T1518: T1518
Essential information
- MITRE technique ID
T1518- Confidence
- 100/100
- Revoked
- No
- Published
- 16/09/2019 19:52
- Modified
- 27/03/2026 01:12
- Author / Source
- The MITRE Corporation
Aliases
Software Discovery
Platforms
windows macos linux IaaS ESXi
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | discovery |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (54)
-
TAG-140 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
PlushDaemon usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
interlock usesRansomware.Live Confidence 100
No description available
First seen 01/01/1970 · Last seen 16/11/5138 · -
Conti usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
IMPERIAL KITTEN usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Blackwood usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[APT37](https://attack.mitre.org/groups/G0067) is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Artem relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Ashen Lepus relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[BRONZE BUTLER](https://attack.mitre.org/groups/G0060) is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Banshee relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (80)
-
Shai-Hulud 2.0 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
RansomHub usesFamily
-
EDRKillShifter usesFamily
-
Moudoor usesThe MITRE Corporation Confidence 100
[gh0st RAT](https://attack.mitre.org/software/S0032) is a remote access tool (RAT). The source code is public and it has been used by multiple groups.(Citation: FireEye Hacking Team)(Citation: Arbor Musical Chairs Feb…
First seen 01/01/1970 · Last seen 16/11/5138 · -
FatalRAT usesFamily
-
Bundlore uses
-
ValleyRAT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
HotCroissant uses
-
Lumma usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
PeerTime usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Crimson RAT usesFamily
-
Subzero usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Reports (50)
-
20 MITREs 3 Malwares 7 Observables 1 APT
-
13 MITREs 4 Malwares 2 Observables 1 APT
-
12 CVEs 14 MITREs 2 Malwares 77 Observables 1 APT
-
17 MITREs 3 Observables
-
24 MITREs 3 Malwares 147 Observables 1 APT
-
16 MITREs 1 Malware 9 Observables
-
25 MITREs 4 Observables 1 APT
-
3 CVEs 16 MITREs 5 Observables
-
19 MITREs 1 Malware 2 Observables 1 APT
-
20 MITREs 1 Malware 56 Observables
-
15 MITREs 3 Malwares 10 Observables
-
14 MITREs 1 Malware 3 Observables
Vulnerabilities (CVE) (85)
Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted …
- Attack vector
- Network
- Complexity
- LOW
- Published
- 23/01/2024
- Modified
- 04/04/2026
Google Chromium V8 Engine contains an integer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted …
- Published
- 08/06/2022
- Modified
- 21/12/2025
Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an …
- Attack vector
- Network
- Published
- 07/11/2023
- Modified
- 21/12/2025
7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction …
- Attack vector
- Local
- Published
- 06/02/2025
- Modified
- 21/12/2025
Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read …
- Attack vector
- Local
- Complexity
- LOW
- Published
- 05/03/2024
- Modified
- 04/04/2026
targets
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware …
- Attack vector
- Network
- Published
- 20/07/2025
- Modified
- 21/12/2025
Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel …
- Published
- 03/11/2021
- Modified
- 03/03/2026
targets
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability allowing an app to modify a sensitive kernel state.
- Attack vector
- Local
- Published
- 26/07/2023
- Modified
- 21/12/2025
Google Chromium V8 Engine contains an unspecified vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted …
- Published
- 08/06/2022
- Modified
- 21/12/2025
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway …
- Published
- 25/06/2025
- Modified
- 26/06/2025
Campaign (1)
-
Juicy Mix uses
Tool (1)
-
ShimRatReporter usesThe MITRE Corporation Confidence 100
[ShimRatReporter](https://attack.mitre.org/software/S0445) is a tool used by suspected Chinese adversary [Mofang](https://attack.mitre.org/groups/G0103) to automatically conduct initial discovery. The details from this discovery are used to customize follow-on payloads (such as…