BIOC
Low
✕
Manipulation of Windows DNS configuration using WMIC
This command can be leveraged by attackers to change the way DNS requests are sent, bypassing the corporate DNS servers.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Tampering
- Status:
- Enabled
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Windows Management Instrumentation (T1047)
Indicator:
Process action type = execution AND target process cmd = *call*SetDNSServerSearchOrder* AND target process name = wmic.exe Process initiator signature = Signed , Unsigned , N/A , Invalid Signature , Weak Hash , cgo signature = Signed , Unsigned , N/A , Invalid Signature , Weak Hash AND initiator signer != Citrix Systems, Inc. AND cgo signer != Citrix Systems, Inc. AND initiator cmd != *Nutanix* AND cgo cmd != *Nutanix* Host host os = windows
Preventable: yes