Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
GroupAPT29 | APT29 used WMI to steal credentials and execute backdoors at a future time. |
| T1047 Windows Management Instrumentation |
GroupCinnamon Tempest | Cinnamon Tempest has used Impacket for lateral movement via WMI. |
| T1047 Windows Management Instrumentation |
GroupChimera | Chimera has used WMIC to execute remote commands. |
| T1047 Windows Management Instrumentation |
GroupMirrorFace | MirrorFace has leveraged WMIC on targeted systems post compromise. |
| T1047 Windows Management Instrumentation |
GroupMedusa Group | Medusa Group has utilized Windows Management Instrumentation to query system information. |
| T1047 Windows Management Instrumentation |
GroupDeep Panda | The Deep Panda group is known to utilize WMI for lateral movement. |
| T1047 Windows Management Instrumentation |
GroupEmber Bear | Ember Bear has used WMI execution with password hashes for command execution and lateral movement. |
| T1047 Windows Management Instrumentation |
GroupWindshift | Windshift has used WMI to collect information about target machines. |
| T1047 Windows Management Instrumentation |
GroupToddyCat | ToddyCat has used WMI to execute scripts for post exploit document collection. |
| T1047 Windows Management Instrumentation |
GroupAPT42 | APT42 has used Windows Management Instrumentation (WMI) to query anti-virus products. |
| T1047 Windows Management Instrumentation |
GroupAPT-C-36 | APT-C-36 has used WMI to execute PowerShell. |
| T1047 Windows Management Instrumentation |
GroupLazarus Group | Lazarus Group has used WMIC for discovery as well as to execute payloads for persistence and lateral movement. |
| T1047 Windows Management Instrumentation |
GroupINC Ransom | INC Ransom has used WMIC to deploy ransomware. |
| T1047 Windows Management Instrumentation |
GroupEarth Lusca | Earth Lusca used a VBA script to execute WMI. |
| T1047 Windows Management Instrumentation |
GroupWizard Spider | Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware. |
| T1047 Windows Management Instrumentation |
GroupVelvet Ant | Velvet Ant used the `wmiexec.py` tool within Impacket for remote process execution via WMI. |
| T1047 Windows Management Instrumentation |
GroupVOID MANTICORE | VOID MANTICORE has utilized WMIC to log into the victim host and create a process `process call create “cmd.exe /c copy \\?\\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\windows\system32\config\system c:\users\public”`. |
| T1047 Windows Management Instrumentation |
GroupMagic Hound | Magic Hound has used a tool to run `cmd /c wmic computersystem get domain` for discovery. |
| T1047 Windows Management Instrumentation |
GroupThreat Group-3390 | A Threat Group-3390 tool can use WMI to execute a binary. |
| T1047 Windows Management Instrumentation |
GroupFIN8 | FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities. |
| T1047 Windows Management Instrumentation |
GroupFIN13 | FIN13 has utilized `WMI` to execute commands and move laterally on compromised Windows machines. |
| T1047 Windows Management Instrumentation |
MalwareEKANS | EKANS can use Windows Mangement Instrumentation (WMI) calls to execute operations. |
| T1047 Windows Management Instrumentation |
MalwareBumblebee | Bumblebee can use WMI to gather system information and to spawn processes for code injection. |
| T1047 Windows Management Instrumentation |
MalwareStuxnet | Stuxnet used WMI with an |
| T1047 Windows Management Instrumentation |
MalwarePOWRUNER | POWRUNER may use WMI when collecting information about a victim. |
| T1047 Windows Management Instrumentation |
MalwareSharpStage | SharpStage can use WMI for execution. |
| T1047 Windows Management Instrumentation |
MalwareSardonic | Sardonic can use WMI to execute PowerShell commands on a compromised machine. |
| T1047 Windows Management Instrumentation |
MalwareHALFBAKED | HALFBAKED can use WMI queries to gather system information. |
| T1047 Windows Management Instrumentation |
MalwareTAMECAT | TAMECAT has used Windows Management Instrumentation (WMI) to query anti-virus products. |
| T1047 Windows Management Instrumentation |
MalwareUrsnif | Ursnif droppers have used WMI classes to execute PowerShell commands. |
| T1047 Windows Management Instrumentation |
MalwareGravityRAT | GravityRAT collects various information via WMI requests, including CPU information in the Win32_Processor entry (Processor ID, Name, Manufacturer and the clock speed). |
| T1047 Windows Management Instrumentation |
MalwareROAMINGHOUSE | ROAMINGHOUSE can use WMI to launch a legitimate executable later used to enable DLL sideloading. |
| T1047 Windows Management Instrumentation |
MalwareTONESHELL | TONESHELL has used WMI queries to gather information from the system. |
| T1047 Windows Management Instrumentation |
MalwarePyDCrypt | PyDCrypt has attempted to execute with WMIC. |
| T1047 Windows Management Instrumentation |
MalwareIMAPLoader | IMAPLoader uses WMI queries to query system information on victim hosts. |
| T1047 Windows Management Instrumentation |
MalwareEmotet | Emotet has used WMI to execute powershell.exe. |
| T1047 Windows Management Instrumentation |
MalwareOlympic Destroyer | Olympic Destroyer uses WMI to help propagate itself across a network. |
| T1047 Windows Management Instrumentation |
MalwareBADHATCH | BADHATCH can utilize WMI to collect system information, create new processes, and run malicious PowerShell scripts on a compromised machine. |
| T1047 Windows Management Instrumentation |
MalwareAction RAT | Action RAT can use WMI to gather AV products installed on an infected host. |
| T1047 Windows Management Instrumentation |
MalwarePUBLOAD | PUBLOAD has used `wmic` to gather information from the victim device. |
| T1047 Windows Management Instrumentation |
MalwareShrinkLocker | ShrinkLocker uses WMI to query information about the victim operating system. |
| T1047 Windows Management Instrumentation |
MalwareFlawedAmmyy | FlawedAmmyy leverages WMI to enumerate anti-virus on the victim. |
| T1047 Windows Management Instrumentation |
MalwareSnip3 | Snip3 can query the WMI class `Win32_ComputerSystem` to gather information. |
| T1047 Windows Management Instrumentation |
MalwareHOPLIGHT | HOPLIGHT has used WMI to recompile the Managed Object Format (MOF) files in the WMI repository. |
| T1047 Windows Management Instrumentation |
MalwareProLock | ProLock can use WMIC to execute scripts on targeted hosts. |
| T1047 Windows Management Instrumentation |
MalwareRaspberry Robin | Raspberry Robin can execute via LNK containing a command to run a legitimate executable, such as wmic.exe, to download a malicious Windows Installer (MSI) package. |
| T1047 Windows Management Instrumentation |
MalwareBlackCat | BlackCat can use `wmic.exe` to delete shadow copies on compromised networks. |
| T1047 Windows Management Instrumentation |
MalwareIcedID | IcedID has used WMI to execute binaries. |
| T1047 Windows Management Instrumentation |
MalwareKazuar | Kazuar obtains a list of running processes through WMI querying. |
| T1047 Windows Management Instrumentation |
MalwareLucifer | Lucifer can use WMI to log into remote machines for propagation. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.