Detected Windows Software Discovery - PowerShell

 Original Source: [Sigma source]
Title: Detected Windows Software Discovery - PowerShell
Status: test
Description:Adversaries may attempt to enumerate software for a variety of reasons, such as figuring out what security measures are present or if the compromised system has a version of software that is vulnerable.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1518/T1518.md
  -https://github.com/harleyQu1nn/AggressorScripts
Author: Nikita Nazarov, oscd.community
Date: 2020-10-16
modified:2022-12-02
Tags:
  • -'attack.discovery'
  • -'attack.t1518'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection:
    ScriptBlockText|contains|all:
      -'get-itemProperty'
      -'\software\'
      -'select-object'
      -'format-table'

  condition:selection
Falsepositives:
  -Legitimate administration activities
Level: medium