LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1588: Obtain Capabilities

Adversaries may buy and/or steal capabilities that can be used during targeting. Rather than developing their own capabilities in-house, adversaries may purchase, freely download, or steal them. Activities may include the acquisition of malware, software (including licenses), exploits, certificates, and information relating to vulnerabilities. Adversaries may obtain capabilities to support their operations throughout numerous phases of the adversary lifecycle.

In addition to downloading free malware, software, and exploits from the internet, adversaries may purchase these capabilities from third-party entities. Third-party entities can include technology companies that specialize in malware and exploits, criminal marketplaces, or from individuals.[1][2]

In addition to purchasing capabilities, adversaries may steal capabilities from third-party entities (including other adversaries). This can include stealing software licenses, malware, SSL/TLS and code-signing certificates, or raiding closed databases of vulnerabilities or exploits.[3]

EnterpriseT1588TechniqueObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Obtain Capabilities is pre-attack preparation: adversaries acquire malware, tools, certificates, exploits, vulnerability information, or AI capabilities instead of building everything themselves. For leaders, the practical issue is that a future incident may be enabled before the first visible intrusion attempt, especially when trusted software, certificates, or newly disclosed vulnerabilities reduce the defender’s warning time.

Executive priority

Treat this as a readiness and prioritization problem, not a single alerting problem. Executives should ask whether vulnerability management, certificate governance, threat intelligence, and pre-compromise monitoring can identify when acquired capabilities could make the organization easier to target. This technique supports business decisions around patch urgency, software trust, supplier and certificate risk, and incident response preparation.

Technical view

This is an ATT&CK PRE-platform, Resource Development technique with no official ATT&CK detection text supplied. SOC and detection teams should validate coverage across the related subtechnique areas: acquired malware, dual-use tools, code-signing certificates, SSL/TLS certificates, exploits, vulnerability information, and AI-enabled preparation. The relationship to DET0850 indicates a detection strategy exists, but local teams still need to map it to their telemetry and use cases. The M1056 Pre-compromise mitigation relationship points toward reducing attack surface and identifying adversarial preparation activity before intrusion.

Likely telemetry

  • Threat intelligence reporting on malware, tools, exploit availability, certificate abuse, and vulnerability interest
  • Vulnerability management data, exposure inventories, and patch status
  • Certificate inventory, code-signing certificate records, and SSL/TLS certificate monitoring
  • Network security telemetry that can surface suspicious infrastructure or certificate patterns
  • Endpoint and software inventory data for unexpected tools or signed binaries

Detection direction

  • Do not rely on a single direct detection; this behavior often occurs before victim-environment telemetry exists.
  • Validate whether threat intelligence is operationalized into watchlists, vulnerability prioritization, certificate monitoring, and SOC hunt hypotheses.
  • Tune detections around suspicious or unexpected use of signed code, unusual TLS/SSL certificate characteristics, known malicious or dual-use tools, and exploit-related exposure where supported by local telemetry.
  • Separate legitimate security research, administrator tooling, and normal certificate issuance from adversary preparation indicators to reduce false positives.
  • Use the related subtechniques to structure coverage reviews: malware, tools, code-signing certificates, digital certificates, exploits, vulnerabilities, and artificial intelligence.

Mitigation priorities

  • Prioritize M1056-style pre-compromise controls: reduce exposed attack surface and improve visibility into adversarial preparation.
  • Maintain current asset, software, vulnerability, and certificate inventories so newly relevant acquired capabilities can be assessed quickly.
  • Tie vulnerability prioritization to exploit availability and exposure, not only severity scores.
  • Govern code-signing and TLS certificate issuance, storage, renewal, and revocation processes.
  • Prepare IR playbooks to investigate when trusted certificates, legitimate tools, or public exploits appear in malicious activity.
Additional notes and limits

This technique is broad and decision-oriented. Its value is in forcing a coverage review across threat intelligence, vulnerability management, certificate governance, SOC detection engineering, and incident response readiness. The related subtechniques provide the practical decomposition for control testing.

The official ATT&CK object provides no detection text and only the PRE platform. Any claims about active exploitation, specific adversaries, affected products, or detection coverage require local evidence or additional intelligence not supplied here.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Obtain Capabilities

Adversaries may buy and/or steal capabilities that can be used during targeting. Rather than developing their own capabilities in-house, adversaries may purchase, freely download, or steal them. Activities may include the acquisition of malware, software (including licenses), exploits, certificates, and information relating to vulnerabilities. Adversaries may obtain capabilities to support their operations throughout numerous phases of the adversary lifecycle.

In addition to downloading free malware, software, and exploits from the internet, adversaries may purchase these capabilities from third-party entities. Third-party entities can include technology companies that specialize in malware and exploits, criminal marketplaces, or from individuals.[1][2]

In addition to purchasing capabilities, adversaries may steal capabilities from third-party entities (including other adversaries). This can include stealing software licenses, malware, SSL/TLS and code-signing certificates, or raiding closed databases of vulnerabilities or exploits.[3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

7 rows
DomainIDNameRelationship / procedure
EnterpriseT1588.006VulnerabilitiesSub-techniqueVulnerabilities subtechnique of this object.
EnterpriseT1588.005ExploitsSub-techniqueExploits subtechnique of this object.
EnterpriseT1588.007Artificial IntelligenceSub-techniqueArtificial Intelligence subtechnique of this object.
EnterpriseT1588.004Digital CertificatesSub-techniqueDigital Certificates subtechnique of this object.
EnterpriseT1588.002ToolSub-techniqueTool subtechnique of this object.
EnterpriseT1588.003Code Signing CertificatesSub-techniqueCode Signing Certificates subtechnique of this object.
EnterpriseT1588.001MalwareSub-techniqueMalware subtechnique of this object.
Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
f89dbfee2b82b19e...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundlef89dbfee2b82…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    NationsBuying

    Nicole Perlroth and David E. Sanger. (2013, July 12). Nations Buying as Hackers Sell Flaws in Computer Code. Retrieved March 9, 2017.

    Open source URL
  2. [2]
    PegasusCitizenLab

    Bill Marczak and John Scott-Railton. (2016, August 24). The Million Dollar Dissident: NSO Group’s iPhone Zero-Days used against a UAE Human Rights Defender. Retrieved December 12, 2016.

    Open source URL
  3. [3]
    DiginotarCompromise

    Fisher, D. (2012, October 31). Final Report on DigiNotar Hack Shows Total Compromise of CA Servers. Retrieved March 6, 2017.

    Open source URL
  4. [4]
    Analyzing CS Dec 2020

    Maynier, E. (2020, December 20). Analyzing Cobalt Strike for Fun and Profit. Retrieved October 12, 2021.

    Open source URL
  5. [5]
    Analyzing CS Dec 2020

    Maynier, E. (2020, December 20). Analyzing Cobalt Strike for Fun and Profit. Retrieved October 12, 2021.

    Open source URL
  6. [6]
    Analyzing CS Dec 2020

    Maynier, E. (2020, December 20). Analyzing Cobalt Strike for Fun and Profit. Retrieved October 12, 2021.

    Open source URL
  7. [7]
    DiginotarCompromise

    Fisher, D. (2012, October 31). Final Report on DigiNotar Hack Shows Total Compromise of CA Servers. Retrieved March 6, 2017.

    Open source URL
  8. [8]
    DiginotarCompromise

    Fisher, D. (2012, October 31). Final Report on DigiNotar Hack Shows Total Compromise of CA Servers. Retrieved March 6, 2017.

    Open source URL
  9. [9]
    FireEyeSupplyChain

    FireEye. (2014). SUPPLY CHAIN ANALYSIS: From Quartermaster to SunshopFireEye. Retrieved March 6, 2017.

    Open source URL
  10. [10]
    FireEyeSupplyChain

    FireEye. (2014). SUPPLY CHAIN ANALYSIS: From Quartermaster to SunshopFireEye. Retrieved March 6, 2017.

    Open source URL
  11. [11]
    FireEyeSupplyChain

    FireEye. (2014). SUPPLY CHAIN ANALYSIS: From Quartermaster to SunshopFireEye. Retrieved March 6, 2017.

    Open source URL
  12. [12]
    NationsBuying

    Nicole Perlroth and David E. Sanger. (2013, July 12). Nations Buying as Hackers Sell Flaws in Computer Code. Retrieved March 9, 2017.

    Open source URL
  13. [13]
    NationsBuying

    Nicole Perlroth and David E. Sanger. (2013, July 12). Nations Buying as Hackers Sell Flaws in Computer Code. Retrieved March 9, 2017.

    Open source URL
  14. [14]
    PegasusCitizenLab

    Bill Marczak and John Scott-Railton. (2016, August 24). The Million Dollar Dissident: NSO Group’s iPhone Zero-Days used against a UAE Human Rights Defender. Retrieved December 12, 2016.

    Open source URL
  15. [15]
    PegasusCitizenLab

    Bill Marczak and John Scott-Railton. (2016, August 24). The Million Dollar Dissident: NSO Group’s iPhone Zero-Days used against a UAE Human Rights Defender. Retrieved December 12, 2016.

    Open source URL
  16. [16]
    Recorded Future Beacon Certificates

    Insikt Group. (2019, June 18). A Multi-Method Approach to Identifying Rogue Cobalt Strike Servers. Retrieved September 16, 2024.

    Open source URL
  17. [17]
    Recorded Future Beacon Certificates

    Insikt Group. (2019, June 18). A Multi-Method Approach to Identifying Rogue Cobalt Strike Servers. Retrieved September 16, 2024.

    Open source URL
  18. [18]
    Recorded Future Beacon Certificates

    Insikt Group. (2019, June 18). A Multi-Method Approach to Identifying Rogue Cobalt Strike Servers. Retrieved September 16, 2024.

    Open source URL
  19. [19]
    Splunk Kovar Certificates 2017

    Kovar, R. (2017, December 11). Tall Tales of Hunting with TLS/SSL Certificates. Retrieved October 16, 2020.

    Open source URL
  20. [20]
    Splunk Kovar Certificates 2017

    Kovar, R. (2017, December 11). Tall Tales of Hunting with TLS/SSL Certificates. Retrieved October 16, 2020.

    Open source URL
  21. [21]
    Splunk Kovar Certificates 2017

    Kovar, R. (2017, December 11). Tall Tales of Hunting with TLS/SSL Certificates. Retrieved October 16, 2020.

    Open source URL
  22. [22]
    mitre-attackT1588
    Open source URL
  23. [23]
    mitre-attackT1588
    Open source URL
  24. [24]
    mitre-attackT1588
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.