ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1518×

11 examples

TechniqueUsed byProcedure example
T1518
Software Discovery
GroupSideCopy

SideCopy has collected browser information from a compromised host.

T1518
Software Discovery
GroupVolt Typhoon

Volt Typhoon has queried the Registry on compromised systems for information on installed software.

T1518
Software Discovery
GroupMuddyWater

MuddyWater has used a PowerShell backdoor to check for Skype connectivity on the target machine.

T1518
Software Discovery
GroupSidewinder

Sidewinder has used tools to enumerate software installed on an infected host.

T1518
Software Discovery
GroupMustang Panda

Mustang Panda has searched the victim system for the InstallUtil.exe program and its version.

T1518
Software Discovery
GroupWindigo

Windigo has used a script to detect installed software on targeted systems.

T1518
Software Discovery
GroupTropic Trooper

Tropic Trooper's backdoor could list the infected system's installed software.

T1518
Software Discovery
GroupBRONZE BUTLER

BRONZE BUTLER has used tools to enumerate software installed on an infected host.

T1518
Software Discovery
GroupWindshift

Windshift has used malware to identify installed software.

T1518
Software Discovery
GroupInception

Inception has enumerated installed software on compromised systems.

T1518
Software Discovery
GroupHEXANE

HEXANE has enumerated programs installed on an infected machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.