Windows Management Instrumentation T1047

Tactic: Execution

Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components.

Events covered

22 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 140 rules share fields, values, and exclusions.

Fields filtered most (64 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine65contains 45, regex_match 13, in 4, wildcard 3, ends_with 2, eq 2, is_not_null 1, length_compare 1, match 1call, create, (?i)\s(os|logicaldisk|share|cpu|memorychip|useraccount|ni..., bootstatuspolicy, delete
Image49ends_with 40, wildcard 5, contains 3, eq 1, ne 1, starts_with 1\wmic.exe, \cmd.exe, \powershell.exe, \pwsh.exe, \wmiprvse.exe
process_name48eq 38, in 5, regex_match 4, ends_with 2wmic.exe, cmd.exe, certutil.exe, powershell.exe, bitsadmin.exe
OriginalFileName46eq 46wmic.exe, bcdedit.exe, powershell.exe, pwsh.dll, vssadmin.exe
parent_process_name28eq 21, regex_match 4, in 3, ends_with 2wmiprvse.exe, cmd.exe, (?i)(WmiPrvSE), (?i)(\x5cwbem\x5cwmiprvse\.exe), \WmiPrvSE.exe
EventID24eq 244688, 4104, 1, 10, 4103
host.os.type22eq 22
event.type21eq 20, ne 1start, change, deletion
EventType17eq 14, starts_with 3, ne 1start, Image loaded, deletion, modification
process.args15eq 11, wildcard 4, contains 2, ends_with 1, is_not_null 1, starts_with 1get, -encodehex, /c, /q, create
ParentImage13ends_with 11, wildcard 2, contains 1, is_not_null 1\wmiprvse.exe, \eqnedt32.exe, \excel.exe, \msaccess.exe, ?:\windows\sys*\wbem\scrcons.exe
ScriptBlockText6contains 4, in 2, eq 1 active_users , basic_info , change_user , win32_service , *invoke-cimmethod*
Type6eq 6
dll.name6eq 6wmiutils.dll, jscript.dll, vbscript.dll, wbemprox.dll, fastprox.dll
event.category5eq 5process, library, driver

Top indicator values (1024 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
OriginalFileNameeq
wmic.exe
4180
OriginalFileNameeq
powershell.exe
6138
Imageends_with
\wmic.exe
2762
Imageends_with
\powershell.exe
6179
Imageends_with
\pwsh.exe
6165
Imageends_with
\cmd.exe
5130
Imageends_with
\cscript.exe
472
Imageends_with
\mshta.exe
466
Imageends_with
\msiexec.exe
420
Imageends_with
\regsvr32.exe
464
Imageends_with
\rundll32.exe
494
Imageends_with
\wmiprvse.exe
42
Imageends_with
\wscript.exe
474
event.typeeq
start
191078
process_nameeq
wmic.exe
1666
process_nameeq
cmd.exe
10121
process_nameeq
powershell.exe
6184
process_nameeq
wscript.exe
583
process_nameeq
certutil.exe
444
parent_process_nameeq
wmiprvse.exe
1525
EventTypeeq
start
13391
EventIDeq
4688
10317
EventIDeq
4104
6269
EventIDeq
1
5241
CommandLinecontains
call
88
CommandLinecontains
create
729
CommandLinecontains
delete
431
CommandLinecontains
process
45
ParentImageends_with
\wmiprvse.exe
58
event.categoryeq
process
5142

Exclusions (588 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.code_signature.trustedeq
true
9
user.ideq
s-1-5-18
9
user.ideq
S-1-5-18
3
process_nameeq
powershell.exe
7
process_nameeq
cmd.exe
4
process_nameeq
wscript.exe
3
Imageeq
c:\windows\system32\svchost.exe
4
Imageeq
?:\windows\system32\conhost.exe
2
Imageeq
c:\windows\system32\wscript.exe
2
ParentImageeq
c:\windows\system32\services.exe
4
Imageends_with
\wmiprvse.exe
3
Imageends_with
\werfault.exe
2
process.Ext.token.integrity_level_nameeq
system
3
CommandLinecontains
create
2
Hasheseq
0e692d9d3342fdcab1ce3d61aed0520989a94371e5898edb266c92f1fe11c97f
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 55 rules

Elastic 44 rules

Splunk 38 rules

Kusto 2 rules

YARA-L 1 rule