ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1518.001×

111 examples

TechniqueUsed byProcedure example
T1518.001
Security Software Discovery
MalwareSplatCloak

SplatCloak has identified drivers of AV solutions by searching for related filenames, keywords and signed certificates.

T1518.001
Security Software Discovery
MalwareWaterbear

Waterbear can find the presence of a specific security software.

T1518.001
Security Software Discovery
MalwareComnie

Comnie attempts to detect several anti-virus products.

T1518.001
Security Software Discovery
MalwareLizar

Lizar can search for processes associated with an anti-virus product from list.

T1518.001
Security Software Discovery
ToolSILENTTRINITY

SILENTTRINITY can determine if an anti-virus product is installed through the resolution of the service's virtual SID.

T1518.001
Security Software Discovery
ToolPacu

Pacu can enumerate AWS security services, including WAF rules and GuardDuty detectors.

T1518.001
Security Software Discovery
ToolTasklist

Tasklist can be used to enumerate security software currently running on a system by process name of known products.

T1518.001
Security Software Discovery
ToolEmpire

Empire can enumerate antivirus software on the target.

T1518.001
Security Software Discovery
Toolnetsh

netsh can be used to discover system firewall settings.

T1518.001
Security Software Discovery
ToolBrute Ratel C4

Brute Ratel C4 can detect EDR userland hooks.

T1518.001
Security Software Discovery
MalwareFlame

Flame identifies security software such as antivirus through the Security module.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.