{"id":"97b9ce1e-c5ab-11ea-87d0-0242ac130003","title":"PSExec and WMI Process Creations Block","description":"Detects blocking of process creations originating from PSExec and WMI commands","author":"Bhabesh Raj","status":"test","level":"high","date":"2020-07-14","modified":"2022-12-25","tags":["attack.execution","attack.lateral-movement","attack.t1047","attack.t1569.002"],"technique_ids":["T1047","T1569.002"],"logsource":{"product":"windows","service":"windefend","definition":"Requirements:Enabled Block process creations originating from PSExec and WMI commands from Attack Surface Reduction (GUID: d1e49aac-8f56-4280-b9ba-993a6d77406c)"},"falsepositives":["Unknown"],"references":["https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide#block-process-creations-originating-from-psexec-and-wmi-commands","https://twitter.com/duff22b/status/1280166329660497920"],"source_path":"rules/windows/builtin/windefend/win_defender_asr_psexec_wmi.yml","source_sha256":"628c32035d2bd274ec33656e88d0d04b6faf7405b44239f8580f0449d7bd4590","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/builtin/windefend/win_defender_asr_psexec_wmi.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: PSExec and WMI Process Creations Block\nid: 97b9ce1e-c5ab-11ea-87d0-0242ac130003\nstatus: test\ndescription: Detects blocking of process creations originating from PSExec and WMI commands\nreferences:\n    - https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide#block-process-creations-originating-from-psexec-and-wmi-commands\n    - https://twitter.com/duff22b/status/1280166329660497920\nauthor: Bhabesh Raj\ndate: 2020-07-14\nmodified: 2022-12-25\ntags:\n    - attack.execution\n    - attack.lateral-movement\n    - attack.t1047\n    - attack.t1569.002\nlogsource:\n    product: windows\n    service: windefend\n    definition: 'Requirements:Enabled Block process creations originating from PSExec and WMI commands from Attack Surface Reduction (GUID: d1e49aac-8f56-4280-b9ba-993a6d77406c)'\ndetection:\n    selection:\n        EventID: 1121\n        ProcessName|endswith:\n            - '\\wmiprvse.exe'\n            - '\\psexesvc.exe'\n    condition: selection\nfalsepositives:\n    - Unknown\nlevel: high\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1047","id":"T1047","name":"Windows Management Instrumentation","page":"techniques/enterprise/T1047/"},{"key":"enterprise/T1569.002","id":"T1569.002","name":"Service Execution","page":"techniques/enterprise/T1569.002/"}],"data_path":"data/detection-rules/97b9ce1e-c5ab-11ea-87d0-0242ac130003.json","kind":"sigma"}
