ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1518.001×

111 examples

TechniqueUsed byProcedure example
T1518.001
Security Software Discovery
MalwareBumblebee

Bumblebee can identify specific analytical tools based on running processes.

T1518.001
Security Software Discovery
MalwareAmadey

Amadey has checked for a variety of antivirus products.

T1518.001
Security Software Discovery
MalwareStuxnet

Stuxnet enumerates the currently running processes related to a variety of security products.

T1518.001
Security Software Discovery
MalwarePOWRUNER

POWRUNER may collect information on the victim's anti-virus software.

T1518.001
Security Software Discovery
MalwareTAMECAT

TAMECAT has used Windows Management Instrumentation (WMI) to check for anti-virus products.

T1518.001
Security Software Discovery
MalwareFelismus

Felismus checks for processes associated with anti-virus vendors.

T1518.001
Security Software Discovery
MalwareZeus Panda

Zeus Panda checks to see if anti-virus, anti-spyware, or firewall products are installed in the victim’s environment.

T1518.001
Security Software Discovery
MalwareStrongPity

StrongPity can identify if ESET or BitDefender antivirus are installed before dropping its payload.

T1518.001
Security Software Discovery
MalwarexCaon

xCaon has checked for the existence of Kaspersky antivirus software on the system.

T1518.001
Security Software Discovery
MalwareROAMINGHOUSE

ROAMINGHOUSE can identify McAfee applications on compromised hosts and change its execution method if one is detected.

T1518.001
Security Software Discovery
MalwareTONESHELL

TONESHELL has checked for the presence of ESET antivirus applications `ekrn.exe` and `egui.exe`.

T1518.001
Security Software Discovery
MalwareKasidet

Kasidet has the ability to identify any anti-virus installed on the infected system.

T1518.001
Security Software Discovery
MalwareMedusa Ransomware

Medusa Ransomware has the capability to detect security solutions for termination or deletion within the victim device using hard-coded lists of strings containing security product executables.

T1518.001
Security Software Discovery
MalwareCrimson

Crimson contains a command to collect information about anti-virus software on the victim.

T1518.001
Security Software Discovery
MalwareDUSTTRAP

DUSTTRAP can identify security software.

T1518.001
Security Software Discovery
MalwareAction RAT

Action RAT can identify AV products on an infected host using the following command: `cmd.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List`.

T1518.001
Security Software Discovery
MalwareAvenger

Avenger has the ability to identify installed anti-virus products on a compromised host.

T1518.001
Security Software Discovery
MalwarePrikormka

A module in Prikormka collects information from the victim about installed anti-virus software.

T1518.001
Security Software Discovery
MalwarePUBLOAD

PUBLOAD has identified AV products on an infected host using the following command: `WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /Format:List`.

T1518.001
Security Software Discovery
MalwareWoody RAT

Woody RAT can detect Avast Software, Doctor Web, Kaspersky, AVG, ESET, and Sophos antivirus programs.

T1518.001
Security Software Discovery
MalwareMafalda

Mafalda can search for a variety of security software programs, EDR systems, and malware analysis tools.

T1518.001
Security Software Discovery
MalwareAuTo Stealer

AuTo Stealer has the ability to collect information about installed AV products from an infected host.

T1518.001
Security Software Discovery
MalwareFlawedAmmyy

FlawedAmmyy will attempt to detect anti-virus products during the initial infection.

T1518.001
Security Software Discovery
MalwareInvisiMole

InvisiMole can check for the presence of network sniffers, AV, and BitDefender firewall.

T1518.001
Security Software Discovery
MalwareWhisperGate

WhisperGate can recognize the presence of monitoring tools on a target system.

T1518.001
Security Software Discovery
MalwareSkidmap

Skidmap has the ability to check if /usr/sbin/setenforce exists. This file controls what mode SELinux is in.

T1518.001
Security Software Discovery
MalwareRaspberry Robin

Raspberry Robin attempts to identify security software running on the victim machine, such as BitDefender, Avast, and Kaspersky.

T1518.001
Security Software Discovery
MalwareMispadu

Mispadu can list installed security products in the victim’s environment.

T1518.001
Security Software Discovery
MalwareRustyWater

RustyWater has attempted to detect more than 25 antivirus and EDR tools.

T1518.001
Security Software Discovery
MalwareIcedID

IcedID can identify AV products on an infected host using the following command:
` WMIC.exe WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get * /Format:List`.

T1518.001
Security Software Discovery
MalwareVERMIN

VERMIN uses WMI to check for anti-virus software installed on the system.

T1518.001
Security Software Discovery
MalwareMarkiRAT

MarkiRAT can check for running processes on the victim’s machine to look for Kaspersky and Bitdefender antivirus products.

T1518.001
Security Software Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP is capable of checking whether a compromised device is running DeepFreeze by Faronics.

T1518.001
Security Software Discovery
MalwareNotPetya

NotPetya determines if specific antivirus programs are running on an infected host machine.

T1518.001
Security Software Discovery
MalwareSpicyOmelette

SpicyOmelette can check for the presence of 29 different antivirus tools.

T1518.001
Security Software Discovery
MalwarePUNCHBUGGY

PUNCHBUGGY can gather AVs registered in the system.

T1518.001
Security Software Discovery
MalwareDarkTortilla

DarkTortilla can check for the Kaspersky Anti-Virus suite.

T1518.001
Security Software Discovery
MalwareExbyte

Exbyte checks for the presence of various security software products during execution.

T1518.001
Security Software Discovery
MalwareDarkWatchman

DarkWatchman can search for anti-virus products on the system.

T1518.001
Security Software Discovery
MalwareLumma Stealer

Lumma Stealer has detected antivirus processes using commands such as “tasklist” and “findstr.”

T1518.001
Security Software Discovery
MalwareDustySky

DustySky checks for the existence of anti-virus.

T1518.001
Security Software Discovery
MalwareRemsec

Remsec has a plugin detect security products via active drivers.

T1518.001
Security Software Discovery
MalwareEpic

Epic searches for anti-malware services running on the victim’s machine and terminates itself if it finds them.

T1518.001
Security Software Discovery
MalwarePureCrypter

PureCrypter can identify installed antivirus solutions.

T1518.001
Security Software Discovery
MalwareDarkGate

DarkGate looks for various security products by process name using hard-coded values in the malware. DarkGate will not execute its keylogging thread if a process name associated with Trend Micro anti-virus is identified, or if runtime checks identify the presence of Kaspersky anti-virus. DarkGate will initiate a new thread if certain security products are identified on the victim, and recreate any malicious files associated with it if it determines they were removed by security software in a new system location.

T1518.001
Security Software Discovery
MalwareThiefQuest

ThiefQuest uses the kill_unwanted function to get a list of running processes, compares each process with an encrypted list of “unwanted” security related programs, and kills the processes for security related programs.

T1518.001
Security Software Discovery
MalwareFerocious

Ferocious has checked for AV software as part of its persistence process.

T1518.001
Security Software Discovery
MalwareNetwalker

Netwalker can detect and terminate active security software-related processes on infected systems.

T1518.001
Security Software Discovery
MalwareLatrodectus

Latrodectus has the ability to identify installed antivirus products.

T1518.001
Security Software Discovery
MalwareMuddyViper

MuddyViper has the ability to check for a specified list of security tools in the compromised environment.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.