Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0364 — Behavioral Detection Strategy for WMI Execution Abuse on Windows
DET0364

Behavioral Detection Strategy for WMI Execution Abuse on Windows

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1031 Analytic 1031
Windows

Detects adversarial abuse of WMI to execute local or remote commands via WMIC, PowerShell, or COM API through a multi-event chain: process creation, command execution, and corresponding network connection if remote.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=3, 22 WinEventLog:WMI EventCode=5857, 5858, 5860, 5861
[WMIQueryScope] Restrict detection scope to suspicious WMI namespaces like `\root\cimv2`, `\root\subscription`.
[TimeWindow] Set maximum allowable time window to correlate WMI process creation and remote connections.
[UserContext] Tune based on interactive vs. system-level execution (e.g., via SYSTEM or low-privileged users).
[RemoteDestinationThreshold] Number of unique remote hosts contacted using WMI within a time window.
[SuspiciousCommandPatterns] Regex patterns to identify adversary-like usage (e.g., `wmic process call`, `powershell Invoke-WmiMethod`).

Detected Techniques

1

Details

MITRE ID
DET0364
STIX ID
x-mitre-detection-strategy--8374a5e5-6d9f-4896-9546-a4d998188ac5
Analytics
1
Techniques Detected
1
By Tactic
Execution
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.