Application Window Discovery T1010
Tactic: Discovery
Adversaries may attempt to get a listing of open application windows. Window listings could convey information about how the system is used. For example, information about application windows could be used identify potential data to collect as well as identifying security tooling (Security Software Discovery) to evade.
Events covered
2 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Security-Auditing | Event ID 4656 | A handle to an object was requested. |
| Defender-DeviceProcessEvents | any | Process activity |
Authoring guide
These 2 rules share fields, values, and exclusions.
Fields filtered most (8 distinct)
These fields appear most often in rule filters.
Top indicator values (21 distinct)
These values appear most often in rule predicates.
Exclusions (1 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Domain: Endpoint