Basyrix SOC Response Atlas by Basyrix

Command and Control

T1105 — Ingress Tool Transfer

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as [ftp](https://attack.mitre.org/software/S0095). Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e...

Investigate Ingress Tool Transfer activity in the context of Command and Control: confirm scope, affected host/identity, and whether it matches expected administrative behaviour before deciding this is benign.

Platforms

ESXi, Linux, macOS, Network Devices, Windows

Priority / status

high / complete

Evidence to collect

  • Host or resource affected
  • Account or identity involved
  • Timestamp of the activity
  • Related process, file, or network artifact
  • Any preceding or follow-on alerts