BIOC
Informational
✕
Enumeration of services via WMIC
Attackers may enumerate existing services using wmic.exe.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Discovery
- Status:
- Enabled
ATT&CK tactics: Discovery (TA0007) Execution (TA0002)
ATT&CK techniques: System Service Discovery (T1007) Windows Management Instrumentation (T1047)
Indicator:
Process action type = execution AND target process cmd = * service * , * win32_service * AND target process name = wmic.exe
Preventable: yes