ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1518×

39 examples

TechniqueUsed byProcedure example
T1518
Software Discovery
MalwareOrz

Orz can gather the victim's Internet Explorer version.

T1518
Software Discovery
MalwareIronWind

IronWind can list installed software on targeted hosts.

T1518
Software Discovery
MalwareInvisibleFerret

InvisibleFerret has gathered installed programs and running processes.

T1518
Software Discovery
MalwarePUBLOAD

PUBLOAD has used several commands executed in sequence via `cmd` in a short interval to gather software versions including querying Registry keys.

T1518
Software Discovery
MalwareWoody RAT

Woody RAT can collect .NET, PowerShell, and Python information from an infected host.

T1518
Software Discovery
MalwareCuckoo Stealer

Cuckoo Stealer has the ability to search systems for installed applications.

T1518
Software Discovery
MalwareInvisiMole

InvisiMole can collect information about installed software used by specific users, software executed on user login, and software executed by each system.

T1518
Software Discovery
MalwareP.A.S. Webshell

P.A.S. Webshell can list PHP server configuration details.

T1518
Software Discovery
MalwareSiloscape

Siloscape searches for the kubectl binary.

T1518
Software Discovery
MalwareMarkiRAT

MarkiRAT can check for the Telegram installation directory by enumerating the files on disk.

T1518
Software Discovery
MalwareSocGholish

SocGholish can identify the victim's browser in order to serve the correct fake update page.

T1518
Software Discovery
MalwareSpicyOmelette

SpicyOmelette can enumerate running software on a targeted system.

T1518
Software Discovery
MalwareLightSpy

If sent the command `16001`, LightSpy uses the `NSFileManger contentsOfDirectoryAtPath()` to enumerate the Applications folder to collect the bundle name, bundle identifier, and version information from each application's `info.plist` file. The results are then converted into a JSON blob for exfiltration.

T1518
Software Discovery
MalwareDyre

Dyre has the ability to identify installed programs on a compromised host.

T1518
Software Discovery
MalwareDustySky

DustySky lists all installed software for the infected machine.

T1518
Software Discovery
MalwareSVCReady

SVCReady can collect a list of installed software from an infected host.

T1518
Software Discovery
MalwareCharmPower

CharmPower can list the installed applications on a compromised host.

T1518
Software Discovery
MalwareBundlore

Bundlore has the ability to enumerate what browser is being used as well as version information for Safari.

T1518
Software Discovery
MalwareGlassWorm

GlassWorm has searched for existing wallet applications to include Ledger Live and Trezor Suite.

T1518
Software Discovery
MalwareMetamorfo

Metamorfo has searched the compromised system for banking applications.

T1518
Software Discovery
MalwareKGH_SPY

KGH_SPY can collect information on installed applications.

T1518
Software Discovery
Malwaredown_new

down_new has the ability to gather information on installed applications.

T1518
Software Discovery
MalwareRedLine Stealer

RedLine Stealer can get a list of programs on the victim device.

T1518
Software Discovery
MalwareRTM

RTM can scan victim drives to look for specific banking software on the machine to determine next actions.

T1518
Software Discovery
MalwareStrelaStealer

StrelaStealer variants use COM objects to enumerate installed applications from the "AppsFolder" on victim machines.

T1518
Software Discovery
MalwareBazar

Bazar can query the Registry for installed applications.

T1518
Software Discovery
MalwareSUGARDUMP

SUGARDUMP can identify Chrome, Opera, Edge Chromium, and Firefox browsers, including version number, on a compromised host.

T1518
Software Discovery
MalwareCobalt Strike

The Cobalt Strike System Profiler can discover applications through the browser and identify the version of Java the target has.

T1518
Software Discovery
MalwareHotCroissant

HotCroissant can retrieve a list of applications from the SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths registry key.

T1518
Software Discovery
MalwareSamurai

Samurai can check for the presence and version of the .NET framework.

T1518
Software Discovery
MalwareTajMahal

TajMahal has the ability to identify the Internet Explorer (IE) version on an infected host.

T1518
Software Discovery
MalwareRaccoon Stealer

Raccoon Stealer is capable of identifying running software on victim machines.

T1518
Software Discovery
MalwareComRAT

ComRAT can check the victim's default browser to determine which process to inject its communications module into.

T1518
Software Discovery
MalwareLunarWeb

LunarWeb can list installed software on compromised systems.

T1518
Software Discovery
MalwareXCSSET

XCSSET uses ps aux with the grep command to enumerate common browsers and system processes potentially impacting XCSSET's exfiltration capabilities.

T1518
Software Discovery
MalwareQakBot

QakBot can enumerate a list of installed programs.

T1518
Software Discovery
MalwareDridex

Dridex has collected a list of installed software on the system.

T1518
Software Discovery
ToolShimRatReporter

ShimRatReporter gathered a list of installed software on the infected host.

T1518
Software Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer has searched for cryptocurrency wallets on targeted hosts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.