Detected Windows Software Discovery

 Original Source: [Sigma source]
Title: Detected Windows Software Discovery
Status: test
Description:Adversaries may attempt to enumerate software for a variety of reasons, such as figuring out what security measures are present or if the compromised system has a version of software that is vulnerable.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1518/T1518.md
  -https://github.com/harleyQu1nn/AggressorScripts
Author: Nikita Nazarov, oscd.community
Date: 2020-10-16
modified:2022-10-09
Tags:
  • -'attack.discovery'
  • -'attack.t1518'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    Image|endswith: '\reg.exe'
    CommandLine|contains|all:
      -'query'
      -'\software\'
      -'/v'
      -'svcversion'

  condition:selection
Falsepositives:
  -Legitimate administration activities
Level: medium