T1518Techniquediscoveryagent-callable

T1518Software Discovery

Platforms: Windows · Azure AD · Office 365 · SaaS · IaaS · Linux · macOS · Google Workspace

ATT&CK version: 14.1

What it is

Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment. Adversaries may use the information from [Software Discovery](https://attack.mitre.org/techniques/T1518) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Adversaries may attempt to enumerate software for a variety of reasons, such as figuring out what security measures are present or if the compromised system has a version of software that is vulnerable to [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068).

ATT&CK tactics· 1

Discovery

References

  1. https://attack.mitre.org/techniques/T1518
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.