Skip to content
Threat Feed

Tag

Wmic

14 briefs RSS
high advisory

Potential Tampering With Security Products Via WMIC

Threat actors, including those behind IcedID, LockBit, and Vice Society, actively utilize the Windows Management Instrumentation Command-line (WMIC) utility to uninstall or terminate security products, aiming to impair host defenses and facilitate ransomware deployment or data exfiltration.

defense-impairment tampering wmic windows lolbin
1r 1t
medium advisory

Application Termination Attempt via Wmic.EXE

Adversaries leverage the native Windows Management Instrumentation Command-line (WMIC) utility to terminate applications, specifically security products, as a defense evasion technique.

defense-evasion windows wmic living-off-the-land
1r 2t
medium advisory

WMIC Remote Command Execution Detection

This brief focuses on detecting the abuse of the Windows Management Instrumentation Command-line (WMIC) utility to execute commands or query information on remote systems, a common technique used by attackers for lateral movement and reconnaissance within compromised networks.

lateral-movement reconnaissance execution wmic windows
1r 1t
medium threat

System Disk And Volume Reconnaissance Via Wmic.EXE

Threat actor Volt Typhoon is observed using the built-in Windows Management Instrumentation Command-line (WMIC.EXE) utility to perform system and volume discovery, gathering critical system information that can facilitate further network exploitation and data exfiltration.

Volt Typhoon +3 discovery reconnaissance wmic living-off-the-land windows
1r 2t
medium advisory

Potential Unquoted Service Path Reconnaissance Via Wmic.EXE

Attackers and pentesters commonly use `wmic.exe` to query Windows service configurations for unquoted paths, a reconnaissance technique that identifies potential privilege escalation opportunities.

reconnaissance privilege-escalation windows wmic
1r 2t 1c
medium advisory

Service Reconnaissance Via Wmic.EXE

Adversaries leverage the native Windows Management Instrumentation Command-line (WMIC) utility to perform service reconnaissance on remote systems, querying for existing services as a prelude to identifying potential targets for lateral movement or privilege escalation.

Windows Operating System windows reconnaissance wmic internal-recon
1r 1t
medium advisory

WMIC Product Reconnaissance for Defense Evasion

A threat brief details the use of `wmic.exe` by attackers to perform product reconnaissance, specifically to identify installed firewall and antivirus software, facilitating defense evasion and tailored attack execution.

reconnaissance defense-evasion windows wmic
1r 2t
high advisory

Windows Defender Tampering via WMIC for Defense Evasion

A technique brief describes how adversaries may use `wmic.exe` to tamper with Windows Defender settings, specifically to add exclusions via the `\root\Microsoft\Windows\Defender` WMI namespace, reducing the host's security posture and enabling further malicious activity.

defense-evasion wmic windows-defender endpoint-security windows
1r 2t
high advisory

Volume Shadow Copy Deletion via WMIC

Attackers use Windows Management Instrumentation Command-line (WMIC) to delete volume shadow copies, inhibiting system recovery in ransomware and destructive attacks.

Windows volume-shadow-copy wmic ransomware impact
2r 2t
high threat

Suspicious WMIC Application Uninstallation

This analytic identifies the use of the WMIC command-line tool to uninstall applications non-interactively, a technique used to evade detection by removing security software, as observed in IcedID campaigns.

Splunk Enterprise +2 IcedID defense-evasion application-uninstall wmic
2r
high advisory

Detection of Process Termination via File Path Using WMIC

This analytic detects the use of `wmic.exe` with the `delete` command to terminate a process by specifying its executable path, often used to disable security tools or critical processes during the setup of malicious activities like cryptocurrency mining.

Splunk Enterprise +2 process-termination wmic cryptocurrency-mining endpoint
2r
medium advisory

Detecting WMIC Systeminfo Discovery Activity

This brief covers detection of adversaries using Windows Management Instrumentation Command-line (WMIC) to gather system information, specifically the `computersystem` class, a technique used for reconnaissance.

Windows wmic discovery
2r 1t
medium advisory

Windows WMI Reconnaissance Activity Detection

Detection of Windows Management Instrumentation Command-line (WMIC) usage for reconnaissance by querying common Win32 WMI classes for system information, potentially indicating post-exploitation activity.

Windows wmic reconnaissance post-exploitation
2r 1t
medium advisory

Detection of WMIC System Information Discovery

Adversaries may use Windows Management Instrumentation Command-line (WMIC) to gather system information, specifically using the `computersystem` alias to retrieve details about the system's configuration, which aids in reconnaissance.

Windows discovery wmic
2r 1t