1200KM / simulation
T1518 Software Discovery — Attack Simulation
Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment. Adversaries may use the information from Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Such software may be deployed widely across the environment for configuration management or security…
Technique description
Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment. Adversaries may use the information from Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Such software may be deployed widely across the environment for configuration management or security…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- WinPwn - powerSQL
Procedure 0bb64470-582a-4155-bde2-d6003a95ed34; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Find and Display Safari Browser Version
Procedure 103d6533-fd2a-4d08-976a-4a598565280f; elevation not declared required; cleanup not declared. Not executed or individually validated.
- WinPwn - DotNet
Procedure 10ba02d0-ab76-4f80-940d-451633f24c5b; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Find and Display Internet Explorer Browser Version
Procedure 68981660-6670-47ee-a5fa-7e74806420a4; elevation not declared required; cleanup not declared. Not executed or individually validated.
- WinPwn - Dotnetsearch
Procedure 7e79a1b6-519e-433c-ad55-3ff293667101; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Applications Installed
Procedure c49978f6-bd6e-4221-ad2c-9e3e30cc1e3b; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.