T1518 Software Discovery
Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment. Adversaries may use the information from [Software Discovery](https://attack.mitre.org/techniques/T1518) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Such…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- HackTool - WinPwn Executionhightest · windows
- HackTool - WinPwn Execution - ScriptBlockhightest · windows
- Sysmon Discovery Via Default Driver Altitude Using Findstr.EXEhightest · windows
- Detected Windows Software Discoverymediumtest · windows
- Detected Windows Software Discovery - PowerShellmediumtest · windows
- Security Software Discovery - MacOsmediumtest · macos
- Security Software Discovery Via Powershell Scriptmediumtest · windows
- Security Tools Keyword Lookup Via Findstr.EXEmediumtest · windows
- System Integrity Protection (SIP) Disabledmediumtest · macos
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.