Skip to content
← LibraryTechnique entry
T1518Discovery

Software Discovery

Identify installed software / running services / kernel versions to pick the right post-exploitation primitive.

§ Where this technique fits

T1518 is catalogued under the Discovery tactic of the offensive-security kill-chain. It appears in 3 approved dossiers in the registry, typically at step 3.3 on average.

Authoritative reference: attack.mitre.org/techniques/T1518/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01seen 2×