Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1518 Software Discovery |
MalwareInvisiMole | InvisiMole can collect information about installed software used by specific users, software executed on user login, and software executed by each system. |
| T1518 Software Discovery |
MalwareP.A.S. Webshell | P.A.S. Webshell can list PHP server configuration details. |
| T1518 Software Discovery |
MalwareSiloscape | Siloscape searches for the kubectl binary. |
| T1518 Software Discovery |
MalwareMarkiRAT | MarkiRAT can check for the Telegram installation directory by enumerating the files on disk. |
| T1518 Software Discovery |
MalwareSocGholish | SocGholish can identify the victim's browser in order to serve the correct fake update page. |
| T1518 Software Discovery |
MalwareSpicyOmelette | SpicyOmelette can enumerate running software on a targeted system. |
| T1518 Software Discovery |
MalwareLightSpy | If sent the command `16001`, LightSpy uses the `NSFileManger contentsOfDirectoryAtPath()` to enumerate the Applications folder to collect the bundle name, bundle identifier, and version information from each application's `info.plist` file. The results are then converted into a JSON blob for exfiltration. |
| T1518 Software Discovery |
MalwareDyre | Dyre has the ability to identify installed programs on a compromised host. |
| T1518 Software Discovery |
MalwareDustySky | DustySky lists all installed software for the infected machine. |
| T1518 Software Discovery |
MalwareSVCReady | SVCReady can collect a list of installed software from an infected host. |
| T1518 Software Discovery |
MalwareCharmPower | CharmPower can list the installed applications on a compromised host. |
| T1518 Software Discovery |
MalwareBundlore | Bundlore has the ability to enumerate what browser is being used as well as version information for Safari. |
| T1518 Software Discovery |
MalwareGlassWorm | GlassWorm has searched for existing wallet applications to include Ledger Live and Trezor Suite. |
| T1518 Software Discovery |
MalwareMetamorfo | Metamorfo has searched the compromised system for banking applications. |
| T1518 Software Discovery |
MalwareKGH_SPY | KGH_SPY can collect information on installed applications. |
| T1518 Software Discovery |
Malwaredown_new | down_new has the ability to gather information on installed applications. |
| T1518 Software Discovery |
MalwareRedLine Stealer | RedLine Stealer can get a list of programs on the victim device. |
| T1518 Software Discovery |
MalwareRTM | RTM can scan victim drives to look for specific banking software on the machine to determine next actions. |
| T1518 Software Discovery |
MalwareStrelaStealer | StrelaStealer variants use COM objects to enumerate installed applications from the "AppsFolder" on victim machines. |
| T1518 Software Discovery |
MalwareBazar | Bazar can query the Registry for installed applications. |
| T1518 Software Discovery |
MalwareSUGARDUMP | SUGARDUMP can identify Chrome, Opera, Edge Chromium, and Firefox browsers, including version number, on a compromised host. |
| T1518 Software Discovery |
MalwareCobalt Strike | The Cobalt Strike System Profiler can discover applications through the browser and identify the version of Java the target has. |
| T1518 Software Discovery |
MalwareHotCroissant | HotCroissant can retrieve a list of applications from the |
| T1518 Software Discovery |
MalwareSamurai | Samurai can check for the presence and version of the .NET framework. |
| T1518 Software Discovery |
MalwareTajMahal | TajMahal has the ability to identify the Internet Explorer (IE) version on an infected host. |
| T1518 Software Discovery |
MalwareRaccoon Stealer | Raccoon Stealer is capable of identifying running software on victim machines. |
| T1518 Software Discovery |
MalwareComRAT | ComRAT can check the victim's default browser to determine which process to inject its communications module into. |
| T1518 Software Discovery |
MalwareLunarWeb | LunarWeb can list installed software on compromised systems. |
| T1518 Software Discovery |
MalwareXCSSET | XCSSET uses |
| T1518 Software Discovery |
MalwareQakBot | QakBot can enumerate a list of installed programs. |
| T1518 Software Discovery |
MalwareDridex | Dridex has collected a list of installed software on the system. |
| T1518 Software Discovery |
ToolShimRatReporter | ShimRatReporter gathered a list of installed software on the infected host. |
| T1518 Software Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has searched for cryptocurrency wallets on targeted hosts. |
| T1518.001 Security Software Discovery |
MalwareBumblebee | Bumblebee can identify specific analytical tools based on running processes. |
| T1518.001 Security Software Discovery |
MalwareAmadey | Amadey has checked for a variety of antivirus products. |
| T1518.001 Security Software Discovery |
MalwareStuxnet | Stuxnet enumerates the currently running processes related to a variety of security products. |
| T1518.001 Security Software Discovery |
MalwarePOWRUNER | POWRUNER may collect information on the victim's anti-virus software. |
| T1518.001 Security Software Discovery |
MalwareTAMECAT | TAMECAT has used Windows Management Instrumentation (WMI) to check for anti-virus products. |
| T1518.001 Security Software Discovery |
MalwareFelismus | Felismus checks for processes associated with anti-virus vendors. |
| T1518.001 Security Software Discovery |
MalwareZeus Panda | Zeus Panda checks to see if anti-virus, anti-spyware, or firewall products are installed in the victim’s environment. |
| T1518.001 Security Software Discovery |
MalwareStrongPity | StrongPity can identify if ESET or BitDefender antivirus are installed before dropping its payload. |
| T1518.001 Security Software Discovery |
MalwarexCaon | xCaon has checked for the existence of Kaspersky antivirus software on the system. |
| T1518.001 Security Software Discovery |
MalwareROAMINGHOUSE | ROAMINGHOUSE can identify McAfee applications on compromised hosts and change its execution method if one is detected. |
| T1518.001 Security Software Discovery |
MalwareTONESHELL | TONESHELL has checked for the presence of ESET antivirus applications `ekrn.exe` and `egui.exe`. |
| T1518.001 Security Software Discovery |
MalwareKasidet | Kasidet has the ability to identify any anti-virus installed on the infected system. |
| T1518.001 Security Software Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has the capability to detect security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables. |
| T1518.001 Security Software Discovery |
MalwareCrimson | Crimson contains a command to collect information about anti-virus software on the victim. |
| T1518.001 Security Software Discovery |
MalwareDUSTTRAP | DUSTTRAP can identify security software. |
| T1518.001 Security Software Discovery |
MalwareAction RAT | Action RAT can identify AV products on an infected host using the following command: `cmd.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List`. |
| T1518.001 Security Software Discovery |
MalwareAvenger | Avenger has the ability to identify installed anti-virus products on a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.