mirror of
https://github.com/keyboardcrunch/SentinelOne-ATTACK-Queries
synced 2026-06-08 17:17:21 +00:00
95 lines
3.1 KiB
Markdown
95 lines
3.1 KiB
Markdown
## Discovery
|
|
|
|
### T1010 Application Window Discovery
|
|
Atomics: [T1010](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1010/T1010.md)
|
|
|
|
|
|
### T1217 Browser Bookmark Discovery
|
|
Atomics: [T1217](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1217/T1217.md)
|
|
|
|
|
|
### T1087.002 Domain Account
|
|
Atomics: [T1087.002](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1087.002/T1087.002.md)
|
|
|
|
|
|
### T1069.002 Domain Groups
|
|
Atomics: [T1069.002](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.002/T1069.002.md)
|
|
|
|
|
|
### T1482 Domain Trust Discovery
|
|
Atomics: [T1482](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1482/T1482.md)
|
|
|
|
|
|
### T1083 File and Directory Discovery
|
|
Atomics: [T1083](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1083/T1083.md)
|
|
|
|
|
|
### T1087.001 Local Account
|
|
Atomics: [T1087.001](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1087.001/T1087.001.md)
|
|
|
|
|
|
### T1069.001 Local Groups
|
|
Atomics: [T1069.001](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1069.001/T1069.001.md)
|
|
|
|
|
|
### T1046 Network Service Scanning
|
|
Atomics: [T1046](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1046/T1046.md)
|
|
|
|
|
|
### T1135 Network Share Discovery
|
|
Atomics: [T1135](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1135/T1135.md)
|
|
|
|
|
|
### T1040 Network Sniffing
|
|
Atomics: [T1040](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1040/T1040.md)
|
|
|
|
|
|
### T1201 Password Policy Discovery
|
|
Atomics: [T1201](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1201/T1201.md)
|
|
|
|
|
|
### T1057 Process Discovery
|
|
Atomics: [T1057](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1057/T1057.md)
|
|
|
|
|
|
### T1012 Query Registry
|
|
Atomics: [T1012](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1012/T1012.md)
|
|
|
|
|
|
### T1018 Remote System Discovery
|
|
Atomics: [T1018](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1018/T1018.md)
|
|
|
|
|
|
### T1518.001 Security Software Discovery
|
|
Atomics: [T1518.001](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1518.001/T1518.001.md)
|
|
|
|
|
|
### T1518 Software Discovery
|
|
Atomics: [T1518](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1518/T1518.md)
|
|
|
|
|
|
### T1082 System Information Discovery
|
|
Atomics: [T1082](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1082/T1082.md)
|
|
|
|
|
|
### T1016 System Network Configuration Discovery
|
|
Atomics: [T1016](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1016/T1016.md)
|
|
|
|
|
|
### T1049 System Network Connections Discovery
|
|
Atomics: [T1049](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1049/T1049.md)
|
|
|
|
|
|
### T1033 System Owner/User Discovery
|
|
Atomics: [T1033](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1033/T1033.md)
|
|
|
|
|
|
### T1007 System Service Discovery
|
|
Atomics: [T1007](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1007/T1007.md)
|
|
|
|
|
|
### T1124 System Time Discovery
|
|
Atomics: [T1124](https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1124/T1124.md)
|
|
|
|
|