Analytics BIOC Low

WmiPrvSe.exe Rare Child Command Line

A remote WMI command executed a binary proxy, the Windows Management Instrumentation (WMI) Provider Host wmiprvse.exe, which executed a rare child command line. Executing a rare child process can be an indication of remote code execution abuse by an attacker.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)
ATT&CK techniques: Remote Services (T1021) Remote Services: Windows Remote Management (T1021.006) Windows Management Instrumentation (T1047)
Attacker's goals:

Gain code execution on a remote host.

Investigative actions:

Investigate the processes being spawned from WmiPrvse.exe on the host for malicious indicators. Correlate the RPC call from the source host and understand what initiated it.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • WmiPrvSe.exe Rare Child Command Line Medium (parent: Low)