For the complete documentation index, see llms.txt. This page is also available as Markdown.

Remote command execution via wmic.exe

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

Windows Management Instrumentation (T1047)

Severity

Low

Description

Remote command execution using the Windows Management Instrumentation command-line tool.

Attacker's Goals

The attacker is expanding his reach into your network by executing commands on a remote endpoint.

Investigative actions

  • Examine Alert Details > Overview to identify the source endpoint, process running the command execution, process owner, and execution destination.

Variations

Remote command execution via wmic.exe

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002)

ATT&CK Technique

Windows Management Instrumentation (T1047)

Severity

Medium

Description

Remote command execution using the Windows Management Instrumentation command-line tool.

Attacker's Goals

The attacker is expanding his reach into your network by executing commands on a remote endpoint.

Investigative actions

  • Examine Alert Details > Overview to identify the source endpoint, process running the command execution, process owner, and execution destination.

Was this helpful?