BIOC
Informational
✕
Query startup programs using wmic.exe
Attackers may use wmic.exe to query programs that run automatically when users log onto the computer system.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Discovery
- Status:
- Enabled
ATT&CK tactics: Discovery (TA0007) Execution (TA0002)
ATT&CK techniques: Windows Management Instrumentation (T1047) System Information Discovery (T1082)
Indicator:
Process action type = execution AND target process cmd = *startup* AND target process name = wmic.exe
Preventable: yes