Analytics BIOC Low

Remote command execution via wmic.exe

Remote command execution using the Windows Management Instrumentation command-line tool.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Windows Management Instrumentation (T1047)
Attacker's goals:

The attacker is expanding his reach into your network by executing commands on a remote endpoint.

Investigative actions:

Examine Alert Details > Overview to identify the source endpoint, process running the command execution, process owner, and execution destination.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Remote command execution via wmic.exe Medium (parent: Low)