ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1518
Software Discovery
MalwareInvisiMole

InvisiMole can collect information about installed software used by specific users, software executed on user login, and software executed by each system.

T1518
Software Discovery
MalwareP.A.S. Webshell

P.A.S. Webshell can list PHP server configuration details.

T1518
Software Discovery
MalwareSiloscape

Siloscape searches for the kubectl binary.

T1518
Software Discovery
MalwareMarkiRAT

MarkiRAT can check for the Telegram installation directory by enumerating the files on disk.

T1518
Software Discovery
MalwareSocGholish

SocGholish can identify the victim's browser in order to serve the correct fake update page.

T1518
Software Discovery
MalwareSpicyOmelette

SpicyOmelette can enumerate running software on a targeted system.

T1518
Software Discovery
MalwareLightSpy

If sent the command `16001`, LightSpy uses the `NSFileManger contentsOfDirectoryAtPath()` to enumerate the Applications folder to collect the bundle name, bundle identifier, and version information from each application's `info.plist` file. The results are then converted into a JSON blob for exfiltration.

T1518
Software Discovery
MalwareDyre

Dyre has the ability to identify installed programs on a compromised host.

T1518
Software Discovery
MalwareDustySky

DustySky lists all installed software for the infected machine.

T1518
Software Discovery
MalwareSVCReady

SVCReady can collect a list of installed software from an infected host.

T1518
Software Discovery
MalwareCharmPower

CharmPower can list the installed applications on a compromised host.

T1518
Software Discovery
MalwareBundlore

Bundlore has the ability to enumerate what browser is being used as well as version information for Safari.

T1518
Software Discovery
MalwareGlassWorm

GlassWorm has searched for existing wallet applications to include Ledger Live and Trezor Suite.

T1518
Software Discovery
MalwareMetamorfo

Metamorfo has searched the compromised system for banking applications.

T1518
Software Discovery
MalwareKGH_SPY

KGH_SPY can collect information on installed applications.

T1518
Software Discovery
Malwaredown_new

down_new has the ability to gather information on installed applications.

T1518
Software Discovery
MalwareRedLine Stealer

RedLine Stealer can get a list of programs on the victim device.

T1518
Software Discovery
MalwareRTM

RTM can scan victim drives to look for specific banking software on the machine to determine next actions.

T1518
Software Discovery
MalwareStrelaStealer

StrelaStealer variants use COM objects to enumerate installed applications from the "AppsFolder" on victim machines.

T1518
Software Discovery
MalwareBazar

Bazar can query the Registry for installed applications.

T1518
Software Discovery
MalwareSUGARDUMP

SUGARDUMP can identify Chrome, Opera, Edge Chromium, and Firefox browsers, including version number, on a compromised host.

T1518
Software Discovery
MalwareCobalt Strike

The Cobalt Strike System Profiler can discover applications through the browser and identify the version of Java the target has.

T1518
Software Discovery
MalwareHotCroissant

HotCroissant can retrieve a list of applications from the SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths registry key.

T1518
Software Discovery
MalwareSamurai

Samurai can check for the presence and version of the .NET framework.

T1518
Software Discovery
MalwareTajMahal

TajMahal has the ability to identify the Internet Explorer (IE) version on an infected host.

T1518
Software Discovery
MalwareRaccoon Stealer

Raccoon Stealer is capable of identifying running software on victim machines.

T1518
Software Discovery
MalwareComRAT

ComRAT can check the victim's default browser to determine which process to inject its communications module into.

T1518
Software Discovery
MalwareLunarWeb

LunarWeb can list installed software on compromised systems.

T1518
Software Discovery
MalwareXCSSET

XCSSET uses ps aux with the grep command to enumerate common browsers and system processes potentially impacting XCSSET's exfiltration capabilities.

T1518
Software Discovery
MalwareQakBot

QakBot can enumerate a list of installed programs.

T1518
Software Discovery
MalwareDridex

Dridex has collected a list of installed software on the system.

T1518
Software Discovery
ToolShimRatReporter

ShimRatReporter gathered a list of installed software on the infected host.

T1518
Software Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has searched for cryptocurrency wallets on targeted hosts.

T1518.001
Security Software Discovery
MalwareBumblebee

Bumblebee can identify specific analytical tools based on running processes.

T1518.001
Security Software Discovery
MalwareAmadey

Amadey has checked for a variety of antivirus products.

T1518.001
Security Software Discovery
MalwareStuxnet

Stuxnet enumerates the currently running processes related to a variety of security products.

T1518.001
Security Software Discovery
MalwarePOWRUNER

POWRUNER may collect information on the victim's anti-virus software.

T1518.001
Security Software Discovery
MalwareTAMECAT

TAMECAT has used Windows Management Instrumentation (WMI) to check for anti-virus products.

T1518.001
Security Software Discovery
MalwareFelismus

Felismus checks for processes associated with anti-virus vendors.

T1518.001
Security Software Discovery
MalwareZeus Panda

Zeus Panda checks to see if anti-virus, anti-spyware, or firewall products are installed in the victim’s environment.

T1518.001
Security Software Discovery
MalwareStrongPity

StrongPity can identify if ESET or BitDefender antivirus are installed before dropping its payload.

T1518.001
Security Software Discovery
MalwarexCaon

xCaon has checked for the existence of Kaspersky antivirus software on the system.

T1518.001
Security Software Discovery
MalwareROAMINGHOUSE

ROAMINGHOUSE can identify McAfee applications on compromised hosts and change its execution method if one is detected.

T1518.001
Security Software Discovery
MalwareTONESHELL

TONESHELL has checked for the presence of ESET antivirus applications `ekrn.exe` and `egui.exe`.

T1518.001
Security Software Discovery
MalwareKasidet

Kasidet has the ability to identify any anti-virus installed on the infected system.

T1518.001
Security Software Discovery
MalwareMedusa Ransomware

Medusa Ransomware has the capability to detect security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables.

T1518.001
Security Software Discovery
MalwareCrimson

Crimson contains a command to collect information about anti-virus software on the victim.

T1518.001
Security Software Discovery
MalwareDUSTTRAP

DUSTTRAP can identify security software.

T1518.001
Security Software Discovery
MalwareAction RAT

Action RAT can identify AV products on an infected host using the following command: `cmd.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List`.

T1518.001
Security Software Discovery
MalwareAvenger

Avenger has the ability to identify installed anti-virus products on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.