T1518.001 Security Software Discovery in real malware
ATT&CK technique T1518.001 Security Software Discovery appears in 252 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.2% of the analyzed corpus. Seven-day prevalence is flat (0 recent vs 0 prior). Most associated families: HUILoader, Delf, RedLine, Vindor, AgentTesla.
Tactics: discovery
Prevalence in the corpus
- Samples exhibiting T1518.001: 252
- Share of analyzed corpus: 0.2%
- Last 7 days: 0 · prior 7 days: 0 (flat)
Malware families using T1518.001
- HUILoader - 47 samples
- Delf - 34 samples
- RedLine - 21 samples
- Vindor - 20 samples
- AgentTesla - 7 samples
Example samples
- 5cef37f1f5ed3bd0708b5f4385844ff64d08fb05f8d03cc8627c365e0b66ddb6 - malicious
- 9a630b8f2ddeed59e50aef8c3ce6e68821667b78948f8fb82e90624fef758bed - malicious
- 1ca3945af366e5ccfd8d82bfe5106ad6a637076fd5ce6352fb8eb6c280f12958 - malicious
- 86e038d9fb1bb8e60915593a3f0ebb053408825037bf13767856d1c5a21f9d42 - malicious
- 46cfeb049ec1b54df89c49003c2b772750bbcd89e6ebb235bf1861771a6613a3 - malicious
- 17c8e5e3d023aa0549f3fcbae7fa1e56cd3a57806dac37b8eaac4a725b29fa8d - malicious
- 0aa16df38d44af2e5d29d58fe212c6460a2b4ea000cfe23a3c0333391ccd397d - malicious
- 8a5c793dfcdb407b439d00ea9688b620ea6976c4871112293d50a58a3572bf73 - malicious
- 14b2c50bbcba74e4ce2c47df644ec0e1d919a2f1fdcff389030c5b1c89f3131b - malicious
- 48724945d19df93be99ee36fa558472f08bd346fb1afd5ce8ace0ab8407f9c04 - malicious
- fbdd212f0d5065411746bbb2d652f3c6e18bb589fb0ca683da81e84e804db1c6 - malicious
- ba93804dc54b3a8d350bf4c2f4c378e4c146c7a4cd13d40a2ba6b0660001df35 - malicious
- 97f36ab0a4ff9453413a38a118c000c659008125fe8fc31c2b79027e580f4a8d - malicious
- 925ad00081c7bceb109c86baed9bf5904dc6e018515416b98169d1c9ca1026aa - malicious
- c261d38419991cfdbd46ef65acfa3668340b9cfa31e82d2137c3d355a0d5a50b - malicious
- 3f4db515af43a5de841ce6d85c74ea5696ec114b4f6fb7761bcea76c91fe990e - malicious
- 2964954d9c0787f8a717b550366eab002e7e2661c38c6d08917f9d012baf0643 - malicious
- f04b2b548cb9969e05ae032cf880efacc67f6a0ac797698b54352928ef75119d - malicious
- b5e39acf564601595e6b6c24d666454264259f2ee3972bf3e96f75856e0310b4 - malicious
- e06abdc0104845361a19f0ab2019f70bfe792a11d94c70810c62591ac29f3a07 - malicious
- 42a9882d713586d4e53037b5a2857f7c0cbdb6b81a83f6fc80f3611f1bfb6093 - malicious
- f51bb7b90c235c491e37f823dc9eea9a898ab05187b7ca77c1ceb2d81f08b406 - malicious
- df6683a642d955e7578d1e3d86909ebfc36b51da34972fcb5eec53affeaaf3b3 - malicious
- 2a05aab8f2b0aa4b8dd85a0d5999c36539e43c2e62fae5d0ed7cfa1fce34e3dc - malicious
- 99147cb03784a3754185947e00f5ee276323bc926392595ebb5d68a8d6b617c5 - malicious
Canonical technique definition: MITRE ATT&CK T1518.001 (ATT&CK v19.1, CC BY 4.0).
Frequently asked about T1518.001
- How common is ATT&CK T1518.001 (Security Software Discovery) in real malware?
- ATT&CK technique T1518.001 Security Software Discovery appears in 252 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.2% of the analyzed corpus. Seven-day prevalence is flat (0 recent vs 0 prior). Most associated families: HUILoader, Delf, RedLine, Vindor, AgentTesla.
- Which malware families use T1518.001?
- In this corpus T1518.001 is most associated with HUILoader (47), Delf (34), RedLine (21), Vindor (20), AgentTesla (7). Counts are analyzed samples per family in which the technique was observed.
- What share of analyzed samples use T1518.001?
- 0.2% of the publicly analyzed corpus (252 of 114610 samples) exhibits T1518.001. Technique attribution comes from behavior captured during real sandbox detonation and from static analysis, not from a vendor label.
All ATT&CK techniques in the corpus · Latest analyzed threats