T1047 Windows Management Instrumentation
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems.(Citation: WMI 1-3) WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access,…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Potential Maze Ransomware Activitycriticaltest · windows
- UNC2452 PowerShell Patterncriticaltest · windows
- Wmiexec Default Output Filecriticaltest · windows
- Wmiprvse Wbemcomn DLL Hijack - Filecriticaltest · windows
- HackTool - CrackMapExec Execution Patternshighstable · windows
- HackTool - Potential Impacket Lateral Movement Activityhighstable · windows
- Blue Mockingbirdhightest · windows
- Blue Mockingbird - Registryhightest · windows
- HTML Help HH.EXE Suspicious Child Processhightest · windows
- HackTool - CrackMapExec Executionhightest · windows
- PSExec and WMI Process Creations Blockhightest · windows
- Potential Remote SquiblyTwo Technique Executionhightest · windows
- Potential Windows Defender Tampering Via Wmic.EXEhightest · windows
- Remote DCOM/WMI Lateral Movementhightest · rpc_firewall
- Script Event Consumer Spawning Processhightest · windows
- Suspicious Encoded Scripts in a WMI Consumerhightest · windows
- Suspicious HH.EXE Executionhightest · windows
- Suspicious Microsoft Office Child Processhightest · windows
- Suspicious Process Created Via Wmic.EXEhightest · windows
- Suspicious WMIC Execution Via Office Processhightest · windows
- Suspicious WmiPrvSE Child Processhightest · windows
- T1047 Wmiprvse Wbemcomn DLL Hijackhightest · windows
- WMImplant Hack Toolhightest · windows
- Wmiprvse Wbemcomn DLL Hijackhightest · windows
- Suspicious Autorun Registry Modified via WMIhighexperimental · windows
Showing 25 of 40.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.