
Rule Info
Name
Windows Defender Services Reconnaissance
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the execution of the `sc.exe` utility used to query the status of security services such as Windows Defender.
Adversaries might use this technique to check the status of these security services while enumerating the target system.
Date
2025-02-13 00:00:00
Modified
None
Id
be7bbcdd-f6e1-4026-80c2-8556ad862b15
Tags
attack.discovery attack.t1518.001
Type
Nextron Sigma feed only (private)