For the complete documentation index, see llms.txt. This page is also available as Markdown.

Discovery of host users via WMIC

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

System Owner/User Discovery (T1033)

Severity

Informational

Description

Attackers may use wmic.exe to list the users of a host, and potentially its owner.

Attacker's Goals

Attackers can attempt to use the command to discover host users and enumerate a huge amount of information.

Investigative actions

Verify whether the command that was executed is benign or normal for the host and/or user performing it (for example, it may be an IT script).

Was this helpful?