ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1518.001
Security Software Discovery
MalwarePrikormka

A module in Prikormka collects information from the victim about installed anti-virus software.

T1518.001
Security Software Discovery
MalwarePUBLOAD

PUBLOAD has identified AV products on an infected host using the following command: `WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List`.

T1518.001
Security Software Discovery
MalwareWoody RAT

Woody RAT can detect Avast Software, Doctor Web, Kaspersky, AVG, ESET, and Sophos antivirus programs.

T1518.001
Security Software Discovery
MalwareMafalda

Mafalda can search for a variety of security software programs, EDR systems, and malware analysis tools.

T1518.001
Security Software Discovery
MalwareAuTo Stealer

AuTo Stealer has the ability to collect information about installed AV products from an infected host.

T1518.001
Security Software Discovery
MalwareFlawedAmmyy

FlawedAmmyy will attempt to detect anti-virus products during the initial infection.

T1518.001
Security Software Discovery
MalwareInvisiMole

InvisiMole can check for the presence of network sniffers, AV, and BitDefender firewall.

T1518.001
Security Software Discovery
MalwareWhisperGate

WhisperGate can recognize the presence of monitoring tools on a target system.

T1518.001
Security Software Discovery
MalwareSkidmap

Skidmap has the ability to check if /usr/sbin/setenforce exists. This file controls what mode SELinux is in.

T1518.001
Security Software Discovery
MalwareRaspberry Robin

Raspberry Robin attempts to identify security software running on the victim machine, such as BitDefender, Avast, and Kaspersky.

T1518.001
Security Software Discovery
MalwareMispadu

Mispadu can list installed security products in the victim’s environment.

T1518.001
Security Software Discovery
MalwareRustyWater

RustyWater has attempted to detect more than 25 antivirus and EDR tools.

T1518.001
Security Software Discovery
MalwareIcedID

IcedID can identify AV products on an infected host using the following command:
` WMIC.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get * /Format:List`.

T1518.001
Security Software Discovery
MalwareVERMIN

VERMIN uses WMI to check for anti-virus software installed on the system.

T1518.001
Security Software Discovery
MalwareMarkiRAT

MarkiRAT can check for running processes on the victim’s machine to look for Kaspersky and Bitdefender antivirus products.

T1518.001
Security Software Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP is capable of checking whether a compromised device is running DeepFreeze by Faronics.

T1518.001
Security Software Discovery
MalwareNotPetya

NotPetya determines if specific antivirus programs are running on an infected host machine.

T1518.001
Security Software Discovery
MalwareSpicyOmelette

SpicyOmelette can check for the presence of 29 different antivirus tools.

T1518.001
Security Software Discovery
MalwarePUNCHBUGGY

PUNCHBUGGY can gather AVs registered in the system.

T1518.001
Security Software Discovery
MalwareDarkTortilla

DarkTortilla can check for the Kaspersky Anti-Virus suite.

T1518.001
Security Software Discovery
MalwareExbyte

Exbyte checks for the presence of various security software products during execution.

T1518.001
Security Software Discovery
MalwareDarkWatchman

DarkWatchman can search for anti-virus products on the system.

T1518.001
Security Software Discovery
MalwareLumma Stealer

Lumma Stealer has detected antivirus processes using commands such as “tasklist” and “findstr.”

T1518.001
Security Software Discovery
MalwareDustySky

DustySky checks for the existence of anti-virus.

T1518.001
Security Software Discovery
MalwareRemsec

Remsec has a plugin detect security products via active drivers.

T1518.001
Security Software Discovery
MalwareEpic

Epic searches for anti-malware services running on the victim’s machine and terminates itself if it finds them.

T1518.001
Security Software Discovery
MalwarePureCrypter

PureCrypter can identify installed antivirus solutions.

T1518.001
Security Software Discovery
MalwareDarkGate

DarkGate looks for various security products by process name using hard-coded values in the malware. DarkGate will not execute its keylogging thread if a process name associated with Trend Micro anti-virus is identified, or if runtime checks identify the presence of Kaspersky anti-virus. DarkGate will initiate a new thread if certain security products are identified on the victim, and recreate any malicious files associated with it if it determines they were removed by security software in a new system location.

T1518.001
Security Software Discovery
MalwareThiefQuest

ThiefQuest uses the kill_unwanted function to get a list of running processes, compares each process with an encrypted list of “unwanted” security related programs, and kills the processes for security related programs.

T1518.001
Security Software Discovery
MalwareFerocious

Ferocious has checked for AV software as part of its persistence process.

T1518.001
Security Software Discovery
MalwareNetwalker

Netwalker can detect and terminate active security software-related processes on infected systems.

T1518.001
Security Software Discovery
MalwareLatrodectus

Latrodectus has the ability to identify installed antivirus products.

T1518.001
Security Software Discovery
MalwareMuddyViper

MuddyViper has the ability to check for a specified list of security tools in the compromised environment.

T1518.001
Security Software Discovery
MalwareEVILNUM

EVILNUM can search for anti-virus products on the system.

T1518.001
Security Software Discovery
MalwareMetamorfo

Metamorfo collects a list of installed antivirus software from the victim’s system.

T1518.001
Security Software Discovery
MalwarePipeMon

PipeMon can check for the presence of ESET and Kaspersky security software.

T1518.001
Security Software Discovery
MalwareT9000

T9000 performs checks for various antivirus and security products during installation.

T1518.001
Security Software Discovery
MalwareMoleNet

MoleNet can use WMI commands to check the system for firewall and antivirus software.

T1518.001
Security Software Discovery
MalwareBLUELIGHT

BLUELIGHT can collect a list of anti-virus products installed on a machine.

T1518.001
Security Software Discovery
Malwaredown_new

down_new has the ability to detect anti-virus products and processes on a compromised host.

T1518.001
Security Software Discovery
MalwareMicropsia

Micropsia searches for anti-virus software and firewall products installed on the victim’s machine using WMI.

T1518.001
Security Software Discovery
MalwareRedLine Stealer

RedLine Stealer has identified installed antivirus software on the system.

T1518.001
Security Software Discovery
MalwareStoneDrill

StoneDrill can check for antivirus and antimalware programs.

T1518.001
Security Software Discovery
MalwareRogueRobin

RogueRobin enumerates running processes to search for Wireshark and Windows Sysinternals suite.

T1518.001
Security Software Discovery
MalwareLitePower

LitePower can identify installed AV software.

T1518.001
Security Software Discovery
MalwareStreamEx

StreamEx has the ability to scan for security tools such as firewalls and antivirus tools.

T1518.001
Security Software Discovery
MalwareMosquito

Mosquito's installer searches the Registry and system to see if specific antivirus tools are installed on the system.

T1518.001
Security Software Discovery
MalwareRTM

RTM can obtain information about security software on the victim.

T1518.001
Security Software Discovery
MalwareBlackByte Ransomware

BlackByte Ransomware looks for security software products prior to full execution.

T1518.001
Security Software Discovery
MalwareGrandoreiro

Grandoreiro can list installed security products including the Trusteer and Diebold Warsaw GAS Tecnologia online banking protections.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.