Application Window Discovery T1010

Tactic: Discovery

Adversaries may attempt to get a listing of open application windows. Window listings could convey information about how the system is used. For example, information about application windows could be used identify potential data to collect as well as identifying security tooling (Security Software Discovery) to evade.

Events covered

2 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 2 rules share fields, values, and exclusions.

Fields filtered most (8 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
AccessMask1eq 10xf003f
DiscoveryCommands1ge 13
LogonId1eq 10x3e4
ObjectName1eq 1servicesactive
ObjectType1eq 1sc_manager object
ParentCommandLine1contains 1, ends_with 1-a, -nao, -t
file_name1eq 1arp.exe, net.exe, netstat.exe
parent_process_name1in 1explorer.exe, mobsync.exe

Top indicator values (21 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
AccessMaskeq
0xf003f
1
DiscoveryCommandsge
3
1
LogonIdeq
0x3e4
1
ObjectNameeq
servicesactive
12
ObjectTypeeq
sc_manager object
12
ParentCommandLinecontains
-a
1
ParentCommandLinecontains
-nao
1
ParentCommandLinecontains
-t
1
ParentCommandLinecontains
/all
1
ParentCommandLinecontains
querytype=all
1
ParentCommandLinecontains
timeout=10
1
ParentCommandLinecontains
view
1
ParentCommandLineends_with
127.0.0.1
1
file_nameeq
arp.exe
1
file_nameeq
net.exe
1
file_nameeq
netstat.exe
1
file_nameeq
nslookup.exe
1
file_nameeq
ping.exe
12
file_nameeq
whoami.exe
1
parent_process_namein
explorer.exe
13
parent_process_namein
mobsync.exe
1

Exclusions (1 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
LogonIdeq
0x3e4
1

Rules under this technique

These vendors publish rules tagged with this technique.

Domain: Endpoint

Platform (all)

Sigma 1 rule

Kusto 1 rule