1200KM / simulation
T1518.001 Security Software Discovery — Attack Simulation
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cloud monitoring agents and anti-virus. Adversaries may use the information from Security Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts…
Technique description
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cloud monitoring agents and anti-virus. Adversaries may use the information from Security Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Security Software Discovery - AV Discovery via Get-CimInstance and Get-WmiObject cmdlets
Procedure 015cd268-996e-4c32-8347-94c80c6286ee; elevation required; cleanup not declared. Not executed or individually validated.
- Security Software Discovery - AV Discovery via WMI
Procedure 1553252f-14ea-4d3b-8a08-d7a4211aa945; elevation required; cleanup not declared. Not executed or individually validated.
- Security Software Discovery - ps (Linux)
Procedure 23b91cd2-c99c-4002-9e41-317c63e024a2; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Security Software Discovery - powershell
Procedure 7f566051-f033-49fb-89de-b6bacab730f0; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Enumerate Windows Defender exclusion paths via MpCmdRun.exe
Procedure 8eb337ee-fa17-4da7-890a-0204ea470718; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Security Software Discovery - Windows Firewall Enumeration
Procedure 9dca5a1d-f78c-4a8d-accb-d6de67cfed6b; elevation required; cleanup not declared. Not executed or individually validated.
- Security Software Discovery - ps (macOS)
Procedure ba62ce11-e820-485f-9c17-6f3c857cd840; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Security Software Discovery - Windows Defender Enumeration
Procedure d3415a0e-66ef-429b-acf4-a768876954f6; elevation required; cleanup not declared. Not executed or individually validated.
- Get Windows Defender exclusion settings using WMIC
Procedure e31564c8-4c60-40cd-a8f4-9261307e8336; elevation required; cleanup not declared. Not executed or individually validated.
- Security Software Discovery
Procedure f92a380f-ced9-491f-b338-95a991418ce2; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Security Software Discovery - pgrep (FreeBSD)
Procedure fa96c21c-5fd6-4428-aa28-51a2fbecdbdc; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Security Software Discovery - Sysmon Service
Procedure fe613cf3-8009-4446-9a0f-bc78a15b66c9; elevation required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Turla · G0010
- Darkhotel · G0012
- Naikon · G0019
- Patchwork · G0040
- Gamaredon Group · G0047
- FIN8 · G0061
- MuddyWater · G0069
- Cobalt Group · G0080
- Tropic Trooper · G0081
- APT38 · G0082
- The White Company · G0089
- Kimsuky · G0094
- Wizard Spider · G0102
- Rocke · G0106
- Windshift · G0112
- Sidewinder · G0121
- TeamTNT · G0139
- Aquatic Panda · G0143
- SideCopy · G1008
- TA2541 · G1018
- ToddyCat · G1022
- Malteiro · G1026
- Play · G1040
- BlackByte · G1043
- APT42 · G1044
- Medusa Group · G1051
- Storm-0501 · G1053
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.