BIOC Low

Manipulation of Windows DNS configuration using WMIC

This command can be leveraged by attackers to change the way DNS requests are sent, bypassing the corporate DNS servers.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Tampering
Status:
Enabled
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Windows Management Instrumentation (T1047)
Indicator:

Process action type = execution AND target process cmd = *call*SetDNSServerSearchOrder* AND target process name = wmic.exe Process initiator signature = Signed , Unsigned , N/A , Invalid Signature , Weak Hash , cgo signature = Signed , Unsigned , N/A , Invalid Signature , Weak Hash AND initiator signer != Citrix Systems, Inc. AND cgo signer != Citrix Systems, Inc. AND initiator cmd != *Nutanix* AND cgo cmd != *Nutanix* Host host os = windows

Preventable: yes