T1047 Wmiprvse Wbemcomn DLL Hijack — Detection Rule

Detects a threat actor creating a file named `wbemcomn.dll` in the `C:\Windows\System32\wbem\` directory over the network for a WMI DLL Hijack scenario.

Read the full analysis on IntelFusions