Software Discovery T1418

Mobile Tactic: Discovery

Authoring guide

These 3 rules share fields, values, and exclusions.

Fields filtered most (9 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType2eq 2DEVICE, THREAT
ChangeType1eq 1UPDATE
DeviceComplianceStatus1in 1Non-Compliant, Partial
DeviceSecurityStatus1in 1THREATS_HIGH, THREATS_MEDIUM
ThreatAction1eq 1DETECTED
ThreatSeverity1in 1CRITICAL, HIGH
ThreatStatus1in 1ACTIVE, OPEN
entries1is_not_null 1
result_type1eq 1maliciousness

Top indicator values (13 distinct)

These values appear most often in rule predicates.

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Application

Domain: Application

Kusto 3 rules