Remote WMI process execution
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
3 Days
Required Data
XDR Agent
Detector Tags
Impacket Analytics
ATT&CK Tactic
Lateral Movement (TA0008)
ATT&CK Technique
Remote Services (T1021), Remote Services: Windows Remote Management (T1021.006)
Severity
Medium
Description
A host that rarely initiates WMI to other remote hosts triggered a remote process execution by using WMI RPC.
Attacker's Goals
Perform lateral movement to new hosts to expand the foothold within a network.
Investigative actions
Investigate the processes being spawned on the host for malicious activities.
Correlate the RPC call from the source host and understand which process or software initiated it.
Variations
PreviousRemote usage of VM Service Account token
NextRemoval of an Azure Owner from an Application or Service Principal
Was this helpful?
