1200KM / simulation
T1047 Windows Management Instrumentation — Attack Simulation
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as…
Technique description
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- WMI Execute rundll32
Procedure 00738d2a-4651-4d76-adf2-c43a41dfb243; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- WMI Reconnaissance List Remote Services
Procedure 0fd48ef7-d890-4e93-a533-f7dedd5191d3; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Create a Process using obfuscated Win32_Process
Procedure 10447c83-fc38-462a-a936-5102363b1c43; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- WMI Reconnaissance Processes
Procedure 5750aa16-0e59-4410-8b9a-8a47ca2788e2; elevation not declared required; cleanup not declared. Not executed or individually validated.
- WMI Reconnaissance Software
Procedure 718aebaa-d0e0-471a-8241-c5afa69c7414; elevation not declared required; cleanup not declared. Not executed or individually validated.
- AveMaria/Warzone program.bat WMIC Process Creation
Procedure 778b54b0-ae7a-4f80-b74b-59eddee87ad5; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Create a Process using WMI Query and an Encoded Command
Procedure 7db7a7f9-9531-4840-9b30-46220135441c; elevation not declared required; cleanup not declared. Not executed or individually validated.
- WMI Execute Remote Process
Procedure 9c8ef159-c666-472f-9874-90c8d60d136b; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Impacket wmiexec.py
Procedure a3ddaf15-d1a1-4bc3-8683-84c7c67120fe; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- WMI Execute Local Process
Procedure b3bdfc91-b33e-4c6d-a5c8-d64bee0276b3; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- WMI Reconnaissance Users
Procedure c107778c-dcf5-47c5-af2e-1d058a3df3ea; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Application uninstall using WMIC
Procedure c510d25b-1667-467d-8331-a56d3e9bc4ff; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Deep Panda · G0009
- APT29 · G0016
- Naikon · G0019
- Threat Group-3390 · G0027
- Lotus Blossom · G0030
- Lazarus Group · G0032
- Sandworm Team · G0034
- FIN6 · G0037
- Stealth Falcon · G0038
- menuPass · G0045
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- FIN8 · G0061
- Leviathan · G0065
- MuddyWater · G0069
- GALLIUM · G0093
- APT41 · G0096
- APT-C-36 · G0099
- Wizard Spider · G0102
- Blue Mockingbird · G0108
- Windshift · G0112
- Chimera · G0114
- Indrik Spider · G0119
- Mustang Panda · G0129
- Aquatic Panda · G0143
- Ember Bear · G1003
- Earth Lusca · G1006
- FIN13 · G1016
- Volt Typhoon · G1017
- TA2541 · G1018
- Cinnamon Tempest · G1021
- ToddyCat · G1022
- INC Ransom · G1032
- BlackByte · G1043
- APT42 · G1044
- Velvet Ant · G1047
- Medusa Group · G1051
- MirrorFace · G1054
- VOID MANTICORE · G1055
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.