EXPLORE
← Back to Explore
T1047

Windows Management Instrumentation

Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems.(Citation: WMI 1-3) WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access, though the latter is facilitated by [Remote Services](https://attack.mitre.org/techniques/T1021) suc...

Windows
87
Detections
4
Sources
42
Threat Actors

BY SOURCE

47sigma20splunk_escu19elastic1kql

PROCEDURES (46)

Wmi14 detections

Auto-extracted: 14 detections for wmi

Service4 detections

Auto-extracted: 4 detections for service

Child Process3 detections

Auto-extracted: 3 detections for child process

Remote2 detections

Auto-extracted: 2 detections for remote

Script Execution Monitoring2 detections

Auto-extracted: 2 detections for script execution monitoring

Wmi2 detections

Auto-extracted: 2 detections for wmi

Process Creation Monitoring2 detections

Auto-extracted: 2 detections for process creation monitoring

Registry2 detections

Auto-extracted: 2 detections for registry

Lateral2 detections

Auto-extracted: 2 detections for lateral

Suspicious2 detections

Auto-extracted: 2 detections for suspicious

Shadow Cop2 detections

Auto-extracted: 2 detections for shadow cop

Powershell2 detections

Auto-extracted: 2 detections for powershell

Bypass2 detections

Auto-extracted: 2 detections for bypass

Privilege2 detections

Auto-extracted: 2 detections for privilege

Wmi2 detections

Auto-extracted: 2 detections for wmi

Suspicious2 detections

Auto-extracted: 2 detections for suspicious

Dll Hijack2 detections

Auto-extracted: 2 detections for dll hijack

Office2 detections

Auto-extracted: 2 detections for office

Ransomware1 detections

Auto-extracted: 1 detections for ransomware

Remote1 detections

Auto-extracted: 1 detections for remote

Exfiltrat1 detections

Auto-extracted: 1 detections for exfiltrat

Dll Hijack1 detections

Auto-extracted: 1 detections for dll hijack

Remote1 detections

Auto-extracted: 1 detections for remote

Dll Hijack1 detections

Auto-extracted: 1 detections for dll hijack

Evasion1 detections

Auto-extracted: 1 detections for evasion

Wmi1 detections

Auto-extracted: 1 detections for wmi

Bypass1 detections

Auto-extracted: 1 detections for bypass

Wmi1 detections

Auto-extracted: 1 detections for wmi

Dll Hijack1 detections

Auto-extracted: 1 detections for dll hijack

Office1 detections

Auto-extracted: 1 detections for office

Wmi1 detections

Auto-extracted: 1 detections for wmi

Privilege1 detections

Auto-extracted: 1 detections for privilege

Service1 detections

Auto-extracted: 1 detections for service

Lateral1 detections

Auto-extracted: 1 detections for lateral

Powershell1 detections

Auto-extracted: 1 detections for powershell

Bypass1 detections

Auto-extracted: 1 detections for bypass

Service1 detections

Auto-extracted: 1 detections for service

Wmi1 detections

Auto-extracted: 1 detections for wmi

Persist1 detections

Auto-extracted: 1 detections for persist

Persist1 detections

Auto-extracted: 1 detections for persist

Registry1 detections

Auto-extracted: 1 detections for registry

Lateral1 detections

Auto-extracted: 1 detections for lateral

Powershell1 detections

Auto-extracted: 1 detections for powershell

Wmi1 detections

Auto-extracted: 1 detections for wmi

Remote1 detections

Auto-extracted: 1 detections for remote

Wmi1 detections

Auto-extracted: 1 detections for wmi

DETECTIONS (87)

Application Removed Via Wmic.EXE
sigmamedium
Application Terminated Via Wmic.EXE
sigmamedium
Computer System Reconnaissance Via Wmic.EXE
sigmamedium
Delayed Execution via Ping
elasticlow
Detect Office products launching wmic.exe
kql
Enumeration Command Spawned via WMIPrvSE
elasticlow
HackTool - CrackMapExec Execution
sigmahigh
HackTool - CrackMapExec Execution Patterns
sigmahigh
HackTool - Potential Impacket Lateral Movement Activity
sigmahigh
Hardware Model Reconnaissance Via Wmic.EXE
sigmamedium
HTML Help HH.EXE Suspicious Child Process
sigmahigh
Impacket Lateral Movement Commandline Parameters
splunk_escu
Impacket Lateral Movement smbexec CommandLine Parameters
splunk_escu
Impacket Lateral Movement WMIExec Commandline Parameters
splunk_escu
Microsoft Build Engine Started by a System Process
elasticmedium
MITRE BZAR Indicators for Execution
sigmamedium
Mofcomp Activity
elasticlow
New Process Created Via Wmic.EXE
sigmamedium
Password Set to Never Expire via WMI
sigmamedium
Persistence via WMI Event Subscription
elasticlow
Persistence via WMI Standard Registry Provider
elastichigh
Possible Lateral Movement PowerShell Spawn
splunk_escu
Potential Product Class Reconnaissance Via Wmic.EXE
sigmamedium
Potential Product Reconnaissance Via Wmic.EXE
sigmamedium
Potential Remote SquiblyTwo Technique Execution
sigmahigh
Potential Unquoted Service Path Reconnaissance Via Wmic.EXE
sigmamedium
Potential Windows Defender Tampering Via Wmic.EXE
sigmahigh
Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell
sigmamedium
PowerShell Invoke CIMMethod CIMSession
splunk_escu
PowerShell Invoke WmiExec Usage
splunk_escu
Process Execution via WMI
splunk_escu
Process Reconnaissance Via Wmic.EXE
sigmamedium
PSExec and WMI Process Creations Block
sigmahigh
RDP Enable or Disable via Win32_TerminalServiceSetting WMI Class
sigmamedium
Registry Manipulation via WMI Stdregprov
sigmamedium
Remote DCOM/WMI Lateral Movement
sigmahigh
Remote Process Instantiation via WMI
splunk_escu
Remote Process Instantiation via WMI and PowerShell
splunk_escu
Remote Process Instantiation via WMI and PowerShell Script Block
splunk_escu
Remote WMI Command Attempt
splunk_escu
Script Event Consumer Spawning Process
sigmahigh
Script Execution via WMI
splunk_escu
Service Control Spawned via Script Interpreter
elasticlow
Service Reconnaissance Via Wmic.EXE
sigmamedium
Service Started/Stopped Via Wmic.EXE
sigmamedium
Service Startup Type Change Via Wmic.EXE
sigmamedium
Successful Account Login Via WMI
sigmalow
Suspicious .NET Code Compilation
elasticmedium
Suspicious Autorun Registry Modified via WMI
sigmahigh
Suspicious Cmd Execution via WMI
elastichigh
Suspicious Encoded Scripts in a WMI Consumer
sigmahigh
Suspicious Execution from a Mounted Device
elasticmedium
Suspicious HH.EXE Execution
sigmahigh
Suspicious Managed Code Hosting Process
elastichigh
Suspicious Microsoft Office Child Process
sigmahigh
Suspicious Process Created Via Wmic.EXE
sigmahigh
Suspicious ScreenConnect Client Child Process
elasticmedium
Suspicious WMI Image Load from MS Office
elasticlow
Suspicious WMIC Execution Via Office Process
sigmahigh
Suspicious WMIC XSL Script Execution
elasticmedium
Suspicious WmiPrvSE Child Process
sigmahigh
System Disk And Volume Reconnaissance Via Wmic.EXE
sigmamedium
T1047 Wmiprvse Wbemcomn DLL Hijack
sigmahigh
Volume Shadow Copy Deletion via PowerShell
elastichigh
Volume Shadow Copy Deletion via WMIC
elastichigh
Web Shell Detection: Script Process Child of Common Web Processes
elastichigh
Windows Hotfix Updates Reconnaissance Via Wmic.EXE
sigmamedium
Windows Script Interpreter Executing Process via WMI
elasticmedium
Windows WinRAR Launched Outside Default Installation Directory
splunk_escu
Windows WMI Impersonate Token
splunk_escu
Windows WMI Process And Service List
splunk_escu
Windows WMI Process Call Create
splunk_escu
Windows WMI Reconnaissance Class Query
splunk_escu
WMI Event Consumer Created Named Pipe
sigmamedium
WMI Incoming Lateral Movement
elasticmedium
WMI Module Loaded By Uncommon Process
sigmalow
WMI Permanent Event Subscription
splunk_escu
WMI Temporary Event Subscription
splunk_escu
WMIC Remote Command Execution
sigmamedium
WMIC Unquoted Services Path Lookup - PowerShell
sigmamedium
Wmiexec Default Output File
sigmacritical
WMImplant Hack Tool
sigmahigh
Wmiprvse LOLBAS Execution Process Spawn
splunk_escu
WmiPrvSE Spawned A Process
sigmamedium
Wmiprvse Wbemcomn DLL Hijack
sigmahigh
Wmiprvse Wbemcomn DLL Hijack - File
sigmacritical
XSL Script Execution Via WMIC.EXE
sigmamedium