Analytics BIOC Low

Potential SCCM credential harvesting using WMI detected

Attackers or malware may use WMI queries to obtain domain credentials that are used by the SCCM.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Execution (TA0002) Credential Access (TA0006)
ATT&CK techniques: Windows Management Instrumentation (T1047) Unsecured Credentials (T1552)
Detector tags: Microsoft SCCM Analytics
Attacker's goals:

Obtain credentials used by the SCCM service.

Investigative actions:

Examine the process that executed the WMI query and the CGO and verify that the processes are from a trusted source. Inspect the system for malicious activity that is related to that process.

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • Potential SCCM credential harvesting using WMI detected from a remote machine Medium (parent: Low)
  • Potential SCCM inventory query using WMI detected Low
  • Potential Enumeration of SCCM User, Device, and Deployment Data via WMI Low