{"id":"T1010","name":"Application Window Discovery","url":"https://attack.mitre.org/techniques/T1010","tactics":["discovery"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0097","stix_id":"x-mitre-detection-strategy--d2daf569-4fc9-46a3-97b7-4d3d76c04a64","name":"Detection of Application Window Enumeration via API or Scripting","url":"https://attack.mitre.org/detectionstrategies/DET0097","analytics":[{"id":"AN0271","stix_id":"x-mitre-analytic--c76d69b2-f1d4-4867-965b-886b6caf95be","name":"Analytic 0271","description":"Processes using Win32 API calls (e.g., EnumWindows, GetForegroundWindow) or scripting tools (e.g., PowerShell, VBScript) to enumerate open windows. These often appear with reconnaissance or data collection TTPs.","url":"https://attack.mitre.org/detectionstrategies/DET0097#AN0271","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"wineventlog-powershell"}],"mutable_elements":[{"field":"AccessedFunction","description":"Tune to focus on suspicious function calls (e.g., user32.dll!EnumWindows)."},{"field":"UserContext","description":"Detect behavior from non-interactive or low-privileged users where enumeration is uncommon."},{"field":"TimeWindow","description":"Shorten detection scope to rapid successive window enumeration attempts."}],"live":true,"detection_strategies":["DET0097"],"techniques":["T1010"]},{"id":"AN0272","stix_id":"x-mitre-analytic--557d1a5d-31ae-4600-b4ed-a456d9964a83","name":"Analytic 0272","description":"Scripted or binary usage of X11 utilities (e.g., xdotool, wmctrl) or direct /proc/*/window mappings to discover open GUI windows and active desktops.","url":"https://attack.mitre.org/detectionstrategies/DET0097#AN0272","platforms":["Linux"],"log_source_references":[{"name":"auditd:EXECVE","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-execve"},{"name":"linus:syslog","channel":"None","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"linus-syslog"}],"mutable_elements":[{"field":"ExecutableName","description":"Common window management utilities can be tuned to reduce noise (e.g., xprop, xwininfo)."},{"field":"DisplayContext","description":"Restrict detection to processes executing under graphical sessions (e.g., DISPLAY=:0)."}],"live":true,"detection_strategies":["DET0097"],"techniques":["T1010"]},{"id":"AN0273","stix_id":"x-mitre-analytic--a31400ee-ac3e-408e-aa4d-fb2b470142ab","name":"Analytic 0273","description":"Processes that utilize AppleScript, `CGWindowListCopyWindowInfo`, or `NSRunningApplication` APIs to list active application windows and foreground processes.","url":"https://attack.mitre.org/detectionstrategies/DET0097#AN0273","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"None","data_component":"DC0021","data_component_name":"OS API Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:osquery","channel":"process_events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"AppleScriptTarget","description":"Tunable to ignore benign scripting like automation by known apps."},{"field":"ParentProcess","description":"Useful to suppress expected automation processes."}],"live":true,"detection_strategies":["DET0097"],"techniques":["T1010"]}],"live":true,"version":"1.0","techniques":["T1010"]}],"sigma_rules":[{"id":"13addce7-47b2-4ca0-a98f-1de964d1d669","title":"SCM Database Handle Failure","author":"Roberto Rodriguez @Cyb3rWard0g","status":"test","level":"medium","date":"2019-08-12","modified":"2022-07-11","description":"Detects non-system users failing to get a handle of the SCM database.","references":["https://threathunterplaybook.com/hunts/windows/190826-RemoteSCMHandle/notebook.html"],"logsource":{"product":"windows","service":"security"},"tags":["attack.discovery","attack.t1010"],"path":"rules/windows/builtin/security/win_security_scm_database_handle_failure.yml","techniques":["T1010"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}