Tag
Potential Tampering With Security Products Via WMIC
1 rule 1 TTPThreat actors, including those behind IcedID, LockBit, and Vice Society, actively utilize the Windows Management Instrumentation Command-line (WMIC) utility to uninstall or terminate security products, aiming to impair host defenses and facilitate ransomware deployment or data exfiltration.
Application Termination Attempt via Wmic.EXE
1 rule 2 TTPsAdversaries leverage the native Windows Management Instrumentation Command-line (WMIC) utility to terminate applications, specifically security products, as a defense evasion technique.
WMIC Remote Command Execution Detection
1 rule 1 TTPThis brief focuses on detecting the abuse of the Windows Management Instrumentation Command-line (WMIC) utility to execute commands or query information on remote systems, a common technique used by attackers for lateral movement and reconnaissance within compromised networks.
System Disk And Volume Reconnaissance Via Wmic.EXE
1 rule 2 TTPsThreat actor Volt Typhoon is observed using the built-in Windows Management Instrumentation Command-line (WMIC.EXE) utility to perform system and volume discovery, gathering critical system information that can facilitate further network exploitation and data exfiltration.
Potential Unquoted Service Path Reconnaissance Via Wmic.EXE
1 rule 2 TTPs 1 CVEAttackers and pentesters commonly use `wmic.exe` to query Windows service configurations for unquoted paths, a reconnaissance technique that identifies potential privilege escalation opportunities.
Service Reconnaissance Via Wmic.EXE
1 rule 1 TTPAdversaries leverage the native Windows Management Instrumentation Command-line (WMIC) utility to perform service reconnaissance on remote systems, querying for existing services as a prelude to identifying potential targets for lateral movement or privilege escalation.
WMIC Product Reconnaissance for Defense Evasion
1 rule 2 TTPsA threat brief details the use of `wmic.exe` by attackers to perform product reconnaissance, specifically to identify installed firewall and antivirus software, facilitating defense evasion and tailored attack execution.
Windows Defender Tampering via WMIC for Defense Evasion
1 rule 2 TTPsA technique brief describes how adversaries may use `wmic.exe` to tamper with Windows Defender settings, specifically to add exclusions via the `\root\Microsoft\Windows\Defender` WMI namespace, reducing the host's security posture and enabling further malicious activity.
Volume Shadow Copy Deletion via WMIC
2 rules 2 TTPsAttackers use Windows Management Instrumentation Command-line (WMIC) to delete volume shadow copies, inhibiting system recovery in ransomware and destructive attacks.
Suspicious WMIC Application Uninstallation
2 rulesThis analytic identifies the use of the WMIC command-line tool to uninstall applications non-interactively, a technique used to evade detection by removing security software, as observed in IcedID campaigns.
Detection of Process Termination via File Path Using WMIC
2 rulesThis analytic detects the use of `wmic.exe` with the `delete` command to terminate a process by specifying its executable path, often used to disable security tools or critical processes during the setup of malicious activities like cryptocurrency mining.
Detecting WMIC Systeminfo Discovery Activity
2 rules 1 TTPThis brief covers detection of adversaries using Windows Management Instrumentation Command-line (WMIC) to gather system information, specifically the `computersystem` class, a technique used for reconnaissance.
Windows WMI Reconnaissance Activity Detection
2 rules 1 TTPDetection of Windows Management Instrumentation Command-line (WMIC) usage for reconnaissance by querying common Win32 WMI classes for system information, potentially indicating post-exploitation activity.
Detection of WMIC System Information Discovery
2 rules 1 TTPAdversaries may use Windows Management Instrumentation Command-line (WMIC) to gather system information, specifically using the `computersystem` alias to retrieve details about the system's configuration, which aids in reconnaissance.