Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns T1518 — Software Discovery
T1518

Software Discovery

Discovery
TLP:CLEAR

Description

Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment. Adversaries may use the information from Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Such software may be deployed widely across the environment for configuration management or security reasons, such as Software Deployment Tools, and may allow adversaries broad access to infect devices or move laterally. Adversaries may attempt to enumerate software for a variety of reasons, such as figuring out what security measures are present or if the compromised system has a version of software that is vulnerable to Exploitation for Privilege Escalation.

MITRE ATT&CK Detection Strategies
1

DET0392 Multi-Platform Software Discovery Behavior Chain
AN1104 ESXi

Adversary uses 'esxcli software vib list' to enumerate installed VIBs, drivers, and modules.

esxi:shell esxi:hostd
AN1103 IaaS

Adversary uses cloud-native APIs or CLI (e.g., AWS Systems Manager, Azure Resource Graph) to list installed software on cloud workloads.

AWS:CloudTrail AWS:CloudTrail
AN1102 macOS

Adversary runs 'system_profiler SPApplicationsDataType' or queries plist files to enumerate software via Terminal or scripts.

macos:unifiedlog auditd:SYSCALL
+2 more analytics

Details

Platforms
Esxi
Iaas
Linux
Macos
Windows
Added
May 2, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.