Sub-technique of T1518 Software Discovery.View on attack.mitre.org
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cloud monitoring agents and anti-virus. Adversaries may use the information from Security Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Example commands that can be used to obtain security software information are netsh, reg query with Reg, dir with cmd, and Tasklist, but other indicators of discovery behavior may be more specific to the type of software or security system the adversary is looking for. It is becoming more common to see macOS malware perform checks for LittleSnitch and KnockKnock software.
Adversaries may also utilize the Cloud API to discover cloud-native security software installed on compute infrastructure, such as the AWS CloudWatch agent, Azure VM Agent, and Google Cloud Monitor agent. These agents may collect metrics and logs from the VM, which may be centrally aggregated in a cloud-based monitoring platform.
Rules on DetectionCode tagged with T1518.001.
| Rule | Level | Log source |
|---|---|---|
| Sysmon Discovery Via Default Driver Altitude Using Findstr.EXE | high | windows / process_creation |
| Security Software Discovery - MacOs | medium | macos / process_creation |
| Security Software Discovery Via Powershell Script | medium | windows / ps_script |
| Security Tools Keyword Lookup Via Findstr.EXE | medium | windows / process_creation |
| System Integrity Protection (SIP) Disabled | medium | macos / process_creation |
| PowerShell AppLocker Policy Discovery Via Get-AppLockerPolicy | low | windows / process_creation |
| Security Software Discovery - Linux | low | linux / process_creation |
| System Integrity Protection (SIP) Enumeration | low | macos / process_creation |
| Used by | Procedure example |
|---|---|
| GroupAPT38 | APT38 has identified security software, configurations, defensive tools, and sensors installed on a compromised system. |
| GroupAPT42 | APT42 has used Windows Management Instrumentation (WMI) to check for anti-virus products. |
| GroupAquatic Panda | Aquatic Panda has attempted to discover third party endpoint detection and response (EDR) tools on compromised systems. |
| GroupBlackByte | BlackByte enumerated installed security products during operations. |
| GroupCobalt Group | Cobalt Group used a JavaScript backdoor that is capable of collecting a list of the security solutions installed on the victim's machine. |
| GroupDarkhotel | Darkhotel has searched for anti-malware strings and anti-virus processes running on the system. |
| GroupFIN8 | FIN8 has used Registry keys to detect and avoid executing in potential sandboxes. |
| GroupGamaredon Group | Gamaredon Group has used PowerShell scripts to identify security software on the victim machine. |
| Used by | Procedure example |
|---|---|
| MalwareABK | ABK has the ability to identify the installed anti-virus product on the compromised host. |
| MalwareAction RAT | Action RAT can identify AV products on an infected host using the following command: `cmd.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List`. |
| MalwareAmadey | Amadey has checked for a variety of antivirus products. |
| MalwareAstaroth | Astaroth checks for the presence of Avast antivirus in the |
| MalwareAuTo Stealer | AuTo Stealer has the ability to collect information about installed AV products from an infected host. |
| MalwareAvenger | Avenger has the ability to identify installed anti-virus products on a compromised host. |
| MalwareBadPatch | BadPatch uses WMI to enumerate installed security products in the victim’s environment. |
| MalwareBazar | Bazar can identify the installed antivirus engine. |
View all 111 software examples
| Used by | Procedure example |
|---|---|
| CampaignFrankenstein | During Frankenstein, the threat actors used WMI queries to determine if analysis tools were running on a compromised system. |
| CampaignKV Botnet Activity | KV Botnet Activity involved removal of security tools, as well as other identified IOT malware, from compromised devices. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used scripts to detect security software. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.