Real-world descriptions of how a group, tool or campaign used a technique.
111 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1518.001 Security Software Discovery |
MalwareBumblebee | Bumblebee can identify specific analytical tools based on running processes. |
| T1518.001 Security Software Discovery |
MalwareAmadey | Amadey has checked for a variety of antivirus products. |
| T1518.001 Security Software Discovery |
MalwareStuxnet | Stuxnet enumerates the currently running processes related to a variety of security products. |
| T1518.001 Security Software Discovery |
MalwarePOWRUNER | POWRUNER may collect information on the victim's anti-virus software. |
| T1518.001 Security Software Discovery |
MalwareTAMECAT | TAMECAT has used Windows Management Instrumentation (WMI) to check for anti-virus products. |
| T1518.001 Security Software Discovery |
MalwareFelismus | Felismus checks for processes associated with anti-virus vendors. |
| T1518.001 Security Software Discovery |
MalwareZeus Panda | Zeus Panda checks to see if anti-virus, anti-spyware, or firewall products are installed in the victim’s environment. |
| T1518.001 Security Software Discovery |
MalwareStrongPity | StrongPity can identify if ESET or BitDefender antivirus are installed before dropping its payload. |
| T1518.001 Security Software Discovery |
MalwarexCaon | xCaon has checked for the existence of Kaspersky antivirus software on the system. |
| T1518.001 Security Software Discovery |
MalwareROAMINGHOUSE | ROAMINGHOUSE can identify McAfee applications on compromised hosts and change its execution method if one is detected. |
| T1518.001 Security Software Discovery |
MalwareTONESHELL | TONESHELL has checked for the presence of ESET antivirus applications `ekrn.exe` and `egui.exe`. |
| T1518.001 Security Software Discovery |
MalwareKasidet | Kasidet has the ability to identify any anti-virus installed on the infected system. |
| T1518.001 Security Software Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has the capability to detect security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables. |
| T1518.001 Security Software Discovery |
MalwareCrimson | Crimson contains a command to collect information about anti-virus software on the victim. |
| T1518.001 Security Software Discovery |
MalwareDUSTTRAP | DUSTTRAP can identify security software. |
| T1518.001 Security Software Discovery |
MalwareAction RAT | Action RAT can identify AV products on an infected host using the following command: `cmd.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List`. |
| T1518.001 Security Software Discovery |
MalwareAvenger | Avenger has the ability to identify installed anti-virus products on a compromised host. |
| T1518.001 Security Software Discovery |
MalwarePrikormka | A module in Prikormka collects information from the victim about installed anti-virus software. |
| T1518.001 Security Software Discovery |
MalwarePUBLOAD | PUBLOAD has identified AV products on an infected host using the following command: `WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List`. |
| T1518.001 Security Software Discovery |
MalwareWoody RAT | Woody RAT can detect Avast Software, Doctor Web, Kaspersky, AVG, ESET, and Sophos antivirus programs. |
| T1518.001 Security Software Discovery |
MalwareMafalda | Mafalda can search for a variety of security software programs, EDR systems, and malware analysis tools. |
| T1518.001 Security Software Discovery |
MalwareAuTo Stealer | AuTo Stealer has the ability to collect information about installed AV products from an infected host. |
| T1518.001 Security Software Discovery |
MalwareFlawedAmmyy | FlawedAmmyy will attempt to detect anti-virus products during the initial infection. |
| T1518.001 Security Software Discovery |
MalwareInvisiMole | InvisiMole can check for the presence of network sniffers, AV, and BitDefender firewall. |
| T1518.001 Security Software Discovery |
MalwareWhisperGate | WhisperGate can recognize the presence of monitoring tools on a target system. |
| T1518.001 Security Software Discovery |
MalwareSkidmap | Skidmap has the ability to check if |
| T1518.001 Security Software Discovery |
MalwareRaspberry Robin | Raspberry Robin attempts to identify security software running on the victim machine, such as BitDefender, Avast, and Kaspersky. |
| T1518.001 Security Software Discovery |
MalwareMispadu | Mispadu can list installed security products in the victim’s environment. |
| T1518.001 Security Software Discovery |
MalwareRustyWater | RustyWater has attempted to detect more than 25 antivirus and EDR tools. |
| T1518.001 Security Software Discovery |
MalwareIcedID | IcedID can identify AV products on an infected host using the following command: |
| T1518.001 Security Software Discovery |
MalwareVERMIN | VERMIN uses WMI to check for anti-virus software installed on the system. |
| T1518.001 Security Software Discovery |
MalwareMarkiRAT | MarkiRAT can check for running processes on the victim’s machine to look for Kaspersky and Bitdefender antivirus products. |
| T1518.001 Security Software Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP is capable of checking whether a compromised device is running DeepFreeze by Faronics. |
| T1518.001 Security Software Discovery |
MalwareNotPetya | NotPetya determines if specific antivirus programs are running on an infected host machine. |
| T1518.001 Security Software Discovery |
MalwareSpicyOmelette | SpicyOmelette can check for the presence of 29 different antivirus tools. |
| T1518.001 Security Software Discovery |
MalwarePUNCHBUGGY | PUNCHBUGGY can gather AVs registered in the system. |
| T1518.001 Security Software Discovery |
MalwareDarkTortilla | DarkTortilla can check for the Kaspersky Anti-Virus suite. |
| T1518.001 Security Software Discovery |
MalwareExbyte | Exbyte checks for the presence of various security software products during execution. |
| T1518.001 Security Software Discovery |
MalwareDarkWatchman | DarkWatchman can search for anti-virus products on the system. |
| T1518.001 Security Software Discovery |
MalwareLumma Stealer | Lumma Stealer has detected antivirus processes using commands such as “tasklist” and “findstr.” |
| T1518.001 Security Software Discovery |
MalwareDustySky | DustySky checks for the existence of anti-virus. |
| T1518.001 Security Software Discovery |
MalwareRemsec | Remsec has a plugin detect security products via active drivers. |
| T1518.001 Security Software Discovery |
MalwareEpic | Epic searches for anti-malware services running on the victim’s machine and terminates itself if it finds them. |
| T1518.001 Security Software Discovery |
MalwarePureCrypter | PureCrypter can identify installed antivirus solutions. |
| T1518.001 Security Software Discovery |
MalwareDarkGate | DarkGate looks for various security products by process name using hard-coded values in the malware. DarkGate will not execute its keylogging thread if a process name associated with Trend Micro anti-virus is identified, or if runtime checks identify the presence of Kaspersky anti-virus. DarkGate will initiate a new thread if certain security products are identified on the victim, and recreate any malicious files associated with it if it determines they were removed by security software in a new system location. |
| T1518.001 Security Software Discovery |
MalwareThiefQuest | ThiefQuest uses the |
| T1518.001 Security Software Discovery |
MalwareFerocious | Ferocious has checked for AV software as part of its persistence process. |
| T1518.001 Security Software Discovery |
MalwareNetwalker | Netwalker can detect and terminate active security software-related processes on infected systems. |
| T1518.001 Security Software Discovery |
MalwareLatrodectus | Latrodectus has the ability to identify installed antivirus products. |
| T1518.001 Security Software Discovery |
MalwareMuddyViper | MuddyViper has the ability to check for a specified list of security tools in the compromised environment. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.