Security Software Discovery via Command Line
Detects the execution of common Windows command-line tools (such as cmd, powershell, or wmic) being used to query system information related to security configurations, antivirus status, firewall status, or installed security products. This behavior is indicative of an adversary performing reconnaissance to understand the defensive landscape of a compromised host.
Microsoft Sentinel (KQL)

