ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1518.001
Security Software Discovery
MalwareLiteDuke

LiteDuke has the ability to check for the presence of Kaspersky security software.

T1518.001
Security Software Discovery
MalwareZxxZ

ZxxZ can search a compromised host to determine if it is running Windows Defender or Kasperky antivirus.

T1518.001
Security Software Discovery
MalwareBazar

Bazar can identify the installed antivirus engine.

T1518.001
Security Software Discovery
MalwareBadPatch

BadPatch uses WMI to enumerate installed security products in the victim’s environment.

T1518.001
Security Software Discovery
MalwareHiddenFace

HiddenFace can identify processes identified with security applications and tooling.

T1518.001
Security Software Discovery
MalwareABK

ABK has the ability to identify the installed anti-virus product on the compromised host.

T1518.001
Security Software Discovery
MalwareFinFisher

FinFisher probes the system to check for antimalware processes.

T1518.001
Security Software Discovery
MalwareSUNBURST

SUNBURST checked for a variety of antivirus/endpoint detection agents prior to execution.

T1518.001
Security Software Discovery
MalwareEvilBunny

EvilBunny has been observed querying installed antivirus software.

T1518.001
Security Software Discovery
MalwareWingbird

Wingbird checks for the presence of Bitdefender security software.

T1518.001
Security Software Discovery
MalwareValak

Valak can determine if a compromised host has security products installed.

T1518.001
Security Software Discovery
MalwareTajMahal

TajMahal has the ability to identify which anti-virus products, firewalls, and anti-spyware products are in use.

T1518.001
Security Software Discovery
MalwareGold Dragon

Gold Dragon checks for anti-malware products and processes.

T1518.001
Security Software Discovery
MalwareCarberp

Carberp has queried the infected system's registry searching for specific registry keys associated with antivirus products.

T1518.001
Security Software Discovery
MalwareFunnyDream

FunnyDream can identify the processes for Bkav antivirus.

T1518.001
Security Software Discovery
MalwareMore_eggs

More_eggs can obtain information on installed anti-malware programs.

T1518.001
Security Software Discovery
MalwareClop

Clop can search for processes with antivirus and antimalware product names.

T1518.001
Security Software Discovery
MalwareYAHOYAH

YAHOYAH checks for antimalware solution processes on the system.

T1518.001
Security Software Discovery
MalwareCHOPSTICK

CHOPSTICK checks for antivirus and forensics software.

T1518.001
Security Software Discovery
MalwareFELIXROOT

FELIXROOT checks for installed security software like antivirus and firewall.

T1518.001
Security Software Discovery
MalwareSPAWNCHIMERA

SPAWNCHIMERA has checked where SELinux is enabled on the targeted host.

T1518.001
Security Software Discovery
Malwarebuild_downer

build_downer has the ability to detect if the infected host is running an anti-virus process.

T1518.001
Security Software Discovery
MalwareMeteor

Meteor has the ability to search for Kaspersky Antivirus on a victim's machine.

T1518.001
Security Software Discovery
MalwareJPIN

JPIN checks for the presence of certain security-related processes and deletes its installer/uninstaller component if it identifies any of them.

T1518.001
Security Software Discovery
MalwareLunarWeb

LunarWeb has run shell commands to obtain a list of installed security products.

T1518.001
Security Software Discovery
MalwareXCSSET

XCSSET searches firewall configuration files located in /Library/Preferences/ and uses csrutil status to determine if System Integrity Protection is enabled.

T1518.001
Security Software Discovery
MalwareCozyCar

The main CozyCar dropper checks whether the victim has an anti-virus product installed. If the installed product is on a predetermined list, the dropper will exit.

T1518.001
Security Software Discovery
MalwarePOWERSTATS

POWERSTATS has detected security tools.

T1518.001
Security Software Discovery
MalwareAstaroth

Astaroth checks for the presence of Avast antivirus in the C:\Program\Files\ folder.

T1518.001
Security Software Discovery
MalwareQakBot

QakBot can identify the installed antivirus product on a targeted system.

T1518.001
Security Software Discovery
MalwareCookieMiner

CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found.

T1518.001
Security Software Discovery
MalwareGelsemium

Gelsemium can check for the presence of specific security products.

T1518.001
Security Software Discovery
MalwarejRAT

jRAT can list security software, such as by using WMIC to identify anti-virus products installed on the victim’s machine and to obtain firewall details.

T1518.001
Security Software Discovery
MalwareSplatCloak

SplatCloak has identified drivers of AV solutions by searching for related filenames, keywords and signed certificates.

T1518.001
Security Software Discovery
MalwareWaterbear

Waterbear can find the presence of a specific security software.

T1518.001
Security Software Discovery
MalwareComnie

Comnie attempts to detect several anti-virus products.

T1518.001
Security Software Discovery
MalwareLizar

Lizar can search for processes associated with an anti-virus product from list.

T1518.001
Security Software Discovery
ToolSILENTTRINITY

SILENTTRINITY can determine if an anti-virus product is installed through the resolution of the service's virtual SID.

T1518.001
Security Software Discovery
ToolPacu

Pacu can enumerate AWS security services, including WAF rules and GuardDuty detectors.

T1518.001
Security Software Discovery
ToolTasklist

Tasklist can be used to enumerate security software currently running on a system by process name of known products.

T1518.001
Security Software Discovery
ToolEmpire

Empire can enumerate antivirus software on the target.

T1518.001
Security Software Discovery
Toolnetsh

netsh can be used to discover system firewall settings.

T1518.001
Security Software Discovery
ToolBrute Ratel C4

Brute Ratel C4 can detect EDR userland hooks.

T1518.001
Security Software Discovery
MalwareFlame

Flame identifies security software such as antivirus through the Security module.

T1526
Cloud Service Discovery
ToolPacu

Pacu can enumerate AWS services, such as CloudTrail and CloudWatch.

T1526
Cloud Service Discovery
ToolAADInternals

AADInternals can enumerate information about a variety of cloud services, such as Office 365 and Sharepoint instances or OpenID Configurations.

T1526
Cloud Service Discovery
ToolROADTools

ROADTools can enumerate Azure AD applications and service principals.

T1526
Cloud Service Discovery
ToolTruffleHog

TruffleHog has the ability to scan code repositories and CI/CD platforms.

T1526
Cloud Service Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can search GitHub for Actions runner processes.

T1528
Steal Application Access Token
MalwareShai-Hulud

Shai-Hulud has stolen access tokens and API tokens from with CI/CD pipeline solutions and repositories.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.