FORENSIA

ATT&CK · T1518.001 · sub-technique

Security Software Discovery

Tactics: discovery

About

Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cloud monitoring agents and anti-virus. Adversaries may use the information from Security Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Example commands that can be used to obtain security software information are netsh, <code>reg query</code> with Reg, <code>dir</code> with cmd, and Tasklist, but other indicators of discovery behavior may be more specific to the type of software or security system the adversary is looking for. It is becoming more common to see macOS malware perform checks for LittleSnitch and KnockKnock software. Adversaries may also utilize the Cloud API to discover cloud-native security software installed on compute infrastructure, such as the AWS CloudWatch agent, Azure VM Agent, and Google Cloud Monitor agent. These agents may collect metrics and logs from the VM, which may be centrally aggregated in a cloud-based monitoring platform.

Platforms: IaaS, Linux, macOS, WindowsParent: T1518 Software DiscoveryMITRE ATT&CK ↗

Used by actors

27 known groups

Software

111 malware/tools implement this

CHOPSTICKCozyCarTasklistDustySkyKasidetEpicT9000netshPrikormkaCrimsonRemsecStreamExFlameRTMFelismusWingbirdFinFisherPOWRUNERPUNCHBUGGYJPINPOWERSTATSComnieGold DragonMosquitoVERMINInvisiMoleFELIXROOTRogueRobinjRATMore_eggsZeus PandaBadPatchMicropsiaEmpireNotPetyaAstarothStoneDrillFlawedAmmyyYAHOYAHEvilBunnyMetamorfoNetwalkerTajMahalSkidmapABKbuild_downerdown_newAvengerValakIcedIDCarberpStrongPityCookieMinerPipeMonLiteDukeGrandoreiroBazarMoleNetSUNBURSTEVILNUMWaterbearThiefQuestStuxnetClopSpicyOmeletteQakBotMarkiRATxCaonBLUELIGHTXCSSETGelsemiumDarkWatchmanFerociousLitePowerLizarMeteorWhisperGateSILENTTRINITYZxxZAmadeyAction RATAuTo StealerBumblebeeFunnyDreamMafaldaBrute Ratel C4Woody RATDarkTortillaPacuDarkGateMispaduRaspberry RobinLunarWebCHIMNEYSWEEPDUSTTRAPLatrodectusExbyteBlackByte RansomwareTAMECATLumma StealerPUBLOADSplatCloakTONESHELLRedLine StealerMedusa RansomwarePureCrypterHiddenFaceSPAWNCHIMERAROAMINGHOUSEMuddyViperRustyWater

Corpus indicators tagged with this technique

847 indicators in the corpus carry T1518.001.

IndicatorTypeFamilySevSrc
12b41c07299d2535f7cdc194d97496acd944a9eb5d94b8d24b19291ed9d0830csha256801
1d52ded1f3838a1eee849ae20b2fee6c84b183cc98abe7244365b9f34b925eeasha256801
7d8b6a64f7b65b281e7b5568929c6f96c62bbae9628162aabe7d8140a86d3de8sha256801
ad0f892b7b99b68491ade4949ef6b575e64d9df5f84a53019b5c1e4eeb4c46a9sha256801
19e0070e5009bd5b376b9be997361d0773dcb004200ee8fafe6c14b96cbd93e4sha256801
1c01ab1b59245f24ebdc5d9c414fcf4e2ce31f71f181522efc5a3d27476c8e21sha256801
512adab2c69feaf026adfb12cbd7d2eb4fee746120491e44f476eebddcbb19f2sha256801
0d681bd160db1b1df5db321a6d2dd9ae81b2609bhash801
1e41c7bfaa6aa3b93b6cc024274a10e33f3e12fe7c98c1db387ef8927f9d1984hashransomware802
d55ce447e249ef9045750865fa196c8ca8434c8c484f861b7bdecbceeab7c16esha256801
a8acc24bb3e6a1a3b66a31ceaefda07d4a0e17415468683458b499f2ba240450sha256801
66bf111030a2e22db575c0b7b7b677208745eef8b44265bb4259f41f126f1bf8sha256801
ccca11a6d5835999c40a0a5264084b3740633600c157754fad2ef59559e31736sha256801
1d699a46339626db299548e32ed3a77eec267840c3de39b49caf38b88aeb150dsha256801
e5c4e634b2f443f783cae1b5e8247a1069df0c9fhashransomware802
6c6cbed6aad96564ed87094785be07a1hashphishing802
55d6238b01a177e25eb7d53c943f3abea64ec073hashphishing802
61e9d76f07334843df561fe4bac449fb6fdaed5e5eb91480bded225f3d265c5fhashphishing802
08060143ea9b55b480746b415af22e3ahashransomware801
b148626849c11dd5b3230632a38a6302hashransomware802
15d1002d9935fbfc9dfc65eb70fe4ecc0943c784hashransomware801
46b2155c1e71b840d4b7a2e94410b89a61e2446523e6f497206d402eb02e0e93hashransomware801
4c357a29b202b77e7db190d359ead2dfd3f8869c6808b96bfa8bee82525bb2a2hashransomware801
6870e3bbf2447c96d21682caf943cf31c2e8c21c8cfb91a5092eab1c9e5f19aehashransomware801
75635009a00cb26d2f532ad974ede59785a18e4b30132a1f585108589394ba5ahashransomware801
a5a5b6257304eefe5212edfd8c0ad27f77357c5046a7acb8eb7ba72ed4bad9e0hashransomware801
ac66c2d47cdefb221822b9074c9810434e8da702a0694139aa9177557e6b292bhashransomware801
ced6b0f44410f6133ad63b61e04613a8b56cc3338d7b34497540e9541163e7echashransomware801
5a23ca644cb1f310be1abd5f6c6a3b3e15681ced99b0947a7f3465a79aae5089sha256801
2267d05dbd5e30c6dfcdde25731280dd755e689faa684bd21cfbef5281fd3e86sha256801

Showing the top 30 by severity of 847.