{
  "node_id": "mitre-attack-t1588-obtain-capabilities",
  "title": "MITRE ATT&CK T1588: Obtain Capabilities (Enterprise Tactic TA0042 - Resource Development)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1588 (Obtain Capabilities) is an Enterprise Resource Development technique. Adversaries may buy and/or steal capabilities that can be used during targeting. Rather than developing their own capabilities in-house, adversaries may purchase, freely download, or steal them. Activities may include the acquisition of malware, software (including licenses), exploits, certificates, and information relating to vulnerabilities. Adversaries may obtain capabilities to support their operations throughout numerous phases of the adversary lifecycle. ATT&CK documents 7 sub-techniques: T1588.001 Malware; T1588.002 Tool; T1588.003 Code Signing Certificates; T1588.004 Digital Certificates; T1588.005 Exploits; T1588.006 Vulnerabilities; T1588.007 Artificial Intelligence. Affected platforms: PRE. MITRE-documented mitigations include M1056 Pre-compromise.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-framework-v14"
  ],
  "primary_citations_count": 6
}