Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1518.001 Security Software Discovery |
MalwareLiteDuke | LiteDuke has the ability to check for the presence of Kaspersky security software. |
| T1518.001 Security Software Discovery |
MalwareZxxZ | ZxxZ can search a compromised host to determine if it is running Windows Defender or Kasperky antivirus. |
| T1518.001 Security Software Discovery |
MalwareBazar | Bazar can identify the installed antivirus engine. |
| T1518.001 Security Software Discovery |
MalwareBadPatch | BadPatch uses WMI to enumerate installed security products in the victim’s environment. |
| T1518.001 Security Software Discovery |
MalwareHiddenFace | HiddenFace can identify processes identified with security applications and tooling. |
| T1518.001 Security Software Discovery |
MalwareABK | ABK has the ability to identify the installed anti-virus product on the compromised host. |
| T1518.001 Security Software Discovery |
MalwareFinFisher | FinFisher probes the system to check for antimalware processes. |
| T1518.001 Security Software Discovery |
MalwareSUNBURST | SUNBURST checked for a variety of antivirus/endpoint detection agents prior to execution. |
| T1518.001 Security Software Discovery |
MalwareEvilBunny | EvilBunny has been observed querying installed antivirus software. |
| T1518.001 Security Software Discovery |
MalwareWingbird | Wingbird checks for the presence of Bitdefender security software. |
| T1518.001 Security Software Discovery |
MalwareValak | Valak can determine if a compromised host has security products installed. |
| T1518.001 Security Software Discovery |
MalwareTajMahal | TajMahal has the ability to identify which anti-virus products, firewalls, and anti-spyware products are in use. |
| T1518.001 Security Software Discovery |
MalwareGold Dragon | Gold Dragon checks for anti-malware products and processes. |
| T1518.001 Security Software Discovery |
MalwareCarberp | Carberp has queried the infected system's registry searching for specific registry keys associated with antivirus products. |
| T1518.001 Security Software Discovery |
MalwareFunnyDream | FunnyDream can identify the processes for Bkav antivirus. |
| T1518.001 Security Software Discovery |
MalwareMore_eggs | More_eggs can obtain information on installed anti-malware programs. |
| T1518.001 Security Software Discovery |
MalwareClop | Clop can search for processes with antivirus and antimalware product names. |
| T1518.001 Security Software Discovery |
MalwareYAHOYAH | YAHOYAH checks for antimalware solution processes on the system. |
| T1518.001 Security Software Discovery |
MalwareCHOPSTICK | CHOPSTICK checks for antivirus and forensics software. |
| T1518.001 Security Software Discovery |
MalwareFELIXROOT | FELIXROOT checks for installed security software like antivirus and firewall. |
| T1518.001 Security Software Discovery |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has checked where SELinux is enabled on the targeted host. |
| T1518.001 Security Software Discovery |
Malwarebuild_downer | build_downer has the ability to detect if the infected host is running an anti-virus process. |
| T1518.001 Security Software Discovery |
MalwareMeteor | Meteor has the ability to search for Kaspersky Antivirus on a victim's machine. |
| T1518.001 Security Software Discovery |
MalwareJPIN | JPIN checks for the presence of certain security-related processes and deletes its installer/uninstaller component if it identifies any of them. |
| T1518.001 Security Software Discovery |
MalwareLunarWeb | LunarWeb has run shell commands to obtain a list of installed security products. |
| T1518.001 Security Software Discovery |
MalwareXCSSET | XCSSET searches firewall configuration files located in |
| T1518.001 Security Software Discovery |
MalwareCozyCar | The main CozyCar dropper checks whether the victim has an anti-virus product installed. If the installed product is on a predetermined list, the dropper will exit. |
| T1518.001 Security Software Discovery |
MalwarePOWERSTATS | POWERSTATS has detected security tools. |
| T1518.001 Security Software Discovery |
MalwareAstaroth | Astaroth checks for the presence of Avast antivirus in the |
| T1518.001 Security Software Discovery |
MalwareQakBot | QakBot can identify the installed antivirus product on a targeted system. |
| T1518.001 Security Software Discovery |
MalwareCookieMiner | CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found. |
| T1518.001 Security Software Discovery |
MalwareGelsemium | Gelsemium can check for the presence of specific security products. |
| T1518.001 Security Software Discovery |
MalwarejRAT | jRAT can list security software, such as by using WMIC to identify anti-virus products installed on the victim’s machine and to obtain firewall details. |
| T1518.001 Security Software Discovery |
MalwareSplatCloak | SplatCloak has identified drivers of AV solutions by searching for related filenames, keywords and signed certificates. |
| T1518.001 Security Software Discovery |
MalwareWaterbear | Waterbear can find the presence of a specific security software. |
| T1518.001 Security Software Discovery |
MalwareComnie | Comnie attempts to detect several anti-virus products. |
| T1518.001 Security Software Discovery |
MalwareLizar | Lizar can search for processes associated with an anti-virus product from list. |
| T1518.001 Security Software Discovery |
ToolSILENTTRINITY | SILENTTRINITY can determine if an anti-virus product is installed through the resolution of the service's virtual SID. |
| T1518.001 Security Software Discovery |
ToolPacu | Pacu can enumerate AWS security services, including WAF rules and GuardDuty detectors. |
| T1518.001 Security Software Discovery |
ToolTasklist | Tasklist can be used to enumerate security software currently running on a system by process name of known products. |
| T1518.001 Security Software Discovery |
ToolEmpire | Empire can enumerate antivirus software on the target. |
| T1518.001 Security Software Discovery |
Toolnetsh | netsh can be used to discover system firewall settings. |
| T1518.001 Security Software Discovery |
ToolBrute Ratel C4 | Brute Ratel C4 can detect EDR userland hooks. |
| T1518.001 Security Software Discovery |
MalwareFlame | Flame identifies security software such as antivirus through the Security module. |
| T1526 Cloud Service Discovery |
ToolPacu | Pacu can enumerate AWS services, such as CloudTrail and CloudWatch. |
| T1526 Cloud Service Discovery |
ToolAADInternals | AADInternals can enumerate information about a variety of cloud services, such as Office 365 and Sharepoint instances or OpenID Configurations. |
| T1526 Cloud Service Discovery |
ToolROADTools | ROADTools can enumerate Azure AD applications and service principals. |
| T1526 Cloud Service Discovery |
ToolTruffleHog | TruffleHog has the ability to scan code repositories and CI/CD platforms. |
| T1526 Cloud Service Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can search GitHub for Actions runner processes. |
| T1528 Steal Application Access Token |
MalwareShai-Hulud | Shai-Hulud has stolen access tokens and API tokens from with CI/CD pipeline solutions and repositories. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.