ATT&CK Technique · Discovery
T1518.001 Security Software DiscoveryMapped by 5 reports, 2 detection rules and 3 tracked actors on The Hunters Ledger. Technique page on attack.mitre.org.
← All techniques and the coverage heatmap
Reports
Each report maps this technique in its own ATT&CK table, at the confidence the report states. The link opens that table.
Detection rules
Rules whose ATT&CK coverage line names this technique, by detection page. The link opens the page's coverage table.
Detection rules
BellaMain Turkish PhaaS Panel (79.137.192.3)BellaMain USOM Poll, Telegram Bot Outbound, and Correlations (SIGMA, Hunting); BellaMain USOM Blocklist Poll from Web Server (Network Layer) (SURICATA, Hunting)
Tracked actors
Designations whose reports map this technique.
- UTA-2026-006: Stock AdaptixC2 operator with an operator-written PowerShell and .NET injection chain
- UTA-2026-008: Developer and operator of the BellaMain Turkish phishing-as-a-service panel
- UTA-2026-024: Windows post-exploitation intrusion set with Sliver and a blockchain-resolved implant
ATT&CK v19.2. MITRE ATT&CK® is a registered trademark of The MITRE Corporation; technique names are MITRE's and link to MITRE's own pages. The mapping on each linked page is this publication's reading of its own evidence.