Application Window Discovery
Discovery
Retrieving running application window titles:
1
get-process | where-object {$_.mainwindowtitle -ne ""} | Select-Object mainwindowtitle
Copied!
A COM method that also includes the process path and window location coordinates:
1
[activator]::CreateInstance([type]::GetTypeFromCLSID("13709620-C279-11CE-A49E-444553540000")).windows()
Copied!

References

Application Window Discovery, Technique T1010 - Enterprise | MITRE ATT&CK®
Last modified 2yr ago
Copy link
Contents
References