Real-world descriptions of how a group, tool or campaign used a technique.
39 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1518 Software Discovery |
MalwareOrz | Orz can gather the victim's Internet Explorer version. |
| T1518 Software Discovery |
MalwareIronWind | IronWind can list installed software on targeted hosts. |
| T1518 Software Discovery |
MalwareInvisibleFerret | InvisibleFerret has gathered installed programs and running processes. |
| T1518 Software Discovery |
MalwarePUBLOAD | PUBLOAD has used several commands executed in sequence via `cmd` in a short interval to gather software versions including querying Registry keys. |
| T1518 Software Discovery |
MalwareWoody RAT | Woody RAT can collect .NET, PowerShell, and Python information from an infected host. |
| T1518 Software Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer has the ability to search systems for installed applications. |
| T1518 Software Discovery |
MalwareInvisiMole | InvisiMole can collect information about installed software used by specific users, software executed on user login, and software executed by each system. |
| T1518 Software Discovery |
MalwareP.A.S. Webshell | P.A.S. Webshell can list PHP server configuration details. |
| T1518 Software Discovery |
MalwareSiloscape | Siloscape searches for the kubectl binary. |
| T1518 Software Discovery |
MalwareMarkiRAT | MarkiRAT can check for the Telegram installation directory by enumerating the files on disk. |
| T1518 Software Discovery |
MalwareSocGholish | SocGholish can identify the victim's browser in order to serve the correct fake update page. |
| T1518 Software Discovery |
MalwareSpicyOmelette | SpicyOmelette can enumerate running software on a targeted system. |
| T1518 Software Discovery |
MalwareLightSpy | If sent the command `16001`, LightSpy uses the `NSFileManger contentsOfDirectoryAtPath()` to enumerate the Applications folder to collect the bundle name, bundle identifier, and version information from each application's `info.plist` file. The results are then converted into a JSON blob for exfiltration. |
| T1518 Software Discovery |
MalwareDyre | Dyre has the ability to identify installed programs on a compromised host. |
| T1518 Software Discovery |
MalwareDustySky | DustySky lists all installed software for the infected machine. |
| T1518 Software Discovery |
MalwareSVCReady | SVCReady can collect a list of installed software from an infected host. |
| T1518 Software Discovery |
MalwareCharmPower | CharmPower can list the installed applications on a compromised host. |
| T1518 Software Discovery |
MalwareBundlore | Bundlore has the ability to enumerate what browser is being used as well as version information for Safari. |
| T1518 Software Discovery |
MalwareGlassWorm | GlassWorm has searched for existing wallet applications to include Ledger Live and Trezor Suite. |
| T1518 Software Discovery |
MalwareMetamorfo | Metamorfo has searched the compromised system for banking applications. |
| T1518 Software Discovery |
MalwareKGH_SPY | KGH_SPY can collect information on installed applications. |
| T1518 Software Discovery |
Malwaredown_new | down_new has the ability to gather information on installed applications. |
| T1518 Software Discovery |
MalwareRedLine Stealer | RedLine Stealer can get a list of programs on the victim device. |
| T1518 Software Discovery |
MalwareRTM | RTM can scan victim drives to look for specific banking software on the machine to determine next actions. |
| T1518 Software Discovery |
MalwareStrelaStealer | StrelaStealer variants use COM objects to enumerate installed applications from the "AppsFolder" on victim machines. |
| T1518 Software Discovery |
MalwareBazar | Bazar can query the Registry for installed applications. |
| T1518 Software Discovery |
MalwareSUGARDUMP | SUGARDUMP can identify Chrome, Opera, Edge Chromium, and Firefox browsers, including version number, on a compromised host. |
| T1518 Software Discovery |
MalwareCobalt Strike | The Cobalt Strike System Profiler can discover applications through the browser and identify the version of Java the target has. |
| T1518 Software Discovery |
MalwareHotCroissant | HotCroissant can retrieve a list of applications from the |
| T1518 Software Discovery |
MalwareSamurai | Samurai can check for the presence and version of the .NET framework. |
| T1518 Software Discovery |
MalwareTajMahal | TajMahal has the ability to identify the Internet Explorer (IE) version on an infected host. |
| T1518 Software Discovery |
MalwareRaccoon Stealer | Raccoon Stealer is capable of identifying running software on victim machines. |
| T1518 Software Discovery |
MalwareComRAT | ComRAT can check the victim's default browser to determine which process to inject its communications module into. |
| T1518 Software Discovery |
MalwareLunarWeb | LunarWeb can list installed software on compromised systems. |
| T1518 Software Discovery |
MalwareXCSSET | XCSSET uses |
| T1518 Software Discovery |
MalwareQakBot | QakBot can enumerate a list of installed programs. |
| T1518 Software Discovery |
MalwareDridex | Dridex has collected a list of installed software on the system. |
| T1518 Software Discovery |
ToolShimRatReporter | ShimRatReporter gathered a list of installed software on the infected host. |
| T1518 Software Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has searched for cryptocurrency wallets on targeted hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.