Cross-source coverage
T1047 / ATT&CK
Windows Management Instrumentation
162 rules · 152 families across 9 sources.
6 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components.
The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as Distributed Component Object Model and Windows Remote Management. Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS.
An adversary can use WMI to interact with local and remote systems and use it as a means to execute various behaviors, such as gathering information for Discovery as well as Execution of commands and payloads. For example, wmic.exe can be abused by an adversary to delete shadow copies with the command wmic.exe Shadowcopy Delete (i.e., Inhibit System Recovery).
Note: wmic.exe is deprecated as of January of 2024, with the WMIC feature being “disabled by default” on Windows 11+. WMIC will be removed from subsequent Windows releases and replaced by PowerShell as the primary WMI interface. In addition to PowerShell and tools like wbemtool.exe, COM APIs can also be used to programmatically interact with WMI via C++,.NET, VBScript, etc.
- Tactics
- Execution
- Platforms
- Windows
- Telemetry
-
WinEventLog:SysmonWinEventLog:WMI
How MITRE says to detect it DET0364
Behavioral Detection Strategy for WMI Execution Abuse on Windows
Windows Analytic 1031
Detects adversarial abuse of WMI to execute local or remote commands via WMIC, PowerShell, or COM API through a multi-event chain: process creation, command execution, and corresponding network connection if remote.
WinEventLog:SysmonEventCode=1WinEventLog:SysmonEventCode=3, 22WinEventLog:WMIEventCode=5857, 5858, 5860, 5861
SigmaHQ/sigma
52 rules| Detection | Severity | Format |
|---|---|---|
| Potential Maze Ransomware Activity | Critical | Sigma |
| UNC2452 PowerShell Pattern | Critical | Sigma |
| Wmiexec Default Output File | Critical | Sigma |
| Wmiprvse Wbemcomn DLL Hijack - File | Critical | Sigma |
| Blue Mockingbird | High | Sigma |
| Blue Mockingbird - Registry | High | Sigma |
| HackTool - CrackMapExec Execution | High | Sigma |
| HackTool - CrackMapExec Execution Patterns | High | Sigma |
| HackTool - Potential Impacket Lateral Movement Activity | High | Sigma |
| HTML Help HH.EXE Suspicious Child Process | High | Sigma |
+ 42 more from SigmaHQ/sigma → showing the 10 highest-severity
Wazuh Core Ruleset
26 rules · 24 families| Detection | Severity | Format |
|---|---|---|
| A powershell process created by WMI executed a base64 encoded command | High | Wazuh XML |
| System information discovery activity detected | Medium | Wazuh XML |
| Windows DC - Clock skew too great. | Medium | Wazuh XML |
| Windows management instrumentation (WMI) created a powershell process | Medium | Wazuh XML |
| WMI query for System Information Discovery. | Medium | Wazuh XML |
| Access to namespace denied. | Low | Wazuh XML |
| A quota reached a warning value, WMI stopped WMIPRVSE.EXE. | Low | Wazuh XML |
| Error encountered trying to load MOF. | Low | Wazuh XML |
| Event filter could not be activated. | Low | Wazuh XML |
| Event provider attempted to register an intrinsic event query. | Low | Wazuh XML |
+ 16 more from Wazuh Core Ruleset → showing the 10 highest-severity
elastic/protections-artifacts
20 rules| Detection | Severity | Format |
|---|---|---|
| Execution via a Suspicious WMI Client | Undefined | Elastic TOML |
| Execution via WMI ActiveScript Event Consumer | Undefined | Elastic TOML |
| Execution via WMI CommandLine Event Consumer | Undefined | Elastic TOML |
| Execution via WMI followed by Network Connection | Undefined | Elastic TOML |
| Inhibit System Recovery via Microsoft Office Process | Undefined | Elastic TOML |
| Inhibit System Recovery via Obfuscated Commands | Undefined | Elastic TOML |
| Inhibit System Recovery via Windows Command Shell | Undefined | Elastic TOML |
| Microsoft Office File Execution via WMI | Undefined | Elastic TOML |
| Process Creation from an Unusual WMI Client | Undefined | Elastic TOML |
| Registry Modification via WMI StdRegProv | Undefined | Elastic TOML |
+ 10 more from elastic/protections-artifacts → showing the 10 highest-severity
splunk/security_content
20 rules| Detection | Severity | Format |
|---|---|---|
| Impacket Lateral Movement Commandline Parameters | Undefined | SPL |
| Impacket Lateral Movement smbexec CommandLine Parameters | Undefined | SPL |
| Impacket Lateral Movement WMIExec Commandline Parameters | Undefined | SPL |
| Possible Lateral Movement PowerShell Spawn | Undefined | SPL |
| PowerShell Invoke CIMMethod CIMSession | Undefined | SPL |
| PowerShell Invoke WmiExec Usage | Undefined | SPL |
| Process Execution via WMI | Undefined | SPL |
| Remote Process Instantiation via WMI | Undefined | SPL |
| Remote Process Instantiation via WMI and PowerShell | Undefined | SPL |
| Remote Process Instantiation via WMI and PowerShell Script Block | Undefined | SPL |
+ 10 more from splunk/security_content → showing the 10 highest-severity
elastic/detection-rules
19 rules| Detection | Severity | Format |
|---|---|---|
| Persistence via WMI Standard Registry Provider | High | Elastic TOML |
| Suspicious Cmd Execution via WMI | High | Elastic TOML |
| Suspicious Managed Code Hosting Process | High | Elastic TOML |
| Volume Shadow Copy Deletion via PowerShell | High | Elastic TOML |
| Volume Shadow Copy Deletion via WMIC | High | Elastic TOML |
| Web Shell Detection: Script Process Child of Common Web Processes | High | Elastic TOML |
| Microsoft Build Engine Started by a System Process | Medium | Elastic TOML |
| Suspicious Execution from a Mounted Device | Medium | Elastic TOML |
| Suspicious .NET Code Compilation | Medium | Elastic TOML |
| Suspicious ScreenConnect Client Child Process | Medium | Elastic TOML |
+ 9 more from elastic/detection-rules → showing the 10 highest-severity
socfortress/Wazuh-Rules
18 rules · 15 families+ 8 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
Azure/Azure-Sentinel
3 rules · 1 family| Detection | Severity | Format |
|---|---|---|
| detect-impacket-wmiexec 3 variants | Undefined | KQL |
| detect-impacket-wmiexec 3 variants | Undefined | KQL |
| detect-impacket-wmiexec 3 variants | Undefined | KQL |
Bert-JanP/Hunting-Queries-Detection-Rules
3 rules| Detection | Severity | Format |
|---|---|---|
| MITRE ATT&CK Mapping | Undefined | KQL |
| WMIC Antivirus Discovery | Undefined | KQL |
| WMIC Remote Command Execution | Undefined | KQL |
chronicle/detection-rules
1 rule| Detection | Severity | Format |
|---|---|---|
| impacket_wmiexec_cisa_report | Medium | YARA-L |