Files
atomic-red-team/Windows/Discovery/Security_Software_Discovery.md
T
Michael Haag 407c84b6f5 Discovery Updates
+ More Tasklist.exe adds
+ Modified file directory listing to be recursive.
2017-11-13 11:02:39 -07:00

612 B

Security Software Discovery

MITRE ATT&CK Technique: T1018

netsh

netsh.exe advfirewall firewall show all profiles

tasklist

Input:

tasklist.exe

Input:

tasklist.exe | findstr virus

Input:

tasklist.exe | findstr cb

Input:

tasklist.exe | findstr defender

PowerShell

powershell.exe get-process | ?{$_.Description -like "*virus*"}

CarbonBlack

powershell.exe get-process | ?{$_.Description -like "*carbonblack*"}

Windows Defender

powershell.exe get-process | ?{$_.Description -like "*defender*"}