0047Gamaredon GroupG0049OilRigG0050APT32G0051FIN10G0052CopyKittensG0053FIN5G0059Magic HoundG0060BRONZE BUTLERG0061FIN8G0064APT33G0069MuddyWaterG0073APT19G0076ThripG0077LeafminerG0078Gorgon GroupG0079DarkHydrusG0080Cobalt GroupG0082APT38G0087APT39G0090WIRTEG0091SilenceG0092TA505G0093GALLIUMG0094KimsukyG0096APT41G0098BlackTechG0099APT-C-36G0100InceptionG0102Wizard SpiderG0105DarkVishnyaG0107WhiteflyG0108Blue MockingbirdG0114ChimeraG0122Silent LibrarianG0129Mustang PandaG0135BackdoorDiplomacyG0136IndigoZebraG0137Ferocious KittenG0143Aquatic PandaG1001HEXANEG1002BITTERG1004LAPSUS$G1005POLONIUMG1006Earth LuscaG1007Aoqin DragonG1009Moses StaffG1013MetadorG1014LuminousMothG1015Scattered SpiderG1016FIN13G1017Volt TyphoonG1018TA2541G1021Cinnamon TempestG1032INC RansomG1033Star BlizzardG1040PlayG1041Sea TurtleG1044APT42G1045Salt TyphoonG1046Storm-1811G1051Medusa GroupG1052Contagious InterviewG1054MirrorFaceG1055VOID MANTICORE

▪Software using this technique (1)

S0681Lizarmalware

▪Reference

T1588.002on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.