Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is security-software discovery?

Security-software discovery is activity used to find what defensive tools are installed and how they are configured.

That may include antivirus, EDR, logging agents, firewalls or other security controls.

This can be a useful part of the incident story because somebody who learns what is watching them may change what they do next.

What might be checked?

A process may look for:

  • installed security products;
  • running services;
  • EDR or antivirus processes;
  • logging agents;
  • exclusions;
  • firewall state; or
  • security-related configuration.

Endpoint records can often show the process or command that performed the check.

Simplified endpoint sequence
10:22:03Z process=query-tool.exe action=enumerate running services10:22:11Z result=SecurityAgent present10:23:04Z later event=attempt to stop SecurityAgent

The first event tells you the defensive product was discovered. The later event is what starts to show how that information may have been used.

Keep discovery and tampering separate

This is important.

Finding a security product does not mean it was disabled.

A later attempt to stop a service, add an exclusion or alter logging is a different event and should be proved separately.

That distinction helps avoid overstating what a simple inventory query means.

Security products can create their own useful trail

EDR or antivirus products may themselves record:

  • the discovery command;
  • the process chain;
  • the user context;
  • attempted configuration changes;
  • prevention or blocking;
  • and later activity from the same process.

So even an attempt to understand or interfere with the security tooling can generate useful evidence.

Normal management tools do this as well

Software inventory, support agents and deployment platforms routinely inspect installed security products.

The sequence is what often makes the difference.

A scheduled inventory job is one thing. Security checks immediately after suspicious access, followed by targeted changes to the same product, are much more useful to investigate.

The practical point is: security-software discovery tells you what the session learned about the defences. Follow that into any later configuration change, service stop or loss of telemetry.

Reference: CIM-125Cyber Incidents & Offender Methods