// MITRE ATT&CK

T1518.001 · Security Software Discovery

🎯 Discovery IaaSLinuxmacOSWindows Sub-technique

Sub-technique of T1518 · Software Discovery.

Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cloud monitoring agents and anti-virus. Adversaries may use the information from [Security Software Di...

How to detect & mitigate it

Detecting Security Software Discovery starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.