system_information_gathering_via_wmicexe
Description
Detects the utilization of wmic.exe in order to obtain specific system information. This action is related to the "System Information Discovery" Technique License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
Query · yara_l
events:
(re.regex($selection1.target.process.file.full_path, `.*wmic\.exe`) and (re.regex($selection1.target.process.command_line, `.* .* DESKTOPMONITOR get pnpdeviceid .*`) or re.regex($selection1.target.process.command_line, `.* .* SOUNDDEV get pnpdeviceid .*`) or re.regex($selection1.target.process.command_line, `.* .* bios get serialnumber .*`) or re.regex($selection1.target.process.command_line, `.* .* baseboard get serialnumber .*`) or re.regex($selection1.target.process.command_line, `.* .* diskdrive get pnpdeviceid .*`) or re.regex($selection1.target.process.command_line, `.* .* cpu get processorid .*`)) and ($selection1.metadata.product_event_type = "4688" or $selection1.metadata.product_event_type = "1"))
condition:
$selection1