1200KM / detection
T1047 Windows Management Instrumentation — Detection Rules
Detection workspace for T1047 Windows Management Instrumentation: 47 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Remote DCOM/WMI Lateral Movement · test · high · {"product":"rpc_firewall","category":"application","definition":"Requirements: install and apply the RPC Firewall to all processes with \"audit:true action:block uuid:367abb81-9844-35f1-ad32-98f038001003"}
- MITRE BZAR Indicators for Execution · test · medium · {"product":"zeek","service":"dce_rpc"}
- Successful Account Login Via WMI · stable · low · {"product":"windows","service":"security"}
- T1047 Wmiprvse Wbemcomn DLL Hijack · test · high · {"product":"windows","service":"security"}
- PSExec and WMI Process Creations Block · test · high · {"product":"windows","service":"windefend","definition":"Requirements:Enabled Block process creations originating from PSExec and WMI commands from Attack Surface Reduction (GUID: d1e49aac-8f56-4280-b9ba-993a6d77406c)"}
- Wmiexec Default Output File · test · critical · {"category":"file_event","product":"windows"}
- Wmiprvse Wbemcomn DLL Hijack - File · test · critical · {"product":"windows","category":"file_event"}
- Wmiprvse Wbemcomn DLL Hijack · test · high · {"product":"windows","category":"image_load"}
- WMI Event Consumer Created Named Pipe · test · medium · {"product":"windows","category":"pipe_created","definition":"Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575"}
- WMIC Unquoted Services Path Lookup - PowerShell · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- WMImplant Hack Tool · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Suspicious Autorun Registry Modified via WMI · experimental · high · {"category":"process_creation","product":"windows"}
- HTML Help HH.EXE Suspicious Child Process · test · high · {"category":"process_creation","product":"windows"}
- Suspicious HH.EXE Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - CrackMapExec Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - CrackMapExec Execution Patterns · stable · high · {"category":"process_creation","product":"windows"}
- HackTool - Potential Impacket Lateral Movement Activity · stable · high · {"category":"process_creation","product":"windows"}
- Suspicious Microsoft Office Child Process · test · high · {"category":"process_creation","product":"windows"}
- RDP Enable or Disable via Win32_TerminalServiceSetting WMI Class · experimental · medium · {"category":"process_creation","product":"windows"}
- Script Event Consumer Spawning Process · test · high · {"category":"process_creation","product":"windows"}
- Password Set to Never Expire via WMI · experimental · medium · {"category":"process_creation","product":"windows"}
- Potential Windows Defender Tampering Via Wmic.EXE · test · high · {"product":"windows","category":"process_creation"}
- Process Creation Attempt via Wmic.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Computer System Reconnaissance Via Wmic.EXE · test · medium · {"product":"windows","category":"process_creation"}
- Hardware Model Reconnaissance Via Wmic.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Windows Hotfix Updates Reconnaissance Via Wmic.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Potential Process Reconnaissance via Wmic.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Potential Product Reconnaissance Via Wmic.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Potential Product Class Reconnaissance Via Wmic.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Service Reconnaissance Via Wmic.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Potential Unquoted Service Path Reconnaissance Via Wmic.EXE · test · medium · {"category":"process_creation","product":"windows"}
- System Disk And Volume Reconnaissance Via Wmic.EXE · test · medium · {"category":"process_creation","product":"windows"}
- WMIC Remote Command Execution · test · medium · {"category":"process_creation","product":"windows"}
- Service Started/Stopped Via Wmic.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Service Startup Type Change Via Wmic.EXE · experimental · medium · {"category":"process_creation","product":"windows"}
- Potential Remote SquiblyTwo Technique Execution · test · high · {"category":"process_creation","product":"windows"}
- Registry Enumeration via WMI Stdregprov · experimental · medium · {"category":"process_creation","product":"windows"}
- Registry Manipulation via WMI Stdregprov · experimental · medium · {"category":"process_creation","product":"windows"}
- Suspicious WMIC Execution Via Office Process · test · high · {"product":"windows","category":"process_creation"}
- Suspicious Process Created Via Wmic.EXE · test · high · {"category":"process_creation","product":"windows"}
- Application Termination Attempt via Wmic.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Application Removed Via Wmic.EXE · test · medium · {"category":"process_creation","product":"windows"}
- XSL Script Execution Via WMIC.EXE · test · medium · {"category":"process_creation","product":"windows"}
- WmiPrvSE Spawned A Process · stable · medium · {"category":"process_creation","product":"windows"}
- Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell · stable · medium · {"category":"process_creation","product":"windows"}
- Suspicious WmiPrvSE Child Process · test · high · {"product":"windows","category":"process_creation"}
- Suspicious Encoded Scripts in a WMI Consumer · test · high · {"product":"windows","category":"wmi_event"}
Atlas deterministic concepts
T1047 Windows Management Instrumentation
MATCH(wmi_process_or_remote_operation) AND caller_or_command NOT_IN approved_wmi_activity -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0364 Behavioral Detection Strategy for WMI Execution Abuse on Windows
AN1031 Analytic 1031
Detects adversarial abuse of WMI to execute local or remote commands via WMIC, PowerShell, or COM API through a multi-event chain: process creation, command execution, and corresponding network connection if remote.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Deep Panda · G0009
- APT29 · G0016
- Naikon · G0019
- Threat Group-3390 · G0027
- Lotus Blossom · G0030
- Lazarus Group · G0032
- Sandworm Team · G0034
- FIN6 · G0037
- Stealth Falcon · G0038
- menuPass · G0045
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- FIN8 · G0061
- Leviathan · G0065
- MuddyWater · G0069
- GALLIUM · G0093
- APT41 · G0096
- APT-C-36 · G0099
- Wizard Spider · G0102
- Blue Mockingbird · G0108
- Windshift · G0112
- Chimera · G0114
- Indrik Spider · G0119
- Mustang Panda · G0129
- Aquatic Panda · G0143
- Ember Bear · G1003
- Earth Lusca · G1006
- FIN13 · G1016
- Volt Typhoon · G1017
- TA2541 · G1018
- Cinnamon Tempest · G1021
- ToddyCat · G1022
- INC Ransom · G1032
- BlackByte · G1043
- APT42 · G1044
- Velvet Ant · G1047
- Medusa Group · G1051
- MirrorFace · G1054
- VOID MANTICORE · G1055
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.