Suspicious WMIC Execution Via Office Process — Detection Rule

Office application called wmic to proxye execution through a LOLBIN process. This is often used to break suspicious parent-child chain (Office app spawns LOLBin).

Read the full analysis on IntelFusions