1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1518 Software Discovery — Detection Rules

Detection workspace for T1518 Software Discovery: 4 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

T1518 Software Discovery

MATCH(command_or_api IN software_inventory_operations) AND caller NOT_IN approved_inventory_tools -> ALERT

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0392 Multi-Platform Software Discovery Behavior Chain

AN1100 Analytic 1100

Adversary spawns a process or script to enumerate installed software using WMI, registry, or PowerShell, potentially followed by additional discovery or evasion behavior.

AN1101 Analytic 1101

Adversary invokes 'dpkg -l', 'rpm -qa', or other package managers via shell or script to enumerate installed software.

AN1102 Analytic 1102

Adversary runs 'system_profiler SPApplicationsDataType' or queries plist files to enumerate software via Terminal or scripts.

AN1103 Analytic 1103

Adversary uses cloud-native APIs or CLI (e.g., AWS Systems Manager, Azure Resource Graph) to list installed software on cloud workloads.

AN1104 Analytic 1104

Adversary uses 'esxcli software vib list' to enumerate installed VIBs, drivers, and modules.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1518 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.