Technique with 2 sub-techniques.View on attack.mitre.org
Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment. Adversaries may use the information from Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Such software may be deployed widely across the environment for configuration management or security reasons, such as Software Deployment Tools, and may allow adversaries broad access to infect devices or move laterally.
Adversaries may attempt to enumerate software for a variety of reasons, such as figuring out what security measures are present or if the compromised system has a version of software that is vulnerable to Exploitation for Privilege Escalation.
Rules on DetectionCode tagged with T1518 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| HackTool - WinPwn Execution | high | windows / process_creation | T1518 |
| HackTool - WinPwn Execution - ScriptBlock | high | windows / ps_script | T1518 |
| Sysmon Discovery Via Default Driver Altitude Using Findstr.EXE | high | windows / process_creation | T1518.001 |
| Detected Windows Software Discovery | medium | windows / process_creation | T1518 |
| Detected Windows Software Discovery - PowerShell | medium | windows / ps_script | T1518 |
| Security Software Discovery - MacOs | medium | macos / process_creation | T1518.001 |
| Security Software Discovery Via Powershell Script | medium | windows / ps_script | T1518.001 |
| Security Tools Keyword Lookup Via Findstr.EXE | medium | windows / process_creation | T1518.001 |
| System Integrity Protection (SIP) Disabled | medium | macos / process_creation | T1518.001 |
| PowerShell AppLocker Policy Discovery Via Get-AppLockerPolicy | low | windows / process_creation | T1518.001 |
| Security Software Discovery - Linux | low | linux / process_creation | T1518.001 |
| System Integrity Protection (SIP) Enumeration | low | macos / process_creation | T1518.001 |
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Windows Software Discovery Via PowerShell | Anomaly | NULL | Powershell Script Block Logging 4104 | T1518 |
| Used by | Procedure example |
|---|---|
| GroupBRONZE BUTLER | BRONZE BUTLER has used tools to enumerate software installed on an infected host. |
| GroupHEXANE | HEXANE has enumerated programs installed on an infected machine. |
| GroupInception | Inception has enumerated installed software on compromised systems. |
| GroupMuddyWater | MuddyWater has used a PowerShell backdoor to check for Skype connectivity on the target machine. |
| GroupMustang Panda | Mustang Panda has searched the victim system for the |
| GroupSideCopy | SideCopy has collected browser information from a compromised host. |
| GroupSidewinder | Sidewinder has used tools to enumerate software installed on an infected host. |
| GroupTropic Trooper | Tropic Trooper's backdoor could list the infected system's installed software. |
| Used by | Procedure example |
|---|---|
| MalwareBazar | Bazar can query the Registry for installed applications. |
| MalwareBundlore | Bundlore has the ability to enumerate what browser is being used as well as version information for Safari. |
| MalwareCharmPower | CharmPower can list the installed applications on a compromised host. |
| MalwareCobalt Strike | The Cobalt Strike System Profiler can discover applications through the browser and identify the version of Java the target has. |
| MalwareComRAT | ComRAT can check the victim's default browser to determine which process to inject its communications module into. |
| MalwareCuckoo Stealer | Cuckoo Stealer has the ability to search systems for installed applications. |
| Malwaredown_new | down_new has the ability to gather information on installed applications. |
| MalwareDridex | Dridex has collected a list of installed software on the system. |
| Used by | Procedure example |
|---|---|
| CampaignJuicy Mix | During Juicy Mix, OilRig used browser data dumper tools to create a list of users with Google Chrome installed. |
| CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors deployed a file called `DeployJava.js` to fingerprint installed software on a victim system prior to exploit delivery. |
| CampaignOperation Wocao | During Operation Wocao, threat actors collected a list of installed software on the infected system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.