Real-world descriptions of how a group, tool or campaign used a technique.
93 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareBlack Basta | Black Basta has used WMI to execute files over the network. |
| T1047 Windows Management Instrumentation |
MalwareStoneDrill | StoneDrill has used the WMI command-line (WMIC) utility to run tasks. |
| T1047 Windows Management Instrumentation |
MalwareOopsIE | OopsIE uses WMI to perform discovery techniques. |
| T1047 Windows Management Instrumentation |
MalwareRogueRobin | RogueRobin uses various WMI queries to check if the sample is running in a sandbox. |
| T1047 Windows Management Instrumentation |
MalwareMosquito | Mosquito's installer uses WMI to search for antivirus display names. |
| T1047 Windows Management Instrumentation |
MalwareSibot | Sibot has used WMI to discover network connections and configurations. Sibot has also used the Win32_Process class to execute a malicious DLL. |
| T1047 Windows Management Instrumentation |
MalwareBazar | Bazar can execute a WMI query to gather information about the installed antivirus engine. |
| T1047 Windows Management Instrumentation |
MalwareRATANKBA | RATANKBA uses WMI to perform process monitoring. |
| T1047 Windows Management Instrumentation |
MalwareLockBit 2.0 | LockBit 2.0 can use wmic.exe to delete volume shadow copies. |
| T1047 Windows Management Instrumentation |
MalwareZebrocy | One variant of Zebrocy uses WMI queries to gather information. |
| T1047 Windows Management Instrumentation |
MalwareCobalt Strike | Cobalt Strike can use WMI to deliver a payload to a remote host. |
| T1047 Windows Management Instrumentation |
MalwareSUNBURST | SUNBURST used the WMI query |
| T1047 Windows Management Instrumentation |
MalwareEvilBunny | EvilBunny has used WMI to gather information about the system. |
| T1047 Windows Management Instrumentation |
MalwareREvil | REvil can use WMI to monitor for and kill specific processes listed in its configuration file. |
| T1047 Windows Management Instrumentation |
MalwareValak | Valak can use |
| T1047 Windows Management Instrumentation |
MalwareAshTag | AshTag can use a .NET program to execute WMI queries and send unique victim IDs to C2. |
| T1047 Windows Management Instrumentation |
MalwareFunnyDream | FunnyDream can use WMI to open a Windows command shell on a remote machine. |
| T1047 Windows Management Instrumentation |
MalwareSysUpdate | SysUpdate can use WMI for execution on a compromised host. |
| T1047 Windows Management Instrumentation |
MalwareLAMEHUG | LAMEHUG can use wmic to collect system information. |
| T1047 Windows Management Instrumentation |
MalwareFELIXROOT | FELIXROOT uses WMI to query the Windows Registry. |
| T1047 Windows Management Instrumentation |
MalwareMeteor | Meteor can use `wmic.exe` as part of its effort to delete shadow copies. |
| T1047 Windows Management Instrumentation |
MalwareMaze | Maze has used WMI to attempt to delete the shadow volumes on a machine, and to connect a virtual machine to the network domain of the victim organization's network. |
| T1047 Windows Management Instrumentation |
MalwareLunarWeb | LunarWeb can use WMI queries for discovery on the victim host. |
| T1047 Windows Management Instrumentation |
MalwareOctopus | Octopus has used wmic.exe for local discovery information. |
| T1047 Windows Management Instrumentation |
MalwareQilin | Qilin can use WMIC to change the Volume Shadow Copy Service (VSS) startup type to manual. |
| T1047 Windows Management Instrumentation |
MalwareAgent Tesla | Agent Tesla has used wmi queries to gather information from the system. |
| T1047 Windows Management Instrumentation |
MalwarePOWERSTATS | POWERSTATS can use WMI queries to retrieve data from compromised hosts. |
| T1047 Windows Management Instrumentation |
MalwareRemexi | Remexi executes received commands with wmic.exe (for WMI commands). |
| T1047 Windows Management Instrumentation |
MalwareAstaroth | Astaroth uses WMIC to execute payloads. |
| T1047 Windows Management Instrumentation |
MalwareQakBot | QakBot can execute WMI queries to gather information. |
| T1047 Windows Management Instrumentation |
MalwarejRAT | jRAT uses WMIC to identify anti-virus products installed on the victim’s machine and to obtain firewall details. |
| T1047 Windows Management Instrumentation |
MalwareINC Ransomware | INC Ransomware has the ability to use wmic.exe to spread to multiple endpoints within a compromised environment. |
| T1047 Windows Management Instrumentation |
MalwareFIVEHANDS | FIVEHANDS can use WMI to delete files on a target machine. |
| T1047 Windows Management Instrumentation |
MalwareHermeticWizard | HermeticWizard can use WMI to create a new process on a remote machine via `C:\windows\system32\cmd.exe /c start C:\windows\system32\\regsvr32.exe /s /iC:\windows\<filename>.dll`. |
| T1047 Windows Management Instrumentation |
ToolCovenant | Covenant can utilize WMI to install new Grunt listeners through XSL files or command one-liners. |
| T1047 Windows Management Instrumentation |
ToolSILENTTRINITY | SILENTTRINITY can use WMI for lateral movement. |
| T1047 Windows Management Instrumentation |
ToolPowerSploit | PowerSploit's |
| T1047 Windows Management Instrumentation |
ToolImpacket | Impacket's `wmiexec` module can be used to execute commands through WMI. |
| T1047 Windows Management Instrumentation |
ToolEmpire | Empire can use WMI to deliver a payload to a remote host. |
| T1047 Windows Management Instrumentation |
ToolPoshC2 | PoshC2 has a number of modules that use WMI to execute tasks. |
| T1047 Windows Management Instrumentation |
ToolBrute Ratel C4 | Brute Ratel C4 can use WMI to move laterally. |
| T1047 Windows Management Instrumentation |
ToolCrackMapExec | CrackMapExec can execute remote commands using Windows Management Instrumentation. |
| T1047 Windows Management Instrumentation |
ToolKoadic | Koadic can use WMI to execute commands. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.