Windows Software Discovery Via PowerShell — Detection Rule

Detects the use of PowerShell based registry queries to pull installed software information from the Uninstall key. This will give an attacker version information on installed software which could be used to identify further vulnerabilities. False positives are unlikely as this is an unusual key to query with PowerShell.

Read the full analysis on IntelFusions