ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1047×

93 examples

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareBlack Basta

Black Basta has used WMI to execute files over the network.

T1047
Windows Management Instrumentation
MalwareStoneDrill

StoneDrill has used the WMI command-line (WMIC) utility to run tasks.

T1047
Windows Management Instrumentation
MalwareOopsIE

OopsIE uses WMI to perform discovery techniques.

T1047
Windows Management Instrumentation
MalwareRogueRobin

RogueRobin uses various WMI queries to check if the sample is running in a sandbox.

T1047
Windows Management Instrumentation
MalwareMosquito

Mosquito's installer uses WMI to search for antivirus display names.

T1047
Windows Management Instrumentation
MalwareSibot

Sibot has used WMI to discover network connections and configurations. Sibot has also used the Win32_Process class to execute a malicious DLL.

T1047
Windows Management Instrumentation
MalwareBazar

Bazar can execute a WMI query to gather information about the installed antivirus engine.

T1047
Windows Management Instrumentation
MalwareRATANKBA

RATANKBA uses WMI to perform process monitoring.

T1047
Windows Management Instrumentation
MalwareLockBit 2.0

LockBit 2.0 can use wmic.exe to delete volume shadow copies.

T1047
Windows Management Instrumentation
MalwareZebrocy

One variant of Zebrocy uses WMI queries to gather information.

T1047
Windows Management Instrumentation
MalwareCobalt Strike

Cobalt Strike can use WMI to deliver a payload to a remote host.

T1047
Windows Management Instrumentation
MalwareSUNBURST

SUNBURST used the WMI query Select * From Win32_SystemDriver to retrieve a driver listing.

T1047
Windows Management Instrumentation
MalwareEvilBunny

EvilBunny has used WMI to gather information about the system.

T1047
Windows Management Instrumentation
MalwareREvil

REvil can use WMI to monitor for and kill specific processes listed in its configuration file.

T1047
Windows Management Instrumentation
MalwareValak

Valak can use wmic process call create in a scheduled task to launch plugins and for execution.

T1047
Windows Management Instrumentation
MalwareAshTag

AshTag can use a .NET program to execute WMI queries and send unique victim IDs to C2.

T1047
Windows Management Instrumentation
MalwareFunnyDream

FunnyDream can use WMI to open a Windows command shell on a remote machine.

T1047
Windows Management Instrumentation
MalwareSysUpdate

SysUpdate can use WMI for execution on a compromised host.

T1047
Windows Management Instrumentation
MalwareLAMEHUG

LAMEHUG can use wmic to collect system information.

T1047
Windows Management Instrumentation
MalwareFELIXROOT

FELIXROOT uses WMI to query the Windows Registry.

T1047
Windows Management Instrumentation
MalwareMeteor

Meteor can use `wmic.exe` as part of its effort to delete shadow copies.

T1047
Windows Management Instrumentation
MalwareMaze

Maze has used WMI to attempt to delete the shadow volumes on a machine, and to connect a virtual machine to the network domain of the victim organization's network.

T1047
Windows Management Instrumentation
MalwareLunarWeb

LunarWeb can use WMI queries for discovery on the victim host.

T1047
Windows Management Instrumentation
MalwareOctopus

Octopus has used wmic.exe for local discovery information.

T1047
Windows Management Instrumentation
MalwareQilin

Qilin can use WMIC to change the Volume Shadow Copy Service (VSS) startup type to manual.

T1047
Windows Management Instrumentation
MalwareAgent Tesla

Agent Tesla has used wmi queries to gather information from the system.

T1047
Windows Management Instrumentation
MalwarePOWERSTATS

POWERSTATS can use WMI queries to retrieve data from compromised hosts.

T1047
Windows Management Instrumentation
MalwareRemexi

Remexi executes received commands with wmic.exe (for WMI commands).

T1047
Windows Management Instrumentation
MalwareAstaroth

Astaroth uses WMIC to execute payloads.

T1047
Windows Management Instrumentation
MalwareQakBot

QakBot can execute WMI queries to gather information.

T1047
Windows Management Instrumentation
MalwarejRAT

jRAT uses WMIC to identify anti-virus products installed on the victim’s machine and to obtain firewall details.

T1047
Windows Management Instrumentation
MalwareINC Ransomware

INC Ransomware has the ability to use wmic.exe to spread to multiple endpoints within a compromised environment.

T1047
Windows Management Instrumentation
MalwareFIVEHANDS

FIVEHANDS can use WMI to delete files on a target machine.

T1047
Windows Management Instrumentation
MalwareHermeticWizard

HermeticWizard can use WMI to create a new process on a remote machine via `C:\windows\system32\cmd.exe /c start C:\windows\system32\\regsvr32.exe /s /iC:\windows\<filename>.dll`.

T1047
Windows Management Instrumentation
ToolCovenant

Covenant can utilize WMI to install new Grunt listeners through XSL files or command one-liners.

T1047
Windows Management Instrumentation
ToolSILENTTRINITY

SILENTTRINITY can use WMI for lateral movement.

T1047
Windows Management Instrumentation
ToolPowerSploit

PowerSploit's Invoke-WmiCommand CodeExecution module uses WMI to execute and retrieve the output from a PowerShell payload.

T1047
Windows Management Instrumentation
ToolImpacket

Impacket's `wmiexec` module can be used to execute commands through WMI.

T1047
Windows Management Instrumentation
ToolEmpire

Empire can use WMI to deliver a payload to a remote host.

T1047
Windows Management Instrumentation
ToolPoshC2

PoshC2 has a number of modules that use WMI to execute tasks.

T1047
Windows Management Instrumentation
ToolBrute Ratel C4

Brute Ratel C4 can use WMI to move laterally.

T1047
Windows Management Instrumentation
ToolCrackMapExec

CrackMapExec can execute remote commands using Windows Management Instrumentation.

T1047
Windows Management Instrumentation
ToolKoadic

Koadic can use WMI to execute commands.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.