Cross-source coverage

T1047 / ATT&CK

Windows Management Instrumentation

168 rules · 158 families across 9 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components.

The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as Distributed Component Object Model and Windows Remote Management. Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS.

An adversary can use WMI to interact with local and remote systems and use it as a means to execute various behaviors, such as gathering information for Discovery as well as Execution of commands and payloads. For example, wmic.exe can be abused by an adversary to delete shadow copies with the command wmic.exe Shadowcopy Delete (i.e., Inhibit System Recovery).

Note: wmic.exe is deprecated as of January of 2024, with the WMIC feature being “disabled by default” on Windows 11+. WMIC will be removed from subsequent Windows releases and replaced by PowerShell as the primary WMI interface. In addition to PowerShell and tools like wbemtool.exe, COM APIs can also be used to programmatically interact with WMI via C++,.NET, VBScript, etc.

Tactics
Execution
Platforms
Windows
Telemetry
WinEventLog:SysmonWinEventLog:WMI

How MITRE says to detect it DET0364

Behavioral Detection Strategy for WMI Execution Abuse on Windows

Windows Analytic 1031

Detects adversarial abuse of WMI to execute local or remote commands via WMIC, PowerShell, or COM API through a multi-event chain: process creation, command execution, and corresponding network connection if remote.

  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Sysmon EventCode=3, 22
  • WinEventLog:WMI EventCode=5857, 5858, 5860, 5861

SigmaHQ/sigma

52 rules
Detection Severity Format
Potential Maze Ransomware Activity Critical Sigma
UNC2452 PowerShell Pattern Critical Sigma
Wmiexec Default Output File Critical Sigma
Wmiprvse Wbemcomn DLL Hijack - File Critical Sigma
Blue Mockingbird High Sigma
Blue Mockingbird - Registry High Sigma
HackTool - CrackMapExec Execution High Sigma
HackTool - CrackMapExec Execution Patterns High Sigma
HackTool - Potential Impacket Lateral Movement Activity High Sigma
HTML Help HH.EXE Suspicious Child Process High Sigma

+ 42 more from SigmaHQ/sigma → showing the 10 highest-severity

Wazuh Core Ruleset

26 rules · 24 families
Detection Severity Format
A powershell process created by WMI executed a base64 encoded command High Wazuh XML
System information discovery activity detected Medium Wazuh XML
Windows DC - Clock skew too great. Medium Wazuh XML
Windows management instrumentation (WMI) created a powershell process Medium Wazuh XML
WMI query for System Information Discovery. Medium Wazuh XML
Access to namespace denied. Low Wazuh XML
A quota reached a warning value, WMI stopped WMIPRVSE.EXE. Low Wazuh XML
Error encountered trying to load MOF. Low Wazuh XML
Event filter could not be activated. Low Wazuh XML
Event provider attempted to register an intrinsic event query. Low Wazuh XML

+ 16 more from Wazuh Core Ruleset → showing the 10 highest-severity

elastic/protections-artifacts

20 rules
Detection Severity Format
Execution via a Suspicious WMI Client Undefined Elastic TOML
Execution via WMI ActiveScript Event Consumer Undefined Elastic TOML
Execution via WMI CommandLine Event Consumer Undefined Elastic TOML
Execution via WMI followed by Network Connection Undefined Elastic TOML
Inhibit System Recovery via Microsoft Office Process Undefined Elastic TOML
Inhibit System Recovery via Obfuscated Commands Undefined Elastic TOML
Inhibit System Recovery via Windows Command Shell Undefined Elastic TOML
Microsoft Office File Execution via WMI Undefined Elastic TOML
Process Creation from an Unusual WMI Client Undefined Elastic TOML
Registry Modification via WMI StdRegProv Undefined Elastic TOML

+ 10 more from elastic/protections-artifacts → showing the 10 highest-severity

splunk/security_content

20 rules
Detection Severity Format
Impacket Lateral Movement Commandline Parameters Undefined SPL
Impacket Lateral Movement smbexec CommandLine Parameters Undefined SPL
Impacket Lateral Movement WMIExec Commandline Parameters Undefined SPL
Possible Lateral Movement PowerShell Spawn Undefined SPL
PowerShell Invoke CIMMethod CIMSession Undefined SPL
PowerShell Invoke WmiExec Usage Undefined SPL
Process Execution via WMI Undefined SPL
Remote Process Instantiation via WMI Undefined SPL
Remote Process Instantiation via WMI and PowerShell Undefined SPL
Remote Process Instantiation via WMI and PowerShell Script Block Undefined SPL

+ 10 more from splunk/security_content → showing the 10 highest-severity

elastic/detection-rules

19 rules
Detection Severity Format
Persistence via WMI Standard Registry Provider High Elastic TOML
Suspicious Cmd Execution via WMI High Elastic TOML
Suspicious Managed Code Hosting Process High Elastic TOML
Volume Shadow Copy Deletion via PowerShell High Elastic TOML
Volume Shadow Copy Deletion via WMIC High Elastic TOML
Web Shell Detection: Script Process Child of Common Web Processes High Elastic TOML
Microsoft Build Engine Started by a System Process Medium Elastic TOML
Suspicious Execution from a Mounted Device Medium Elastic TOML
Suspicious .NET Code Compilation Medium Elastic TOML
Suspicious ScreenConnect Client Child Process Medium Elastic TOML

+ 9 more from elastic/detection-rules → showing the 10 highest-severity

socfortress/Wazuh-Rules

18 rules · 15 families
Detection Severity Format
Sysmon - Event 13: RegistryEvent PsExec EulaAccepted Detected Critical Wazuh XML
Powershell script: CIM method/session detected (lateral movement) High Wazuh XML
Powershell script: Invoke-WmiExec detected (pass-the-hash) High Wazuh XML
Powershell script: WMI-based remote execution detected High Wazuh XML
Sysmon - Event 1: Process creation · win.eventdata.parentImage = winword.exe$|excel.exe$|powerpnt.exe 3 variants High Wazuh XML
Sysmon - Event 1: Process creation · win.eventdata.parentImage = winword.exe$|excel.exe$|powerpnt.exe 3 variants High Wazuh XML
Sysmon - Event 1: Process creation · win.eventdata.parentImage = winword.exe$|excel.exe$|powerpnt.exe 3 variants High Wazuh XML
Sysmon - Event 10: ProcessAccess by · Windows Management Instrumentation (T1047) Low Wazuh XML
Sysmon - Event 11: FileCreate by · File System Permissions Weakness (T1047) Low Wazuh XML
Sysmon - Event 11: FileCreate by · Windows Management Instrumentation (T1047) Low Wazuh XML

+ 8 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

chronicle/detection-rules

7 rules
Detection Severity Format
impacket_wmiexec_cisa_report Medium YARA-L
fireeye_red_team_tool__modified_impacket_wmiexec_via_cmdline Undefined YARA-L
possible_impacketobfuscation_wmiexec_or_smbexec_utility_via_cmdline Undefined YARA-L
suspicious_wmi_execution Undefined YARA-L
ursnif_trojan_detection_cmd_obfuscation Undefined YARA-L
wmi_event_subscription Undefined YARA-L
wmi_persistence__script_event_consumer Undefined YARA-L

Azure/Azure-Sentinel

3 rules · 1 family
Detection Severity Format
detect-impacket-wmiexec 3 variants Undefined KQL
detect-impacket-wmiexec 3 variants Undefined KQL
detect-impacket-wmiexec 3 variants Undefined KQL

Bert-JanP/Hunting-Queries-Detection-Rules

3 rules
Detection Severity Format
MITRE ATT&CK Mapping Undefined KQL
WMIC Antivirus Discovery Undefined KQL
WMIC Remote Command Execution Undefined KQL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.