Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareLucifer | Lucifer can use WMI to log into remote machines for propagation. |
| T1047 Windows Management Instrumentation |
MalwareBlackEnergy | A BlackEnergy 2 plug-in uses WMI to gather victim host details. |
| T1047 Windows Management Instrumentation |
MalwareNotPetya | NotPetya can use |
| T1047 Windows Management Instrumentation |
MalwareAvaddon | Avaddon uses wmic.exe to delete shadow copies. |
| T1047 Windows Management Instrumentation |
MalwareSocGholish | SocGholish has used WMI calls for script execution and system profiling. |
| T1047 Windows Management Instrumentation |
MalwareHELLOKITTY | HELLOKITTY can use WMI to delete volume shadow copies. |
| T1047 Windows Management Instrumentation |
MalwareDarkTortilla | DarkTortilla can use WMI queries to obtain system information. |
| T1047 Windows Management Instrumentation |
MalwareDarkWatchman | DarkWatchman can use WMI to execute commands. |
| T1047 Windows Management Instrumentation |
MalwareDustySky | The DustySky dropper uses Windows Management Instrumentation to extract information about the operating system and whether an anti-virus is active. |
| T1047 Windows Management Instrumentation |
MalwareDEATHRANSOM | DEATHRANSOM has the ability to use WMI to delete volume shadow copies. |
| T1047 Windows Management Instrumentation |
MalwareAkira | Akira will leverage COM objects accessed through WMI during execution to evade detection. |
| T1047 Windows Management Instrumentation |
MalwareDarkGate | DarkGate has used WMI to execute files over the network and to obtain information about the domain. |
| T1047 Windows Management Instrumentation |
MalwareSVCReady | SVCReady can use `WMI` queries to detect the presence of a virtual machine environment. |
| T1047 Windows Management Instrumentation |
MalwareNetwalker | Netwalker can use WMI to delete Shadow Volumes. |
| T1047 Windows Management Instrumentation |
MalwareWannaCry | WannaCry utilizes |
| T1047 Windows Management Instrumentation |
MalwareLatrodectus | Latrodectus has used WMI in malicious email infection chains to facilitate the installation of remotely-hosted files. |
| T1047 Windows Management Instrumentation |
MalwareLODEINFO | LODEINFO can execute commands with WMI. |
| T1047 Windows Management Instrumentation |
MalwareCharmPower | CharmPower can use `wmic` to gather information from a system. |
| T1047 Windows Management Instrumentation |
MalwareEVILNUM | EVILNUM has used the Windows Management Instrumentation (WMI) tool to enumerate infected machines. |
| T1047 Windows Management Instrumentation |
MalwareKOMPROGO | KOMPROGO is capable of running WMI queries. |
| T1047 Windows Management Instrumentation |
MalwareMoleNet | MoleNet can perform WMI commands on the system. |
| T1047 Windows Management Instrumentation |
MalwareMicropsia | Micropsia searches for anti-virus software and firewall products installed on the victim’s machine using WMI. |
| T1047 Windows Management Instrumentation |
MalwareBlack Basta | Black Basta has used WMI to execute files over the network. |
| T1047 Windows Management Instrumentation |
MalwareStoneDrill | StoneDrill has used the WMI command-line (WMIC) utility to run tasks. |
| T1047 Windows Management Instrumentation |
MalwareOopsIE | OopsIE uses WMI to perform discovery techniques. |
| T1047 Windows Management Instrumentation |
MalwareRogueRobin | RogueRobin uses various WMI queries to check if the sample is running in a sandbox. |
| T1047 Windows Management Instrumentation |
MalwareMosquito | Mosquito's installer uses WMI to search for antivirus display names. |
| T1047 Windows Management Instrumentation |
MalwareSibot | Sibot has used WMI to discover network connections and configurations. Sibot has also used the Win32_Process class to execute a malicious DLL. |
| T1047 Windows Management Instrumentation |
MalwareBazar | Bazar can execute a WMI query to gather information about the installed antivirus engine. |
| T1047 Windows Management Instrumentation |
MalwareRATANKBA | RATANKBA uses WMI to perform process monitoring. |
| T1047 Windows Management Instrumentation |
MalwareLockBit 2.0 | LockBit 2.0 can use wmic.exe to delete volume shadow copies. |
| T1047 Windows Management Instrumentation |
MalwareZebrocy | One variant of Zebrocy uses WMI queries to gather information. |
| T1047 Windows Management Instrumentation |
MalwareCobalt Strike | Cobalt Strike can use WMI to deliver a payload to a remote host. |
| T1047 Windows Management Instrumentation |
MalwareSUNBURST | SUNBURST used the WMI query |
| T1047 Windows Management Instrumentation |
MalwareEvilBunny | EvilBunny has used WMI to gather information about the system. |
| T1047 Windows Management Instrumentation |
MalwareREvil | REvil can use WMI to monitor for and kill specific processes listed in its configuration file. |
| T1047 Windows Management Instrumentation |
MalwareValak | Valak can use |
| T1047 Windows Management Instrumentation |
MalwareAshTag | AshTag can use a .NET program to execute WMI queries and send unique victim IDs to C2. |
| T1047 Windows Management Instrumentation |
MalwareFunnyDream | FunnyDream can use WMI to open a Windows command shell on a remote machine. |
| T1047 Windows Management Instrumentation |
MalwareSysUpdate | SysUpdate can use WMI for execution on a compromised host. |
| T1047 Windows Management Instrumentation |
MalwareLAMEHUG | LAMEHUG can use wmic to collect system information. |
| T1047 Windows Management Instrumentation |
MalwareFELIXROOT | FELIXROOT uses WMI to query the Windows Registry. |
| T1047 Windows Management Instrumentation |
MalwareMeteor | Meteor can use `wmic.exe` as part of its effort to delete shadow copies. |
| T1047 Windows Management Instrumentation |
MalwareMaze | Maze has used WMI to attempt to delete the shadow volumes on a machine, and to connect a virtual machine to the network domain of the victim organization's network. |
| T1047 Windows Management Instrumentation |
MalwareLunarWeb | LunarWeb can use WMI queries for discovery on the victim host. |
| T1047 Windows Management Instrumentation |
MalwareOctopus | Octopus has used wmic.exe for local discovery information. |
| T1047 Windows Management Instrumentation |
MalwareQilin | Qilin can use WMIC to change the Volume Shadow Copy Service (VSS) startup type to manual. |
| T1047 Windows Management Instrumentation |
MalwareAgent Tesla | Agent Tesla has used wmi queries to gather information from the system. |
| T1047 Windows Management Instrumentation |
MalwarePOWERSTATS | POWERSTATS can use WMI queries to retrieve data from compromised hosts. |
| T1047 Windows Management Instrumentation |
MalwareRemexi | Remexi executes received commands with wmic.exe (for WMI commands). |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.