Real-world descriptions of how a group, tool or campaign used a technique.
111 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1518.001 Security Software Discovery |
MalwareSplatCloak | SplatCloak has identified drivers of AV solutions by searching for related filenames, keywords and signed certificates. |
| T1518.001 Security Software Discovery |
MalwareWaterbear | Waterbear can find the presence of a specific security software. |
| T1518.001 Security Software Discovery |
MalwareComnie | Comnie attempts to detect several anti-virus products. |
| T1518.001 Security Software Discovery |
MalwareLizar | Lizar can search for processes associated with an anti-virus product from list. |
| T1518.001 Security Software Discovery |
ToolSILENTTRINITY | SILENTTRINITY can determine if an anti-virus product is installed through the resolution of the service's virtual SID. |
| T1518.001 Security Software Discovery |
ToolPacu | Pacu can enumerate AWS security services, including WAF rules and GuardDuty detectors. |
| T1518.001 Security Software Discovery |
ToolTasklist | Tasklist can be used to enumerate security software currently running on a system by process name of known products. |
| T1518.001 Security Software Discovery |
ToolEmpire | Empire can enumerate antivirus software on the target. |
| T1518.001 Security Software Discovery |
Toolnetsh | netsh can be used to discover system firewall settings. |
| T1518.001 Security Software Discovery |
ToolBrute Ratel C4 | Brute Ratel C4 can detect EDR userland hooks. |
| T1518.001 Security Software Discovery |
MalwareFlame | Flame identifies security software such as antivirus through the Security module. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.