216.73.216.226

T1518.002: Backup Software Discovery

View on MITRE ATT&CK The MITRE Corporation · Published 22/05/2025 20:57 · Modified 27/03/2026 01:09

Essential information

MITRE technique ID
T1518.002
Confidence
100/100
Revoked
No
Published
22/05/2025 20:57
Modified
27/03/2026 01:09
Author / Source
The MITRE Corporation

Platforms

windows macos linux

Description

Adversaries may attempt to get a listing of backup software or configurations that are installed on a system. Adversaries may use this information to shape follow-on behaviors, such as [Data Destruction](https://attack.mitre.org/techniques/T1485), [Inhibit System Recovery](https://attack.mitre.org/techniques/T1490), or [Data Encrypted for Impact](https://attack.mitre.org/techniques/T1486). Commands that can be used to obtain security software information are [netsh](https://attack.mitre.org/software/S0108), `reg query` with [Reg](https://attack.mitre.org/software/S0075), `dir` with [cmd](https://attack.mitre.org/software/S0106), and [Tasklist](https://attack.mitre.org/software/S0057), but other indicators of discovery behavior may be more specific to the type of software or security system the adversary is looking for, such as Veeam, Acronis, Dropbox, or Paragon.(Citation: Symantec Play Ransomware 2023)

Kill chain phases

Kill chainPhase
mitre-attack discovery

Marking (TLP)

Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references