Analytics BIOC
Low
✕
Potential SCCM credential harvesting using WMI detected
Attackers or malware may use WMI queries to obtain domain credentials that are used by the SCCM.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Execution (TA0002) Credential Access (TA0006)
ATT&CK techniques: Windows Management Instrumentation (T1047) Unsecured Credentials (T1552)
Detector tags: Microsoft SCCM Analytics
Attacker's goals:
Obtain credentials used by the SCCM service.
Investigative actions:
Examine the process that executed the WMI query and the CGO and verify that the processes are from a trusted source. Inspect the system for malicious activity that is related to that process.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
3 variations:
- Potential SCCM credential harvesting using WMI detected from a remote machine Medium (parent: Low)
- Potential SCCM inventory query using WMI detected Low
- Potential Enumeration of SCCM User, Device, and Deployment Data via WMI Low