MITRE ATT&CK Technique
T1518Software Discovery
- First Reported
- Aug 3, 2026
- Latest Reported
- Aug 3, 2026
Official Description
Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment. Adversaries may use the information from [Software Discovery](https://attack.mitre.org/techniques/T1518) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Such software may be deployed widely across the environment for configuration management or security reasons, such as [Software Deployment Tools](https://attack.mitre.org/techniques/T1072), and may allow adversaries broad access to infect devices or move laterally.
Adversaries may attempt to enumerate software for a variety of reasons, such as figuring out what security measures are present or if the compromised system has a version of software that is vulnerable to [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068).
Such software may be deployed widely across the environment for configuration management or security reasons, such as [Software Deployment Tools](https://attack.mitre.org/techniques/T1072), and may allow adversaries broad access to infect devices or move laterally.
Adversaries may attempt to enumerate software for a variety of reasons, such as figuring out what security measures are present or if the compromised system has a version of software that is vulnerable to [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068).
- Tactics
- Discovery
- Platforms
- ESXi, IaaS, Linux, macOS, Windows
- MITRE Version
- 1.5
- Last Modified
- May 12, 2026
Sub-techniques (2)
Reported Context (1)
- The stealer checked installation paths for wallets, development tools, game launchers, VPNs, messaging applications, Roblox, and Minecraft. Fake Roblox Xeno Cheats Deliver Java Stealer Through Discord and Forums
Malware (1)
MITRE ATT&CK (16)
Vendors (1)
Products (7)
Tools (3)
Industries (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.