1200KM / detection
T1518 Software Discovery — Detection Rules
Detection workspace for T1518 Software Discovery: 4 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- HackTool - WinPwn Execution - ScriptBlock · test · high · {"category":"ps_script","product":"windows","definition":"Requirements: Script Block Logging must be enabled"}
- Detected Windows Software Discovery - PowerShell · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- HackTool - WinPwn Execution · test · high · {"category":"process_creation","product":"windows"}
- Detected Windows Software Discovery · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1518 Software Discovery
MATCH(command_or_api IN software_inventory_operations) AND caller NOT_IN approved_inventory_tools -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0392 Multi-Platform Software Discovery Behavior Chain
AN1100 Analytic 1100
Adversary spawns a process or script to enumerate installed software using WMI, registry, or PowerShell, potentially followed by additional discovery or evasion behavior.
AN1101 Analytic 1101
Adversary invokes 'dpkg -l', 'rpm -qa', or other package managers via shell or script to enumerate installed software.
AN1102 Analytic 1102
Adversary runs 'system_profiler SPApplicationsDataType' or queries plist files to enumerate software via Terminal or scripts.
AN1103 Analytic 1103
Adversary uses cloud-native APIs or CLI (e.g., AWS Systems Manager, Azure Resource Graph) to list installed software on cloud workloads.
AN1104 Analytic 1104
Adversary uses 'esxcli software vib list' to enumerate installed VIBs, drivers, and modules.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.