T1047 Windows Management Instrumentation — ATT&CK Technique
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as Distributed Component Object Model and Windows Remote Management. Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS. An adversary can use WMI to interact with local and remote systems and use it as a means to execute various behaviors, such as gathering information for Discovery as well as Execution of commands and payloads. For example, `wmic.exe` can be abused by an adversary to delete shadow copies with the command `wmic.exe Shadowcopy Delete` (i.e., Inhibit System Recovery). **Note:** `wmic.exe` is deprecated as of January of 2024, with the WMIC feature being “disabled by default” on Windows 11+. WMIC will be removed from subsequent Windows releases and replaced by PowerShell as the primary WMI interface. In addition to PowerShell and tools like `wbemtool.exe`, COM APIs can also be used to programmatically interact with WMI via C++, .NET, VBScript, etc.
Detection coverage (50)
- Blue Mockingbird high
- Blue Mockingbird - Registry high
- Potential Maze Ransomware Activity critical
- UNC2452 PowerShell Pattern critical
- WMI Module Loaded By Uncommon Process low
- Remote DCOM/WMI Lateral Movement high
- MITRE BZAR Indicators for Execution medium
- RDP Enable or Disable via Win32_TerminalServiceSetting WMI Class medium
- Successful Account Login Via WMI low
- T1047 Wmiprvse Wbemcomn DLL Hijack high
- PSExec and WMI Process Creations Block high
- Wmiexec Default Output File critical
- Wmiprvse Wbemcomn DLL Hijack - File critical
- Wmiprvse Wbemcomn DLL Hijack high
- WMI Event Consumer Created Named Pipe medium
- WMImplant Hack Tool high
- WMIC Unquoted Services Path Lookup - PowerShell medium
- Suspicious Autorun Registry Modified via WMI high
- HTML Help HH.EXE Suspicious Child Process high
- HackTool - CrackMapExec Execution Patterns high
- Suspicious HH.EXE Execution high
- HackTool - CrackMapExec Execution high
- HackTool - Potential Impacket Lateral Movement Activity high
- Suspicious Microsoft Office Child Process high
- Script Event Consumer Spawning Process high
- New Process Created Via Wmic.EXE medium
- Password Set to Never Expire via WMI medium
- Computer System Reconnaissance Via Wmic.EXE medium
- Potential Windows Defender Tampering Via Wmic.EXE high
- Windows Hotfix Updates Reconnaissance Via Wmic.EXE medium
- Service Reconnaissance Via Wmic.EXE medium
- Service Started/Stopped Via Wmic.EXE medium
- Hardware Model Reconnaissance Via Wmic.EXE medium
- Potential Product Class Reconnaissance Via Wmic.EXE medium
- WMIC Remote Command Execution medium
- Suspicious WMIC Execution Via Office Process high
- XSL Script Execution Via WMIC.EXE medium
- Process Reconnaissance Via Wmic.EXE medium
- Potential Unquoted Service Path Reconnaissance Via Wmic.EXE medium
- Potential Remote SquiblyTwo Technique Execution high
- Application Removed Via Wmic.EXE medium
- Suspicious WmiPrvSE Child Process high
- Potential Product Reconnaissance Via Wmic.EXE medium
- System Disk And Volume Reconnaissance Via Wmic.EXE medium
- Registry Manipulation via WMI Stdregprov medium
- Service Startup Type Change Via Wmic.EXE medium
- Application Terminated Via Wmic.EXE medium
- Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell medium
- Suspicious Process Created Via Wmic.EXE high
- WmiPrvSE Spawned A Process medium
Malware using this technique
- Sardonic
- Meteor
- RogueRobin
- LAMEHUG
- SUNBURST
- MoleNet
- BlackEnergy
- FunnyDream
- jRAT
- Emotet
- AshTag
- FIVEHANDS
- Zebrocy
- Mosquito
- Agent Tesla
- PoshC2
- Bumblebee
- CrackMapExec
- Action RAT
- Covenant
- EvilBunny
- Stuxnet
- PowerSploit
- Raspberry Robin
- IMAPLoader
- POWRUNER
- SocGholish
- FlawedAmmyy
- Qilin
- LODEINFO
- ProLock
- POWERSTATS
- Akira
- TONESHELL
- SILENTTRINITY
- OopsIE
- TAMECAT
- Brute Ratel C4
- Koadic
- INC Ransomware
- DarkGate
- ShrinkLocker
- Sibot
- DustySky
- WannaCry
- EKANS
- RATANKBA
- BlackCat
- NotPetya
- HALFBAKED
Threat actors using this technique
- APT27
- MirrorFace
- APT42
- Cinnamon Tempest
- APT10
- INC Ransom
- Gamaredon Group
- APT32
- Mustang Panda
- MuddyWater
- APT35
- Conti
- Void Manticore
- APT40
- Velvet Ant
- APT-C-36
- FIN7
- GALLIUM
- Volt Typhoon
- Blue Mockingbird
- Ember Bear
- Chimera
- Naikon
- Lazarus Group
- Lotus Blossom
- Sandworm Team
- Earth Lusca
- Evil Corp
- BlackByte
- FIN13
- TA2541
- Stealth Falcon
- Aquatic Panda
- APT29
- OilRig
- Windshift
- FIN6
- Medusa Ransomware
- ToddyCat
- Deep Panda
- APT41
- FIN8