Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1518/T1518.001
MITRE ATT&CK Sub-Technique

T1518.001: Security Software Discovery

ShareXLinkedInRedditHN

Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cloud monitoring agents and anti-virus. Adversaries may use the information from [Security Software Discovery](https://attack.mitre.org/techniques/T1518/001) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Example commands that can be used to obtain security software information are [netsh](https://attack.mitre.org/software/S0108), <code>reg query</code> with [Reg](https://attack.mitre.org/software/S0075), <code>dir</code> with [cmd](https://attack.mitre.org/software/S0106), and [Tasklist](https://attack.mitre.org/software/S0057), but other indicators of discovery behavior may be more specific to the type of software or security system the adversary is looking for. It is becoming more common to see macOS malware perform checks for LittleSnitch and KnockKnock software. Adversaries may also utilize the [Cloud API](https://attack.mitre.org/techniques/T1059/009) to discover cloud-native security software installed on compute infrastructure, such as the AWS CloudWatch agent, Azure VM Agent, and Google Cloud Monitor agent. These agents may collect metrics and logs from the VM, which may be centrally aggregated in a cloud-based monitoring platform.

Tactics
Discovery
Platforms
IaaS, Linux, macOS, Windows

▪Parent technique

T1518: Software Discovery

▪Used by groups (27)

G0010TurlaG0012DarkhotelG0019NaikonG0040PatchworkG0047Gamaredon GroupG0061FIN8G0069MuddyWaterG0080Cobalt GroupG0081Tropic TrooperG0082APT38G0089The White CompanyG0094KimsukyG0102Wizard SpiderG0106RockeG0112WindshiftG0121SidewinderG0139TeamTNTG0143Aquatic PandaG1008SideCopyG1018TA2541G1022ToddyCatG1026MalteiroG1040PlayG1043BlackByteG1044APT42G1051Medusa GroupG1053Storm-0501

▪Software using this technique (111)

S0023CHOPSTICKmalwareS0046CozyCarmalwareS0057TasklisttoolS0062DustySkymalwareS0088KasidetmalwareS0091EpicmalwareS0098T9000malwareS0108netshtoolS0113PrikormkamalwareS0115CrimsonmalwareS0125RemsecmalwareS0142StreamExmalwareS0143FlamemalwareS0148RTMmalwareS0171FelismusmalwareS0176WingbirdmalwareS0182FinFishermalwareS0184POWRUNERmalwareS0196PUNCHBUGGYmalwareS0201JPINmalwareS0223POWERSTATSmalwareS0244ComniemalwareS0249Gold DragonmalwareS0256MosquitomalwareS0257VERMINmalwareS0260InvisiMolemalwareS0267FELIXROOTmalwareS0270RogueRobinmalwareS0283jRATmalwareS0284More_eggsmalwareS0330Zeus PandamalwareS0337BadPatchmalwareS0339MicropsiamalwareS0363EmpiretoolS0368NotPetyamalwareS0373AstarothmalwareS0380StoneDrillmalwareS0381FlawedAmmyymalwareS0388YAHOYAHmalwareS0396EvilBunnymalwareS0455MetamorfomalwareS0457NetwalkermalwareS0467TajMahalmalwareS0468SkidmapmalwareS0469ABKmalwareS0471build_downermalwareS0472down_newmalwareS0473AvengermalwareS0476ValakmalwareS0483IcedIDmalwareS0484CarberpmalwareS0491StrongPitymalwareS0492CookieMinermalwareS0501PipeMonmalwareS0513LiteDukemalwareS0531GrandoreiromalwareS0534BazarmalwareS0553MoleNetmalwareS0559SUNBURSTmalwareS0568EVILNUMmalwareS0579WaterbearmalwareS0595ThiefQuestmalwareS0603StuxnetmalwareS0611ClopmalwareS0646SpicyOmelettemalwareS0650QakBotmalwareS0652MarkiRATmalwareS0653xCaonmalwareS0657BLUELIGHTmalwareS0658XCSSETmalwareS0666GelsemiummalwareS0673DarkWatchmanmalwareS0679FerociousmalwareS0680LitePowermalwareS0681LizarmalwareS0688MeteormalwareS0689WhisperGatemalwareS0692SILENTTRINITYtoolS1013ZxxZmalwareS1025AmadeymalwareS1028Action RATmalwareS1029AuTo StealermalwareS1039BumblebeemalwareS1044FunnyDreammalwareS1060MafaldamalwareS1063Brute Ratel C4toolS1065Woody RATmalwareS1066DarkTortillamalwareS1091PacutoolS1111DarkGatemalwareS1122MispadumalwareS1130Raspberry RobinmalwareS1141LunarWebmalwareS1149CHIMNEYSWEEPmalwareS1159DUSTTRAPmalwareS1160LatrodectusmalwareS1179ExbytemalwareS1180BlackByte RansomwaremalwareS1193TAMECATmalwareS1213Lumma StealermalwareS1228PUBLOADmalwareS1234SplatCloakmalwareS1239TONESHELLmalwareS1240RedLine StealermalwareS1244Medusa RansomwaremalwareS9019PureCryptermalwareS9023HiddenFacemalwareS9024SPAWNCHIMERAmalwareS9026ROAMINGHOUSEmalwareS9032MuddyVipermalwareS9037RustyWatermalware

▪Reference

T1518.001on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.