# T1518.001 Security Software Discovery

> As of 2026-10-05, T1518.001 (Security Software Discovery) appears in 114 tracked threats, first reported 2026-02-04 and most recently 2026-09-29, with linked actors including APT38, Sapphire Sleet, SideCopy; it most often appears alongside T1082 (System Information Discovery).

- **Tracked threats:** 114 (13 critical, 89 high, 12 medium)
- **First seen:** 2026-02-04
- **Last seen:** 2026-09-29
- **Threat actors:** 48
- **Detection rules:** 171 (counts only; Blue tier and above)

## Key facts

- **ID:** T1518.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Parent:** T1518
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1518/001/

## Activity timeline

T1518.001 first appeared in tracked threats on 2026-02-04 and was most recently reported on 2026-09-29. The busiest month was 2026-07 with 51 reports, and 114 of the 114 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1518.001 Security Software Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix, as a sub-technique of [T1518 Software Discovery](https://intel.threadlinqs.com/technique/T1518). Threadlinqs maps 114 of 2623 tracked threats (4.3%) to it; by severity that is 13 critical, 89 high, 12 medium.

Threats that use T1518.001 most often also use [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (91 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (77 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (73 threats), [T1036.005 Match Legitimate Resource Name or Location](https://intel.threadlinqs.com/technique/T1036.005) (70 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (70 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

48 tracked threat actors appear in the threats that use T1518.001; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (3), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (3), [SideCopy](https://intel.threadlinqs.com/actor/SideCopy) (3), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (3), [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) (3).

## Data sources

Telemetry that can reveal T1518.001, per MITRE ATT&CK.

- Command — Command Execution
- Firewall — Firewall Enumeration, Firewall Metadata
- Process — OS API Execution, Process Creation

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 3
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 3
- [SideCopy](https://intel.threadlinqs.com/actor/SideCopy) — 3
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 3
- [UAT-11795](https://intel.threadlinqs.com/actor/UAT-11795) — 3
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 2
- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 2
- [ClickLock Dev](https://intel.threadlinqs.com/actor/ClickLock%20Dev) — 2
- [TA578 - G1038](https://intel.threadlinqs.com/actor/TA578%20-%20G1038) — 2
- [Transparent Tribe](https://intel.threadlinqs.com/actor/Transparent%20Tribe) — 2
- [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) — 2
- [AMOS Operators](https://intel.threadlinqs.com/actor/AMOS%20Operators) — 1

## Tracked threats

The 30 most recent of 114 tracked threats that use T1518.001.

- [Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…](https://intel.threadlinqs.com/threat/TL-2026-2766) — high — 2026-09-29
- [Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate…](https://intel.threadlinqs.com/threat/TL-2026-2708) — medium — 2026-09-27
- [Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip…](https://intel.threadlinqs.com/threat/TL-2026-2654) — high — 2026-09-25
- [Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogs](https://intel.threadlinqs.com/threat/TL-2026-2652) — high — 2026-09-25
- [Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass…](https://intel.threadlinqs.com/threat/TL-2026-2631) — high — 2026-09-23
- [Chinese-Speaking 'Kapibala' Actor (Red Heron-Linked) Chains WordPress wp2shell, Zyxel GS1900, and Ubiquiti…](https://intel.threadlinqs.com/threat/TL-2026-2619) — critical — 2026-09-22
- [BigDiskBuster PoC Blocks Microsoft Defender Antivirus Updates via Disk-Space Exhaustion](https://intel.threadlinqs.com/threat/TL-2026-2618) — medium — 2026-09-22
- [BigDiskBuster PoC Blocks Windows Defender Signature/Platform Updates (DoS)](https://intel.threadlinqs.com/threat/TL-2026-2613) — medium — 2026-09-22
- [LLM-Driven Reverse Engineering of Palo Alto Cortex XDR Yields Working EDR Evasion (SpecterOps)](https://intel.threadlinqs.com/threat/TL-2026-2576) — high — 2026-09-19
- [CISA Warns of Active Exploitation of Critical ConnectWise ScreenConnect Flaw (CVE-2026-84869, CVSS 9.9)](https://intel.threadlinqs.com/threat/TL-2026-2533) — critical — 2026-09-16
- [BambooToken Malware Uses MQTT Protocol for Cross-Platform Windows/Linux C2](https://intel.threadlinqs.com/threat/TL-2026-2520) — high — 2026-09-15
- [BambooToken: Cross-Platform Windows/Linux Malware Using MQTT C2, Delivered via Tendyron OnKey DLL…](https://intel.threadlinqs.com/threat/TL-2026-2519) — high — 2026-09-15
- [Pro-Ukraine 'Hacking Cat' Group Deploys Gorilla RAT, Monkey Ransomware, and Nemo Wiper Against Russian…](https://intel.threadlinqs.com/threat/TL-2026-2515) — high — 2026-09-15
- [Sudo iptables NOPASSWD Misconfiguration Enables Local Privilege Escalation via Comment Injection](https://intel.threadlinqs.com/threat/TL-2026-2478) — medium — 2026-09-13
- [Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela Breach](https://intel.threadlinqs.com/threat/TL-2026-2219) — high — 2026-08-29
- [SparrowDoor Backdoor: NCSC Malware Analysis Report on a Persistent Loader with Clipboard Logging, AV…](https://intel.threadlinqs.com/threat/TL-2026-2136) — medium — 2026-08-24
- [Banking Trojans: Manic, Grandoreiro, and ToxicPanda 2.0 in the Spotlight](https://intel.threadlinqs.com/threat/TL-2026-2118) — high — 2026-08-22
- [Agent Tesla v4 Hidden Behind Unicode-Emoji-Obfuscated JScript Evades Detection in BEC Campaign Targeting…](https://intel.threadlinqs.com/threat/TL-2026-2108) — high — 2026-08-22
- [SilkParasite: China-Nexus APT Deploys Seven RAT Families Against Central Asian Governments](https://intel.threadlinqs.com/threat/TL-2026-2200) — high — 2026-08-19
- [Bring Your Own EDR Attack Turns SentinelOne Into PPL-Protected Trojan Horse to Shield Malware](https://intel.threadlinqs.com/threat/TL-2026-2017) — high — 2026-08-14
- [VIP Crypt and ASMCrypt: Commercial Crypter Services Enabling Malware Evasion of Windows Defenses](https://intel.threadlinqs.com/threat/TL-2026-2014) — medium — 2026-08-14
- [HoneyMyte (Mustang Panda) Upgrades CoolClient Backdoor with Kernel-Level Windows Rootkit (msagent.sys)](https://intel.threadlinqs.com/threat/TL-2026-2013) — high — 2026-08-14
- [Dragon Breath (APT-Q-27) Deploys RONINGLOADER to Disable Security Tools and Drop Gh0st RAT](https://intel.threadlinqs.com/threat/TL-2026-1996) — high — 2026-08-12
- [Kynx Stealer: MaaS Infostealer Targeting Crypto Wallets, Gaming Platforms, and AI Coding Tools](https://intel.threadlinqs.com/threat/TL-2026-1943) — critical — 2026-08-08
- [N-able N-central Authentication Bypass Flaws (CVE-2026-18556, CVE-2026-18577) Actively Exploited for Admin…](https://intel.threadlinqs.com/threat/TL-2026-1941) — high — 2026-08-08
- [DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in Browser Cache Images via Steganography](https://intel.threadlinqs.com/threat/TL-2026-1847) — high — 2026-08-03
- [N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeover](https://intel.threadlinqs.com/threat/TL-2026-1830) — critical — 2026-08-03
- [Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto…](https://intel.threadlinqs.com/threat/TL-2026-1820) — medium — 2026-08-02
- [CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver…](https://intel.threadlinqs.com/threat/TL-2026-1808) — high — 2026-07-31
- [OctLurk/SilkLurk Backdoors Target Central Asian Government Networks for Keylogging and Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-1786) — high — 2026-07-31

## Related CVEs

CVEs referenced by the tracked threats that use T1518.001, most frequent first.

- [CVE-2026-18556](https://intel.threadlinqs.com/cve/CVE-2026-18556)
- [CVE-2026-18577](https://intel.threadlinqs.com/cve/CVE-2026-18577)
- [CVE-2026-33825](https://intel.threadlinqs.com/cve/CVE-2026-33825)
- [CVE-2015-2291](https://intel.threadlinqs.com/cve/CVE-2015-2291)
- [CVE-2019-11580](https://intel.threadlinqs.com/cve/CVE-2019-11580)
- [CVE-2020-25213](https://intel.threadlinqs.com/cve/CVE-2020-25213)
- [CVE-2020-36847](https://intel.threadlinqs.com/cve/CVE-2020-36847)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2022-0847](https://intel.threadlinqs.com/cve/CVE-2022-0847)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2024-43451](https://intel.threadlinqs.com/cve/CVE-2024-43451)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-7443](https://intel.threadlinqs.com/cve/CVE-2025-7443)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-15681](https://intel.threadlinqs.com/cve/CVE-2026-15681)
- [CVE-2026-15682](https://intel.threadlinqs.com/cve/CVE-2026-15682)
- [CVE-2026-1969](https://intel.threadlinqs.com/cve/CVE-2026-1969)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-34908](https://intel.threadlinqs.com/cve/CVE-2026-34908)
- [CVE-2026-34909](https://intel.threadlinqs.com/cve/CVE-2026-34909)
- [CVE-2026-34910](https://intel.threadlinqs.com/cve/CVE-2026-34910)
- [CVE-2026-3844](https://intel.threadlinqs.com/cve/CVE-2026-3844)
- [CVE-2026-42897](https://intel.threadlinqs.com/cve/CVE-2026-42897)
- [CVE-2026-48907](https://intel.threadlinqs.com/cve/CVE-2026-48907)
- [CVE-2026-50656](https://intel.threadlinqs.com/cve/CVE-2026-50656)
- [CVE-2026-56271](https://intel.threadlinqs.com/cve/CVE-2026-56271)

## Detection coverage

Threadlinqs maintains 171 detection rules mapped to T1518.001 (SPL 42, KQL 70, Sigma 59). Rule content is available to Blue tier accounts and above; this page shows counts only.

171 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1518 Software Discovery](https://intel.threadlinqs.com/technique/T1518) — 340 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1518.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
