JamPlus
Where this stands
One published detection covers this technique. Every one is unverified — no rule on Siemphony has been executed against real telemetry.
What the technique is
Adversaries may use JamPlus to proxy the execution of a malicious script. JamPlus is a build utility tool for code and data build systems. It works with several popular compilers and can be used for generating workspaces in code editors such as Visual Studio. Adversaries may abuse the JamPlus build utility to execute malicious scripts via a.jam file, which describes the build process and required dependencies. Because the malicious script is executed from a reputable developer tool, it may subvert application control security systems such as Smart App Control.
Read it on attack.mitre.orgWhat MITRE says you would watch
- AN1610
Abuse of JamPlus.exe to launch malicious payloads via crafted.jam files, resulting in abnormal process creation, command execution, or artifact generation outside of standard development workflows.
Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.