Security Software Discovery

T1518.001

Sub-technique of T1518 Software Discovery.View on attack.mitre.org

About this technique

Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cloud monitoring agents and anti-virus. Adversaries may use the information from Security Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Example commands that can be used to obtain security software information are netsh, reg query with Reg, dir with cmd, and Tasklist, but other indicators of discovery behavior may be more specific to the type of software or security system the adversary is looking for. It is becoming more common to see macOS malware perform checks for LittleSnitch and KnockKnock software.

Adversaries may also utilize the Cloud API to discover cloud-native security software installed on compute infrastructure, such as the AWS CloudWatch agent, Azure VM Agent, and Google Cloud Monitor agent. These agents may collect metrics and logs from the VM, which may be centrally aggregated in a cloud-based monitoring platform.

Detection rules8

Rules on DetectionCode tagged with T1518.001.

Sigma8

RuleLevelLog source
Sysmon Discovery Via Default Driver Altitude Using Findstr.EXEhighwindows / process_creation
Security Software Discovery - MacOsmediummacos / process_creation
Security Software Discovery Via Powershell Scriptmediumwindows / ps_script
Security Tools Keyword Lookup Via Findstr.EXEmediumwindows / process_creation
System Integrity Protection (SIP) Disabledmediummacos / process_creation
PowerShell AppLocker Policy Discovery Via Get-AppLockerPolicylowwindows / process_creation
Security Software Discovery - Linuxlowlinux / process_creation
System Integrity Protection (SIP) Enumerationlowmacos / process_creation

Splunk0

No Splunk rules are mapped to this technique yet.

Groups27

Show 3 more

Software111

Show 87 more

Campaigns3

Procedure examples141

Groups27

Used byProcedure example
GroupAPT38

APT38 has identified security software, configurations, defensive tools, and sensors installed on a compromised system.

GroupAPT42

APT42 has used Windows Management Instrumentation (WMI) to check for anti-virus products.

GroupAquatic Panda

Aquatic Panda has attempted to discover third party endpoint detection and response (EDR) tools on compromised systems.

GroupBlackByte

BlackByte enumerated installed security products during operations.

GroupCobalt Group

Cobalt Group used a JavaScript backdoor that is capable of collecting a list of the security solutions installed on the victim's machine.

GroupDarkhotel

Darkhotel has searched for anti-malware strings and anti-virus processes running on the system.

GroupFIN8

FIN8 has used Registry keys to detect and avoid executing in potential sandboxes.

GroupGamaredon Group

Gamaredon Group has used PowerShell scripts to identify security software on the victim machine.

View all 27 groups examples

Software111

Used byProcedure example
MalwareABK

ABK has the ability to identify the installed anti-virus product on the compromised host.

MalwareAction RAT

Action RAT can identify AV products on an infected host using the following command: `cmd.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List`.

MalwareAmadey

Amadey has checked for a variety of antivirus products.

MalwareAstaroth

Astaroth checks for the presence of Avast antivirus in the C:\Program\Files\ folder.

MalwareAuTo Stealer

AuTo Stealer has the ability to collect information about installed AV products from an infected host.

MalwareAvenger

Avenger has the ability to identify installed anti-virus products on a compromised host.

MalwareBadPatch

BadPatch uses WMI to enumerate installed security products in the victim’s environment.

MalwareBazar

Bazar can identify the installed antivirus engine.

View all 111 software examples

Campaigns3

Used byProcedure example
CampaignFrankenstein

During Frankenstein, the threat actors used WMI queries to determine if analysis tools were running on a compromised system.

CampaignKV Botnet Activity

KV Botnet Activity involved removal of security tools, as well as other identified IOT malware, from compromised devices.

CampaignOperation Wocao

During Operation Wocao, threat actors used scripts to detect security software.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.