ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1518.001×

111 examples

TechniqueUsed byProcedure example
T1518.001
Security Software Discovery
MalwareEVILNUM

EVILNUM can search for anti-virus products on the system.

T1518.001
Security Software Discovery
MalwareMetamorfo

Metamorfo collects a list of installed antivirus software from the victim’s system.

T1518.001
Security Software Discovery
MalwarePipeMon

PipeMon can check for the presence of ESET and Kaspersky security software.

T1518.001
Security Software Discovery
MalwareT9000

T9000 performs checks for various antivirus and security products during installation.

T1518.001
Security Software Discovery
MalwareMoleNet

MoleNet can use WMI commands to check the system for firewall and antivirus software.

T1518.001
Security Software Discovery
MalwareBLUELIGHT

BLUELIGHT can collect a list of anti-virus products installed on a machine.

T1518.001
Security Software Discovery
Malwaredown_new

down_new has the ability to detect anti-virus products and processes on a compromised host.

T1518.001
Security Software Discovery
MalwareMicropsia

Micropsia searches for anti-virus software and firewall products installed on the victim’s machine using WMI.

T1518.001
Security Software Discovery
MalwareRedLine Stealer

RedLine Stealer has identified installed antivirus software on the system.

T1518.001
Security Software Discovery
MalwareStoneDrill

StoneDrill can check for antivirus and antimalware programs.

T1518.001
Security Software Discovery
MalwareRogueRobin

RogueRobin enumerates running processes to search for Wireshark and Windows Sysinternals suite.

T1518.001
Security Software Discovery
MalwareLitePower

LitePower can identify installed AV software.

T1518.001
Security Software Discovery
MalwareStreamEx

StreamEx has the ability to scan for security tools such as firewalls and antivirus tools.

T1518.001
Security Software Discovery
MalwareMosquito

Mosquito's installer searches the Registry and system to see if specific antivirus tools are installed on the system.

T1518.001
Security Software Discovery
MalwareRTM

RTM can obtain information about security software on the victim.

T1518.001
Security Software Discovery
MalwareBlackByte Ransomware

BlackByte Ransomware looks for security software products prior to full execution.

T1518.001
Security Software Discovery
MalwareGrandoreiro

Grandoreiro can list installed security products including the Trusteer and Diebold Warsaw GAS Tecnologia online banking protections.

T1518.001
Security Software Discovery
MalwareLiteDuke

LiteDuke has the ability to check for the presence of Kaspersky security software.

T1518.001
Security Software Discovery
MalwareZxxZ

ZxxZ can search a compromised host to determine if it is running Windows Defender or Kasperky antivirus.

T1518.001
Security Software Discovery
MalwareBazar

Bazar can identify the installed antivirus engine.

T1518.001
Security Software Discovery
MalwareBadPatch

BadPatch uses WMI to enumerate installed security products in the victim’s environment.

T1518.001
Security Software Discovery
MalwareHiddenFace

HiddenFace can identify processes identified with security applications and tooling.

T1518.001
Security Software Discovery
MalwareABK

ABK has the ability to identify the installed anti-virus product on the compromised host.

T1518.001
Security Software Discovery
MalwareFinFisher

FinFisher probes the system to check for antimalware processes.

T1518.001
Security Software Discovery
MalwareSUNBURST

SUNBURST checked for a variety of antivirus/endpoint detection agents prior to execution.

T1518.001
Security Software Discovery
MalwareEvilBunny

EvilBunny has been observed querying installed antivirus software.

T1518.001
Security Software Discovery
MalwareWingbird

Wingbird checks for the presence of Bitdefender security software.

T1518.001
Security Software Discovery
MalwareValak

Valak can determine if a compromised host has security products installed.

T1518.001
Security Software Discovery
MalwareTajMahal

TajMahal has the ability to identify which anti-virus products, firewalls, and anti-spyware products are in use.

T1518.001
Security Software Discovery
MalwareGold Dragon

Gold Dragon checks for anti-malware products and processes.

T1518.001
Security Software Discovery
MalwareCarberp

Carberp has queried the infected system's registry searching for specific registry keys associated with antivirus products.

T1518.001
Security Software Discovery
MalwareFunnyDream

FunnyDream can identify the processes for Bkav antivirus.

T1518.001
Security Software Discovery
MalwareMore_eggs

More_eggs can obtain information on installed anti-malware programs.

T1518.001
Security Software Discovery
MalwareClop

Clop can search for processes with antivirus and antimalware product names.

T1518.001
Security Software Discovery
MalwareYAHOYAH

YAHOYAH checks for antimalware solution processes on the system.

T1518.001
Security Software Discovery
MalwareCHOPSTICK

CHOPSTICK checks for antivirus and forensics software.

T1518.001
Security Software Discovery
MalwareFELIXROOT

FELIXROOT checks for installed security software like antivirus and firewall.

T1518.001
Security Software Discovery
MalwareSPAWNCHIMERA

SPAWNCHIMERA has checked where SELinux is enabled on the targeted host.

T1518.001
Security Software Discovery
Malwarebuild_downer

build_downer has the ability to detect if the infected host is running an anti-virus process.

T1518.001
Security Software Discovery
MalwareMeteor

Meteor has the ability to search for Kaspersky Antivirus on a victim's machine.

T1518.001
Security Software Discovery
MalwareJPIN

JPIN checks for the presence of certain security-related processes and deletes its installer/uninstaller component if it identifies any of them.

T1518.001
Security Software Discovery
MalwareLunarWeb

LunarWeb has run shell commands to obtain a list of installed security products.

T1518.001
Security Software Discovery
MalwareXCSSET

XCSSET searches firewall configuration files located in /Library/Preferences/ and uses csrutil status to determine if System Integrity Protection is enabled.

T1518.001
Security Software Discovery
MalwareCozyCar

The main CozyCar dropper checks whether the victim has an anti-virus product installed. If the installed product is on a predetermined list, the dropper will exit.

T1518.001
Security Software Discovery
MalwarePOWERSTATS

POWERSTATS has detected security tools.

T1518.001
Security Software Discovery
MalwareAstaroth

Astaroth checks for the presence of Avast antivirus in the C:\Program\Files\ folder.

T1518.001
Security Software Discovery
MalwareQakBot

QakBot can identify the installed antivirus product on a targeted system.

T1518.001
Security Software Discovery
MalwareCookieMiner

CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found.

T1518.001
Security Software Discovery
MalwareGelsemium

Gelsemium can check for the presence of specific security products.

T1518.001
Security Software Discovery
MalwarejRAT

jRAT can list security software, such as by using WMIC to identify anti-virus products installed on the victim’s machine and to obtain firewall details.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.