BIOC Informational

Enumeration of services via WMIC

Attackers may enumerate existing services using wmic.exe.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Discovery
Status:
Enabled
ATT&CK tactics: Discovery (TA0007) Execution (TA0002)
ATT&CK techniques: System Service Discovery (T1007) Windows Management Instrumentation (T1047)
Indicator:

Process action type = execution AND target process cmd = * service * , * win32_service * AND target process name = wmic.exe

Preventable: yes