Real-world descriptions of how a group, tool or campaign used a technique.
111 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1518.001 Security Software Discovery |
MalwareEVILNUM | EVILNUM can search for anti-virus products on the system. |
| T1518.001 Security Software Discovery |
MalwareMetamorfo | Metamorfo collects a list of installed antivirus software from the victim’s system. |
| T1518.001 Security Software Discovery |
MalwarePipeMon | PipeMon can check for the presence of ESET and Kaspersky security software. |
| T1518.001 Security Software Discovery |
MalwareT9000 | T9000 performs checks for various antivirus and security products during installation. |
| T1518.001 Security Software Discovery |
MalwareMoleNet | MoleNet can use WMI commands to check the system for firewall and antivirus software. |
| T1518.001 Security Software Discovery |
MalwareBLUELIGHT | BLUELIGHT can collect a list of anti-virus products installed on a machine. |
| T1518.001 Security Software Discovery |
Malwaredown_new | down_new has the ability to detect anti-virus products and processes on a compromised host. |
| T1518.001 Security Software Discovery |
MalwareMicropsia | Micropsia searches for anti-virus software and firewall products installed on the victim’s machine using WMI. |
| T1518.001 Security Software Discovery |
MalwareRedLine Stealer | RedLine Stealer has identified installed antivirus software on the system. |
| T1518.001 Security Software Discovery |
MalwareStoneDrill | StoneDrill can check for antivirus and antimalware programs. |
| T1518.001 Security Software Discovery |
MalwareRogueRobin | RogueRobin enumerates running processes to search for Wireshark and Windows Sysinternals suite. |
| T1518.001 Security Software Discovery |
MalwareLitePower | LitePower can identify installed AV software. |
| T1518.001 Security Software Discovery |
MalwareStreamEx | StreamEx has the ability to scan for security tools such as firewalls and antivirus tools. |
| T1518.001 Security Software Discovery |
MalwareMosquito | Mosquito's installer searches the Registry and system to see if specific antivirus tools are installed on the system. |
| T1518.001 Security Software Discovery |
MalwareRTM | RTM can obtain information about security software on the victim. |
| T1518.001 Security Software Discovery |
MalwareBlackByte Ransomware | BlackByte Ransomware looks for security software products prior to full execution. |
| T1518.001 Security Software Discovery |
MalwareGrandoreiro | Grandoreiro can list installed security products including the Trusteer and Diebold Warsaw GAS Tecnologia online banking protections. |
| T1518.001 Security Software Discovery |
MalwareLiteDuke | LiteDuke has the ability to check for the presence of Kaspersky security software. |
| T1518.001 Security Software Discovery |
MalwareZxxZ | ZxxZ can search a compromised host to determine if it is running Windows Defender or Kasperky antivirus. |
| T1518.001 Security Software Discovery |
MalwareBazar | Bazar can identify the installed antivirus engine. |
| T1518.001 Security Software Discovery |
MalwareBadPatch | BadPatch uses WMI to enumerate installed security products in the victim’s environment. |
| T1518.001 Security Software Discovery |
MalwareHiddenFace | HiddenFace can identify processes identified with security applications and tooling. |
| T1518.001 Security Software Discovery |
MalwareABK | ABK has the ability to identify the installed anti-virus product on the compromised host. |
| T1518.001 Security Software Discovery |
MalwareFinFisher | FinFisher probes the system to check for antimalware processes. |
| T1518.001 Security Software Discovery |
MalwareSUNBURST | SUNBURST checked for a variety of antivirus/endpoint detection agents prior to execution. |
| T1518.001 Security Software Discovery |
MalwareEvilBunny | EvilBunny has been observed querying installed antivirus software. |
| T1518.001 Security Software Discovery |
MalwareWingbird | Wingbird checks for the presence of Bitdefender security software. |
| T1518.001 Security Software Discovery |
MalwareValak | Valak can determine if a compromised host has security products installed. |
| T1518.001 Security Software Discovery |
MalwareTajMahal | TajMahal has the ability to identify which anti-virus products, firewalls, and anti-spyware products are in use. |
| T1518.001 Security Software Discovery |
MalwareGold Dragon | Gold Dragon checks for anti-malware products and processes. |
| T1518.001 Security Software Discovery |
MalwareCarberp | Carberp has queried the infected system's registry searching for specific registry keys associated with antivirus products. |
| T1518.001 Security Software Discovery |
MalwareFunnyDream | FunnyDream can identify the processes for Bkav antivirus. |
| T1518.001 Security Software Discovery |
MalwareMore_eggs | More_eggs can obtain information on installed anti-malware programs. |
| T1518.001 Security Software Discovery |
MalwareClop | Clop can search for processes with antivirus and antimalware product names. |
| T1518.001 Security Software Discovery |
MalwareYAHOYAH | YAHOYAH checks for antimalware solution processes on the system. |
| T1518.001 Security Software Discovery |
MalwareCHOPSTICK | CHOPSTICK checks for antivirus and forensics software. |
| T1518.001 Security Software Discovery |
MalwareFELIXROOT | FELIXROOT checks for installed security software like antivirus and firewall. |
| T1518.001 Security Software Discovery |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has checked where SELinux is enabled on the targeted host. |
| T1518.001 Security Software Discovery |
Malwarebuild_downer | build_downer has the ability to detect if the infected host is running an anti-virus process. |
| T1518.001 Security Software Discovery |
MalwareMeteor | Meteor has the ability to search for Kaspersky Antivirus on a victim's machine. |
| T1518.001 Security Software Discovery |
MalwareJPIN | JPIN checks for the presence of certain security-related processes and deletes its installer/uninstaller component if it identifies any of them. |
| T1518.001 Security Software Discovery |
MalwareLunarWeb | LunarWeb has run shell commands to obtain a list of installed security products. |
| T1518.001 Security Software Discovery |
MalwareXCSSET | XCSSET searches firewall configuration files located in |
| T1518.001 Security Software Discovery |
MalwareCozyCar | The main CozyCar dropper checks whether the victim has an anti-virus product installed. If the installed product is on a predetermined list, the dropper will exit. |
| T1518.001 Security Software Discovery |
MalwarePOWERSTATS | POWERSTATS has detected security tools. |
| T1518.001 Security Software Discovery |
MalwareAstaroth | Astaroth checks for the presence of Avast antivirus in the |
| T1518.001 Security Software Discovery |
MalwareQakBot | QakBot can identify the installed antivirus product on a targeted system. |
| T1518.001 Security Software Discovery |
MalwareCookieMiner | CookieMiner has checked for the presence of "Little Snitch", macOS network monitoring and application firewall software, stopping and exiting if it is found. |
| T1518.001 Security Software Discovery |
MalwareGelsemium | Gelsemium can check for the presence of specific security products. |
| T1518.001 Security Software Discovery |
MalwarejRAT | jRAT can list security software, such as by using WMIC to identify anti-virus products installed on the victim’s machine and to obtain firewall details. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.