APT29
|
Step
|
ATT&CK Pattern
|
Detection Type |
Detection Note |
|
12.C.1
|
|
|
Minimum detection criteria was not met for this procedure.
|
|
12.C.2
|
|
|
Minimum detection criteria was not met for this procedure.
|
|
Enumerated installed software via the Registry (Wow6432 Uninstall key) using PowerShell
powershell.exe executing a Registry query for HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall
Enumerated installed software via the Registry (Uninstall key) using PowerShell
powershell.exe executing a Registry query for HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall