AppLocker and Security Product Enumeration via PowerShell, reg.exe, or wmic
Detects reconnaissance activities targeting host-based security configurations, including AppLocker policies, Windows security features via registry keys, and endpoint security product status via WMI. These actions are common in the early stages of an attack to understand the environment's defensive posture.
SentinelOne

