← Back to Explore
sigmamediumHunting
WMIC Unquoted Services Path Lookup - PowerShell
Detects known WMI recon method to look for unquoted service paths, often used by pentest inside of powershell scripts attackers enum scripts
Detection Query
selection:
ScriptBlockText|contains:
- "Get-WmiObject "
- "gwmi "
ScriptBlockText|contains|all:
- " Win32_Service "
- Name
- DisplayName
- PathName
- StartMode
condition: selection
Author
Nasreddine Bencherchali (Nextron Systems)
Created
2022-06-20
Data Sources
windowsps_script
Platforms
windows
References
Tags
attack.executionattack.t1047
Raw Content
title: WMIC Unquoted Services Path Lookup - PowerShell
id: 09658312-bc27-4a3b-91c5-e49ab9046d1b
related:
- id: 68bcd73b-37ef-49cb-95fc-edc809730be6
type: similar
status: test
description: Detects known WMI recon method to look for unquoted service paths, often used by pentest inside of powershell scripts attackers enum scripts
references:
- https://github.com/nccgroup/redsnarf/blob/35949b30106ae543dc6f2bc3f1be10c6d9a8d40e/redsnarf.py
- https://github.com/S3cur3Th1sSh1t/Creds/blob/eac23d67f7f90c7fc8e3130587d86158c22aa398/PowershellScripts/jaws-enum.ps1
- https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/
author: Nasreddine Bencherchali (Nextron Systems)
date: 2022-06-20
modified: 2022-11-25
tags:
- attack.execution
- attack.t1047
logsource:
product: windows
category: ps_script
definition: 'Requirements: Script Block Logging must be enabled'
detection:
selection:
ScriptBlockText|contains:
- 'Get-WmiObject '
- 'gwmi '
ScriptBlockText|contains|all:
- ' Win32_Service '
- 'Name'
- 'DisplayName'
- 'PathName'
- 'StartMode'
condition: selection
falsepositives:
- Unknown
level: medium