Software Discovery

T1518

Technique with 2 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment. Adversaries may use the information from Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Such software may be deployed widely across the environment for configuration management or security reasons, such as Software Deployment Tools, and may allow adversaries broad access to infect devices or move laterally.

Adversaries may attempt to enumerate software for a variety of reasons, such as figuring out what security measures are present or if the compromised system has a version of software that is vulnerable to Exploitation for Privilege Escalation.

Detection rules13

Rules on DetectionCode tagged with T1518 or one of its sub-techniques.

Sigma12

Splunk1

RuleTypeRiskData sourceTechnique
Windows Software Discovery Via PowerShellAnomalyNULLPowershell Script Block Logging 4104T1518

Sub-techniques2

IDNameExamples
T1518.001Security Software Discovery141
T1518.002Backup Software Discovery1

Groups11

Software39

Show 15 more

Campaigns3

Procedure examples53

Groups11

Used byProcedure example
GroupBRONZE BUTLER

BRONZE BUTLER has used tools to enumerate software installed on an infected host.

GroupHEXANE

HEXANE has enumerated programs installed on an infected machine.

GroupInception

Inception has enumerated installed software on compromised systems.

GroupMuddyWater

MuddyWater has used a PowerShell backdoor to check for Skype connectivity on the target machine.

GroupMustang Panda

Mustang Panda has searched the victim system for the InstallUtil.exe program and its version.

GroupSideCopy

SideCopy has collected browser information from a compromised host.

GroupSidewinder

Sidewinder has used tools to enumerate software installed on an infected host.

GroupTropic Trooper

Tropic Trooper's backdoor could list the infected system's installed software.

View all 11 groups examples

Software39

Used byProcedure example
MalwareBazar

Bazar can query the Registry for installed applications.

MalwareBundlore

Bundlore has the ability to enumerate what browser is being used as well as version information for Safari.

MalwareCharmPower

CharmPower can list the installed applications on a compromised host.

MalwareCobalt Strike

The Cobalt Strike System Profiler can discover applications through the browser and identify the version of Java the target has.

MalwareComRAT

ComRAT can check the victim's default browser to determine which process to inject its communications module into.

MalwareCuckoo Stealer

Cuckoo Stealer has the ability to search systems for installed applications.

Malwaredown_new

down_new has the ability to gather information on installed applications.

MalwareDridex

Dridex has collected a list of installed software on the system.

View all 39 software examples

Campaigns3

Used byProcedure example
CampaignJuicy Mix

During Juicy Mix, OilRig used browser data dumper tools to create a list of users with Google Chrome installed.

CampaignOperation Dust Storm

During Operation Dust Storm, the threat actors deployed a file called `DeployJava.js` to fingerprint installed software on a victim system prior to exploit delivery.

CampaignOperation Wocao

During Operation Wocao, threat actors collected a list of installed software on the infected system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.