Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1518.001 Security Software Discovery |
MalwarePrikormka | A module in Prikormka collects information from the victim about installed anti-virus software. |
| T1518.001 Security Software Discovery |
MalwarePUBLOAD | PUBLOAD has identified AV products on an infected host using the following command: `WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List`. |
| T1518.001 Security Software Discovery |
MalwareWoody RAT | Woody RAT can detect Avast Software, Doctor Web, Kaspersky, AVG, ESET, and Sophos antivirus programs. |
| T1518.001 Security Software Discovery |
MalwareMafalda | Mafalda can search for a variety of security software programs, EDR systems, and malware analysis tools. |
| T1518.001 Security Software Discovery |
MalwareAuTo Stealer | AuTo Stealer has the ability to collect information about installed AV products from an infected host. |
| T1518.001 Security Software Discovery |
MalwareFlawedAmmyy | FlawedAmmyy will attempt to detect anti-virus products during the initial infection. |
| T1518.001 Security Software Discovery |
MalwareInvisiMole | InvisiMole can check for the presence of network sniffers, AV, and BitDefender firewall. |
| T1518.001 Security Software Discovery |
MalwareWhisperGate | WhisperGate can recognize the presence of monitoring tools on a target system. |
| T1518.001 Security Software Discovery |
MalwareSkidmap | Skidmap has the ability to check if |
| T1518.001 Security Software Discovery |
MalwareRaspberry Robin | Raspberry Robin attempts to identify security software running on the victim machine, such as BitDefender, Avast, and Kaspersky. |
| T1518.001 Security Software Discovery |
MalwareMispadu | Mispadu can list installed security products in the victim’s environment. |
| T1518.001 Security Software Discovery |
MalwareRustyWater | RustyWater has attempted to detect more than 25 antivirus and EDR tools. |
| T1518.001 Security Software Discovery |
MalwareIcedID | IcedID can identify AV products on an infected host using the following command: |
| T1518.001 Security Software Discovery |
MalwareVERMIN | VERMIN uses WMI to check for anti-virus software installed on the system. |
| T1518.001 Security Software Discovery |
MalwareMarkiRAT | MarkiRAT can check for running processes on the victim’s machine to look for Kaspersky and Bitdefender antivirus products. |
| T1518.001 Security Software Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP is capable of checking whether a compromised device is running DeepFreeze by Faronics. |
| T1518.001 Security Software Discovery |
MalwareNotPetya | NotPetya determines if specific antivirus programs are running on an infected host machine. |
| T1518.001 Security Software Discovery |
MalwareSpicyOmelette | SpicyOmelette can check for the presence of 29 different antivirus tools. |
| T1518.001 Security Software Discovery |
MalwarePUNCHBUGGY | PUNCHBUGGY can gather AVs registered in the system. |
| T1518.001 Security Software Discovery |
MalwareDarkTortilla | DarkTortilla can check for the Kaspersky Anti-Virus suite. |
| T1518.001 Security Software Discovery |
MalwareExbyte | Exbyte checks for the presence of various security software products during execution. |
| T1518.001 Security Software Discovery |
MalwareDarkWatchman | DarkWatchman can search for anti-virus products on the system. |
| T1518.001 Security Software Discovery |
MalwareLumma Stealer | Lumma Stealer has detected antivirus processes using commands such as “tasklist” and “findstr.” |
| T1518.001 Security Software Discovery |
MalwareDustySky | DustySky checks for the existence of anti-virus. |
| T1518.001 Security Software Discovery |
MalwareRemsec | Remsec has a plugin detect security products via active drivers. |
| T1518.001 Security Software Discovery |
MalwareEpic | Epic searches for anti-malware services running on the victim’s machine and terminates itself if it finds them. |
| T1518.001 Security Software Discovery |
MalwarePureCrypter | PureCrypter can identify installed antivirus solutions. |
| T1518.001 Security Software Discovery |
MalwareDarkGate | DarkGate looks for various security products by process name using hard-coded values in the malware. DarkGate will not execute its keylogging thread if a process name associated with Trend Micro anti-virus is identified, or if runtime checks identify the presence of Kaspersky anti-virus. DarkGate will initiate a new thread if certain security products are identified on the victim, and recreate any malicious files associated with it if it determines they were removed by security software in a new system location. |
| T1518.001 Security Software Discovery |
MalwareThiefQuest | ThiefQuest uses the |
| T1518.001 Security Software Discovery |
MalwareFerocious | Ferocious has checked for AV software as part of its persistence process. |
| T1518.001 Security Software Discovery |
MalwareNetwalker | Netwalker can detect and terminate active security software-related processes on infected systems. |
| T1518.001 Security Software Discovery |
MalwareLatrodectus | Latrodectus has the ability to identify installed antivirus products. |
| T1518.001 Security Software Discovery |
MalwareMuddyViper | MuddyViper has the ability to check for a specified list of security tools in the compromised environment. |
| T1518.001 Security Software Discovery |
MalwareEVILNUM | EVILNUM can search for anti-virus products on the system. |
| T1518.001 Security Software Discovery |
MalwareMetamorfo | Metamorfo collects a list of installed antivirus software from the victim’s system. |
| T1518.001 Security Software Discovery |
MalwarePipeMon | PipeMon can check for the presence of ESET and Kaspersky security software. |
| T1518.001 Security Software Discovery |
MalwareT9000 | T9000 performs checks for various antivirus and security products during installation. |
| T1518.001 Security Software Discovery |
MalwareMoleNet | MoleNet can use WMI commands to check the system for firewall and antivirus software. |
| T1518.001 Security Software Discovery |
MalwareBLUELIGHT | BLUELIGHT can collect a list of anti-virus products installed on a machine. |
| T1518.001 Security Software Discovery |
Malwaredown_new | down_new has the ability to detect anti-virus products and processes on a compromised host. |
| T1518.001 Security Software Discovery |
MalwareMicropsia | Micropsia searches for anti-virus software and firewall products installed on the victim’s machine using WMI. |
| T1518.001 Security Software Discovery |
MalwareRedLine Stealer | RedLine Stealer has identified installed antivirus software on the system. |
| T1518.001 Security Software Discovery |
MalwareStoneDrill | StoneDrill can check for antivirus and antimalware programs. |
| T1518.001 Security Software Discovery |
MalwareRogueRobin | RogueRobin enumerates running processes to search for Wireshark and Windows Sysinternals suite. |
| T1518.001 Security Software Discovery |
MalwareLitePower | LitePower can identify installed AV software. |
| T1518.001 Security Software Discovery |
MalwareStreamEx | StreamEx has the ability to scan for security tools such as firewalls and antivirus tools. |
| T1518.001 Security Software Discovery |
MalwareMosquito | Mosquito's installer searches the Registry and system to see if specific antivirus tools are installed on the system. |
| T1518.001 Security Software Discovery |
MalwareRTM | RTM can obtain information about security software on the victim. |
| T1518.001 Security Software Discovery |
MalwareBlackByte Ransomware | BlackByte Ransomware looks for security software products prior to full execution. |
| T1518.001 Security Software Discovery |
MalwareGrandoreiro | Grandoreiro can list installed security products including the Trusteer and Diebold Warsaw GAS Tecnologia online banking protections. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.