Files
atomic-red-team/Windows/Discovery/Security_Software_Discovery.md
T
Michael Haag 976f3ba40f Adds
Security software discovery
system time discovery
2017-11-01 16:02:40 -07:00

460 B

Security Software Discovery

MITRE ATT&CK Technique: T1018

netsh

netsh.exe advfirewall firewall

tasklist

tasklist.exe

PowerShell

powershell.exe get-process | ?{$_.Description -like "*virus*"}

CarbonBlack

powershell.exe get-process | ?{$_.Description -like "*carbonblack*"}

Windows Defender

powershell.exe get-process | ?{$_.Description -like "*defender*"}