Process Creation from an Unusual WMI Client
Description
Identify attempts to create a process calling the WMI Win32_Process Create Method. Adversaries may use WMI to indirectly spawn a child process.
Query · eql
api where
process.Ext.api.name == "IWbemServices::ExecMethod" and
process.Ext.api.parameters.operation : "*Win32_Process::Create*" and
not (process.code_signature.trusted == true and
process.code_signature.subject_name in ("TENABLE, INC.", "Autodesk, Inc.", "Archer Technologies LLC", "Opera Norway AS",
"Beijing Qihu Technology Co., Ltd.", "ACD Systems International Inc.", "CS.NIWC-ATLANTIC.001", "Check Point Software Technologies Ltd.",
"VMware, Inc.", "Dell Technologies Inc.", "Atlassian Pty Ltd", "Recast Software, Inc.", "Specops Software Inc.", "Omnissa, LLC")) and
not process.executable :
("C:\\Program Files\\*.exe",
"C:\\Program Files (x86)\\*.exe",
"C:\\Windows\\System32\\wbem\\WMIC.exe",
"C:\\Windows\\System32\\svchost.exe",
"F:\\SuperGrate.exe",
"D:\\supergrate*",
"\\Device\\Mup\\*",
"\\Device\\HarddiskVolume5\\SuperGrate\\SuperGrate.exe",
"C:\\Windows\\System32\\cscript.exe",
"C:\\Windows\\SysWOW64\\cscript.exe",
"C:\\Windows\\System32\\inetsrv\\w3wp.exe",
"C:\\Program Files\\Qognify\\UpdateAgent\\bin\\VMS_UpdateAgent.exe",
"C:\\Program Files\\SCAP Compliance Checker 5.10.1\\lib64\\scc64.exe",
"?:\\Program Files\\Microsoft Configuration Manager\\bin\\X64\\smsexec.exe") and
not process.parent.executable : ("C:\\Program Files (x86)\\Avaya\\Avaya one-X Agent\\OneXAgentUI.exe") and
not (process.name == "powershell.exe" and process.parent.executable == "C:\\Program Files\\Microsoft Monitoring Agent\\Agent\\MonitoringHost.exe") and
not (process.executable : "C:\\Windows\\System32\\svchost.exe" and
process.parent.executable : "C:\\Windows\\System32\\services.exe" and
process.command_line :
("C:\\windows\\system32\\svchost.exe -k netsvcs -p",
"C:\\Windows\\system32\\svchost.exe -k netsvcs -p -s Winmgmt",
"C:\\Windows\\system32\\svchost.exe -k winmgmt -s Winmgmt",
"C:\\WINDOWS\\system32\\svchost.exe -k netsvcs -s Winmgmt")) and
not (process.executable : "C:\\Windows\\System32\\wsmprovhost.exe" and process.parent.executable : "C:\\Windows\\System32\\svchost.exe") and
not (process.name : "powershell.exe" and user.id == "S-1-5-18") and
not (process.name : "powershell.exe" and process.parent.executable : "D:\\ServiceNow\\PROD\\agent\\jre\\bin\\java.exe") and
not (process.name == "powershell.exe" and
process.command_line : ("powershell.exe -NonInteractive -NoProfile -ExecutionPolicy Bypass -EncodedCommand CgAgACAAIAAgACYAYwBoAGMAcAAuAGMAbwBtACAANgA1ADAAMAAxACAAPgAgACQAbgB1AGwAbAAKACAAIAAgACAAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgAuAFIAZQBhAGQAVABvAEUAbgBkACgAKQAKACAAIAAgACAAJABzAHAAbABpAHQAXwBwAGEAcgB0AHMAIAA9ACAAJABlAHgAZQBjAF8AdwByAGEAcABwAGUAcgBfAHMAdAByAC4AUwBwAGwAaQB0ACgAQAAoACIAYAAwAGAAMABgADAAYAAwACIAKQAsACAAMgAsACAAWwBTAHQAcgBpAG4AZwBTAHAAbABpAHQATwBwAHQAaQBvAG4AcwBdADoAOgBSAGUAbQBvAHYAZQBFAG0AcAB0AHkARQBuAHQAcgBpAGUAcwApAAoAIAAgACAAIABTAGUAdAAtAFYAYQByAGkAYQBiAGwAZQAgAC0ATgBhAG0AZQAgAGoAcwBvAG4AXwByAGEAdwAgAC0AVgBhAGwAdQBlACAAJABzAHAAbABpAHQAXwBwAGEAcgB0AHMAWwAxAF0ACgAgACAAIAAgACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIAIAA9ACAAWwBTAGMAcgBpAHAAdABCAGwAbwBjAGsAXQA6ADoAQwByAGUAYQB0AGUAKAAkAHMAcABsAGkAdABfAHAAYQByAHQAcwBbADAAXQApAAoAIAAgACAAIAAmACQAZQB4AGUAYwBfAHcAcgBhAHAAcABlAHIACgA=",
"\"powershell.exe\" & {Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType Hyphen -CommandParamVariation C -UseEncodedArguments -EncodedArgumentsParamVariation EA -Execute -ErrorAction Stop}",
"\"powershell.exe\" & {Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType Hyphen -EncodedCommandParamVariation E -Execute -ErrorAction Stop}",
"\"powershell.exe\" & {Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType Hyphen -CommandParamVariation C -Execute -ErrorAction Stop}",
"*dAByAHkAIAB7ACAAWwBDAG8AbgBzAG8AbABlAF0AOgA6AEkAbgBwAHUAdABFAG4AYwBvAGQAaQ*",
"*JABFAHIAcgBvAHIAQQBjAHQAaQBvAG4AUAByAGUAZgBlAHIAZQBuAGMAZQAgAD0AIAAiAFMAdABvAHAAIgA*",
"*cABcAEEAcABwAEQAYQB0AGEAXABMAG8AYwBhAGwALwBBAGMAdABpAHYAZQBCAGEAYwBrAHUAcAAv*",
"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe -executionpolicy unrestricted -noninteractive -nologo -noprofile -command \"& { [Console]::OutputEncoding = [Text.UTF8Encoding]::UTF8; Write-Output SNC_PowerShell_PID=$pid*",
"*AkAGUAeABlAGMAXwB3AHIAYQBwAHAAZQByAF8AcwB0AHIALgBTAHAAbABpAHQAKABAACg*",
"\"C:\\Windows\\system32\\windowspowershell\\v1.0\\powershell.exe\" -ExecutionPolicy Unrestricted -Command \"& '\"C:\\Program Files\\Microsoft Monitoring Agent\\Agent\\Health Service State\\Monitoring Host Temporary Files *\\LaunchRestartHealthService.ps1*",
"\"powershell.exe\" & {Out-ATHPowerShellCommandLineParameter -CommandLineSwitchType Hyphen -EncodedCommandParamVariation E -UseEncodedArguments -EncodedArgumentsParamVariation EncodedArguments -Execute -ErrorAction Stop}")) and
not (process.name : "powershell.exe" and
process.parent.executable : ("C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
"C:\\Windows\\System32\\wsmprovhost.exe",
"?:\\Program Files\\PowerShell\\*\\pwsh.exe")) and
not (process.name : "powershell.exe" and
process.parent.executable : ("?:\\Users\\*\\.local\\bin\\claude.exe",
"?:\\Users\\*\\@anthropic-ai\\claude-code\\bin\\claude.exe")) and
not (process.executable : ("C:\\Windows\\SysWOW64\\msiexec.exe", "C:\\Windows\\System32\\msiexec.exe") and
process.parent.executable : ("C:\\Windows\\System32\\msiexec.exe", "C:\\Windows\\SysWOW64\\msiexec.exe") and
process.code_signature.subject_name == "Microsoft Windows" and
process.code_signature.trusted == true) and
not (process.executable : ("C:\\Windows\\System32\\wscript.exe", "C:\\Windows\\SysWOW64\\wscript.exe") and
process.parent.executable : "C:\\Windows\\System32\\svchost.exe")