Real-world descriptions of how a group, tool or campaign used a technique.
11 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1518 Software Discovery |
GroupSideCopy | SideCopy has collected browser information from a compromised host. |
| T1518 Software Discovery |
GroupVolt Typhoon | Volt Typhoon has queried the Registry on compromised systems for information on installed software. |
| T1518 Software Discovery |
GroupMuddyWater | MuddyWater has used a PowerShell backdoor to check for Skype connectivity on the target machine. |
| T1518 Software Discovery |
GroupSidewinder | Sidewinder has used tools to enumerate software installed on an infected host. |
| T1518 Software Discovery |
GroupMustang Panda | Mustang Panda has searched the victim system for the |
| T1518 Software Discovery |
GroupWindigo | Windigo has used a script to detect installed software on targeted systems. |
| T1518 Software Discovery |
GroupTropic Trooper | Tropic Trooper's backdoor could list the infected system's installed software. |
| T1518 Software Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER has used tools to enumerate software installed on an infected host. |
| T1518 Software Discovery |
GroupWindshift | Windshift has used malware to identify installed software. |
| T1518 Software Discovery |
GroupInception | Inception has enumerated installed software on compromised systems. |
| T1518 Software Discovery |
GroupHEXANE | HEXANE has enumerated programs installed on an infected machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.