Software Discovery T1518

Tactic: Discovery

Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment. Adversaries may use the information from Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Events covered

6 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 45 rules share fields, values, and exclusions.

Fields filtered most (35 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine21contains 10, regex_match 9, ends_with 1, is_not_null 1(?i)\s+AntiVirusProduct\s+, (?i)\w+(\.exe)?\x22?\s+(avira|cb|cylance|defender|kaspers..., (?i)((\s+query\s+|Get-ItemProperty|gp\s).*\x5cUninstall\x..., auditbeat, -effective
process_name15eq 11, in 6, regex_match 2grep, egrep, pgrep, (?i)\x5cwindows\x5csystem32\x5cfindstr\.exe|\x5cwindows\x..., apt
event.type13eq 13start
EventType12in 8, eq 5exec, exec_event, ProcessRollup2, createassociation, describeinstancepatches
host.os.type12eq 11, in 1
EventID10eq 104104, 4688, 4103, 1
process.args10eq 5, in 4, starts_with 2, wildcard 2--all, --version, -a, /bin/which, /etc/dnf/dnf.conf
Image9ends_with 8, eq 1/csrutil, \find.exe, \findstr.exe, /egrep, /grep
ScriptBlockText5contains 4, eq 1, in 1*avira*, *carbonblack*, *cylance*, .getgporeport(), ::getipglobalproperties()
OriginalFileName4eq 4find.exe, findstr.exe, powershell.exe, pwsh.dll, wmic.exe
event.category4eq 4process, file
Type3eq 3
ParentImage2is_not_null 2
parent_process_name2eq 1, is_not_null 1wmiprvse.exe
user.id2ne 20, S-1-5-18

Top indicator values (518 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
131087
EventTypein
exec
7206
EventTypein
exec_event
7150
EventTypein
start
6168
EventTypein
ProcessRollup2
5118
EventTypein
executed
498
EventTypein
process_started
483
EventIDeq
4104
4269
EventIDeq
4688
4317
EventIDeq
4103
3105
EventIDeq
1
2242
CommandLineregex_match
(?i)\s+AntiVirusProduct\s+
33
CommandLineregex_match
(?i)\w+(\.exe)?\x22?\s+(avira|cb|cylance|defender|kaspersky|kes|mc|sec|sentin...
33
CommandLineregex_match
(?i)((\s+query\s+|Get-ItemProperty|gp\s).*\x5cUninstall\x5c\*)|wmic\s+product...
22
EventTypeeq
exec
3579
event.categoryeq
process
3141
process_namein
pgrep
35
CommandLinecontains
auditbeat
23
CommandLinecontains
falcond
22
CommandLinecontains
filebeat
23
CommandLinecontains
nessusd
22
CommandLinecontains
osqueryd
22
CommandLinecontains
packetbeat
23
CommandLinecontains
td-agent
23
Imageends_with
/csrutil
22
Imageends_with
\find.exe
27
Imageends_with
\findstr.exe
211
OriginalFileNameeq
find.exe
27
OriginalFileNameeq
findstr.exe
212
process_nameeq
grep
26

Exclusions (276 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.entry_leader.executablein
/usr/local/qualys/cloud-agent/bin/qualys-cloud-agent
3
CurrentDirectoryin
/opt/msp-agent
2
CommandLinecontains
HexProductState
1
CommandLinecontains
\commandcenteragent\
1
CommandLinecontains
\commandcenteragent\agent.ps1
1
CommandLineeq
"c:\windows\system32\windowspowershell\v1.0\powershell.exe" -version 5.1 -s...
1
CommandLineeq
Powershell "(Get-CimInstance -ClassName Win32_DeviceGuard -Namespace...
1
CommandLineeq
grep --color=auto eset command-line scanner, version %s -a2
1
CommandLineeq
grep -i mcafee web gateway core version:
1
CommandLineeq
grep eset command-line scanner, version %s -a2
1
CommandLineeq
powershell "get-ciminstance -namespace root/securitycenter2 -classname...
1
CommandLinestarts_with
event0.process.command_line
1
CommandLinestarts_with
event1.process.command_line
1
CommandLinewildcard
"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" -NoLogo...
1
CommandLinewildcard
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 14 rules

Elastic 17 rules

Splunk 10 rules

Kusto 2 rules

Panther 2 rules