Analytics BIOC
Low
✕
WmiPrvSe.exe Rare Child Command Line
A remote WMI command executed a binary proxy, the Windows Management Instrumentation (WMI) Provider Host wmiprvse.exe, which executed a rare child command line. Executing a rare child process can be an indication of remote code execution abuse by an attacker.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)
ATT&CK techniques: Remote Services (T1021) Remote Services: Windows Remote Management (T1021.006) Windows Management Instrumentation (T1047)
Attacker's goals:
Gain code execution on a remote host.
Investigative actions:
Investigate the processes being spawned from WmiPrvse.exe on the host for malicious indicators. Correlate the RPC call from the source host and understand what initiated it.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- WmiPrvSe.exe Rare Child Command Line Medium (parent: Low)