Software Discovery T1518

Tactic: Discovery

Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment. Adversaries may use the information from Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Events covered

6 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 44 rules share fields, values, and exclusions.

Fields filtered most (35 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine20contains 9, regex_match 9, ends_with 1, is_not_null 1(?i)\s+AntiVirusProduct\s+, (?i)\w+(\.exe)?\x22?\s+(avira|cb|cylance|defender|kaspers..., (?i)((\s+query\s+|Get-ItemProperty|gp\s).*\x5cUninstall\x..., auditbeat, 385201
process_name15eq 11, in 6, regex_match 2grep, egrep, pgrep, (?i)\x5cwindows\x5csystem32\x5cfindstr\.exe|\x5cwindows\x..., apt
event.type13eq 13start
EventType12in 8, eq 5exec, exec_event, ProcessRollup2, createassociation, describeinstancepatches
host.os.type12eq 11, in 1
EventID10eq 104104, 4688, 4103, 1
process.args10eq 5, in 4, starts_with 2, wildcard 2--all, --version, -a, /bin/which, /etc/dnf/dnf.conf
Image8ends_with 7, eq 1/csrutil, \find.exe, \findstr.exe, /egrep, /grep
ScriptBlockText5contains 4, eq 1, in 1*avira*, *carbonblack*, *cylance*, .getgporeport(), ::getipglobalproperties()
event.category4eq 4process, file
OriginalFileName3eq 3find.exe, findstr.exe, wmic.exe
Type3eq 3
ParentImage2is_not_null 2
parent_process_name2eq 1, is_not_null 1wmiprvse.exe
user.id2ne 20, S-1-5-18

Top indicator values (510 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
131078
EventTypein
exec
7201
EventTypein
exec_event
7149
EventTypein
start
6163
EventTypein
ProcessRollup2
5117
EventTypein
executed
498
EventTypein
process_started
483
EventIDeq
4104
4269
EventIDeq
4688
4317
EventIDeq
4103
3105
EventIDeq
1
2241
CommandLineregex_match
(?i)\s+AntiVirusProduct\s+
33
CommandLineregex_match
(?i)\w+(\.exe)?\x22?\s+(avira|cb|cylance|defender|kaspersky|kes|mc|sec|sentin...
33
CommandLineregex_match
(?i)((\s+query\s+|Get-ItemProperty|gp\s).*\x5cUninstall\x5c\*)|wmic\s+product...
22
EventTypeeq
exec
3576
event.categoryeq
process
3142
process_namein
pgrep
35
CommandLinecontains
auditbeat
23
CommandLinecontains
falcond
22
CommandLinecontains
filebeat
23
CommandLinecontains
nessusd
22
CommandLinecontains
osqueryd
22
CommandLinecontains
packetbeat
23
CommandLinecontains
td-agent
23
Imageends_with
/csrutil
22
Imageends_with
\find.exe
27
Imageends_with
\findstr.exe
211
OriginalFileNameeq
find.exe
27
OriginalFileNameeq
findstr.exe
212
process_nameeq
grep
26

Exclusions (273 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.entry_leader.executablein
/usr/local/qualys/cloud-agent/bin/qualys-cloud-agent
3
CurrentDirectoryin
/opt/msp-agent
2
CommandLinecontains
HexProductState
1
CommandLinecontains
\commandcenteragent\
1
CommandLinecontains
\commandcenteragent\agent.ps1
1
CommandLineeq
"c:\windows\system32\windowspowershell\v1.0\powershell.exe" -version 5.1 -s...
1
CommandLineeq
Powershell "(Get-CimInstance -ClassName Win32_DeviceGuard -Namespace...
1
CommandLineeq
grep --color=auto eset command-line scanner, version %s -a2
1
CommandLineeq
grep -i mcafee web gateway core version:
1
CommandLineeq
grep eset command-line scanner, version %s -a2
1
CommandLineeq
powershell "get-ciminstance -namespace root/securitycenter2 -classname...
1
CommandLinestarts_with
event0.process.command_line
1
CommandLinestarts_with
event1.process.command_line
1
CommandLinewildcard
"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" -NoLogo...
1
CommandLinewildcard
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 13 rules

Elastic 17 rules

Splunk 10 rules

Kusto 2 rules

Panther 2 rules