APT29
|
Step
|
ATT&CK Pattern
|
Detection Type |
Detection Note |
|
12.C.1
|
|
|
Telemetry showed script block with registry query for installed software.
[1]
|
|
12.C.2
|
|
|
Telemetry showed script block with registry query for installed software.
[1]
|
|
Enumerated installed software via the Registry (Wow6432 Uninstall key) using PowerShell
powershell.exe executing a Registry query for HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall
[1]
Enumerated installed software via the Registry (Uninstall key) using PowerShell
powershell.exe executing a Registry query for HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
[1]