Operation DragonReturn DcRAT AV Enumeration via SecurityCenter2 WMI

Detects the use of wmic.exe or PowerShell to query the WMI 'SecurityCenter2' namespace for 'AntiVirusProduct' information. This is a common discovery technique used by adversaries to identify installed security software to assess their environment before launching payloads.