Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1518 Software Discovery |
Malwaredown_new | down_new has the ability to gather information on installed applications. |
| T1518 Software Discovery |
MalwareRedLine Stealer | RedLine Stealer can get a list of programs on the victim device. |
| T1518 Software Discovery |
MalwareRTM | RTM can scan victim drives to look for specific banking software on the machine to determine next actions. |
| T1518 Software Discovery |
MalwareStrelaStealer | StrelaStealer variants use COM objects to enumerate installed applications from the "AppsFolder" on victim machines. |
| T1518 Software Discovery |
MalwareBazar | Bazar can query the Registry for installed applications. |
| T1518 Software Discovery |
MalwareSUGARDUMP | SUGARDUMP can identify Chrome, Opera, Edge Chromium, and Firefox browsers, including version number, on a compromised host. |
| T1518 Software Discovery |
MalwareCobalt Strike | The Cobalt Strike System Profiler can discover applications through the browser and identify the version of Java the target has. |
| T1518 Software Discovery |
MalwareHotCroissant | HotCroissant can retrieve a list of applications from the |
| T1518 Software Discovery |
MalwareSamurai | Samurai can check for the presence and version of the .NET framework. |
| T1518 Software Discovery |
MalwareTajMahal | TajMahal has the ability to identify the Internet Explorer (IE) version on an infected host. |
| T1518 Software Discovery |
MalwareRaccoon Stealer | Raccoon Stealer is capable of identifying running software on victim machines. |
| T1518 Software Discovery |
MalwareComRAT | ComRAT can check the victim's default browser to determine which process to inject its communications module into. |
| T1518 Software Discovery |
MalwareLunarWeb | LunarWeb can list installed software on compromised systems. |
| T1518 Software Discovery |
MalwareXCSSET | XCSSET uses |
| T1518 Software Discovery |
MalwareQakBot | QakBot can enumerate a list of installed programs. |
| T1518 Software Discovery |
MalwareDridex | Dridex has collected a list of installed software on the system. |
| T1518 Software Discovery |
ToolShimRatReporter | ShimRatReporter gathered a list of installed software on the infected host. |
| T1518 Software Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has searched for cryptocurrency wallets on targeted hosts. |
| T1518.001 Security Software Discovery |
CampaignKV Botnet Activity | KV Botnet Activity involved removal of security tools, as well as other identified IOT malware, from compromised devices. |
| T1518.001 Security Software Discovery |
CampaignFrankenstein | During Frankenstein, the threat actors used WMI queries to determine if analysis tools were running on a compromised system. |
| T1518.001 Security Software Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors used scripts to detect security software. |
| T1518.001 Security Software Discovery |
GroupAPT38 | APT38 has identified security software, configurations, defensive tools, and sensors installed on a compromised system. |
| T1518.001 Security Software Discovery |
GroupBlackByte | BlackByte enumerated installed security products during operations. |
| T1518.001 Security Software Discovery |
GroupSideCopy | SideCopy uses a loader DLL file to collect AV product names from an infected host. |
| T1518.001 Security Software Discovery |
GroupKimsuky | Kimsuky has checked for the presence of antivirus software with |
| T1518.001 Security Software Discovery |
GroupPatchwork | Patchwork scanned the “Program Files” directories for a directory with the string “Total Security” (the installation path of the “360 Total Security” antivirus tool). |
| T1518.001 Security Software Discovery |
GroupMuddyWater | MuddyWater has used malware to check running processes against a hard-coded list of security tools often used by malware researchers. |
| T1518.001 Security Software Discovery |
GroupNaikon | Naikon uses commands such as |
| T1518.001 Security Software Discovery |
GroupGamaredon Group | Gamaredon Group has used PowerShell scripts to identify security software on the victim machine. |
| T1518.001 Security Software Discovery |
GroupTeamTNT | TeamTNT has searched for security products on infected machines. |
| T1518.001 Security Software Discovery |
GroupSidewinder | Sidewinder has used the Windows service |
| T1518.001 Security Software Discovery |
GroupRocke | Rocke used scripts which detected and uninstalled antivirus software. |
| T1518.001 Security Software Discovery |
GroupTA2541 | TA2541 has used tools to search victim systems for security products such as antivirus and firewall software. |
| T1518.001 Security Software Discovery |
GroupTropic Trooper | Tropic Trooper can search for anti-virus software running on the system. |
| T1518.001 Security Software Discovery |
GroupAquatic Panda | Aquatic Panda has attempted to discover third party endpoint detection and response (EDR) tools on compromised systems. |
| T1518.001 Security Software Discovery |
GroupThe White Company | The White Company has checked for specific antivirus products on the target’s computer, including Kaspersky, Quick Heal, AVG, BitDefender, Avira, Sophos, Avast!, and ESET. |
| T1518.001 Security Software Discovery |
GroupTurla | Turla has obtained information on security software, including security logging information that may indicate whether their malware has been detected. |
| T1518.001 Security Software Discovery |
GroupStorm-0501 | Storm-0501 has detected endpoint security solutions using `sc query sense` and `sc query windefend`. |
| T1518.001 Security Software Discovery |
GroupMedusa Group | Medusa Group has detected security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables. |
| T1518.001 Security Software Discovery |
GroupDarkhotel | Darkhotel has searched for anti-malware strings and anti-virus processes running on the system. |
| T1518.001 Security Software Discovery |
GroupWindshift | Windshift has used malware to identify installed AV and commonly used forensic and malware analysis tools. |
| T1518.001 Security Software Discovery |
GroupToddyCat | ToddyCat can determine is Kaspersky software is running on an endpoint by running `cmd /c wmic process where name="avp.exe"`. |
| T1518.001 Security Software Discovery |
GroupMalteiro | Malteiro collects the installed antivirus on the victim machine. |
| T1518.001 Security Software Discovery |
GroupAPT42 | APT42 has used Windows Management Instrumentation (WMI) to check for anti-virus products. |
| T1518.001 Security Software Discovery |
GroupCobalt Group | Cobalt Group used a JavaScript backdoor that is capable of collecting a list of the security solutions installed on the victim's machine. |
| T1518.001 Security Software Discovery |
GroupWizard Spider | Wizard Spider has used WMI to identify anti-virus products installed on a victim's machine. |
| T1518.001 Security Software Discovery |
GroupPlay | Play has used the information-stealing tool Grixba to scan for anti-virus software. |
| T1518.001 Security Software Discovery |
GroupFIN8 | FIN8 has used Registry keys to detect and avoid executing in potential sandboxes. |
| T1518.001 Security Software Discovery |
MalwareBumblebee | Bumblebee can identify specific analytical tools based on running processes. |
| T1518.001 Security Software Discovery |
MalwareAmadey | Amadey has checked for a variety of antivirus products. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.