ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
GroupAPT29

APT29 used WMI to steal credentials and execute backdoors at a future time.

T1047
Windows Management Instrumentation
GroupCinnamon Tempest

Cinnamon Tempest has used Impacket for lateral movement via WMI.

T1047
Windows Management Instrumentation
GroupChimera

Chimera has used WMIC to execute remote commands.

T1047
Windows Management Instrumentation
GroupMirrorFace

MirrorFace has leveraged WMIC on targeted systems post compromise.

T1047
Windows Management Instrumentation
GroupMedusa Group

Medusa Group has utilized Windows Management Instrumentation to query system information.

T1047
Windows Management Instrumentation
GroupDeep Panda

The Deep Panda group is known to utilize WMI for lateral movement.

T1047
Windows Management Instrumentation
GroupEmber Bear

Ember Bear has used WMI execution with password hashes for command execution and lateral movement.

T1047
Windows Management Instrumentation
GroupWindshift

Windshift has used WMI to collect information about target machines.

T1047
Windows Management Instrumentation
GroupToddyCat

ToddyCat has used WMI to execute scripts for post exploit document collection.

T1047
Windows Management Instrumentation
GroupAPT42

APT42 has used Windows Management Instrumentation (WMI) to query anti-virus products.

T1047
Windows Management Instrumentation
GroupAPT-C-36

APT-C-36 has used WMI to execute PowerShell.

T1047
Windows Management Instrumentation
GroupLazarus Group

Lazarus Group has used WMIC for discovery as well as to execute payloads for persistence and lateral movement.

T1047
Windows Management Instrumentation
GroupINC Ransom

INC Ransom has used WMIC to deploy ransomware.

T1047
Windows Management Instrumentation
GroupEarth Lusca

Earth Lusca used a VBA script to execute WMI.

T1047
Windows Management Instrumentation
GroupWizard Spider

Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware.

T1047
Windows Management Instrumentation
GroupVelvet Ant

Velvet Ant used the `wmiexec.py` tool within Impacket for remote process execution via WMI.

T1047
Windows Management Instrumentation
GroupVOID MANTICORE

VOID MANTICORE has utilized WMIC to log into the victim host and create a process `process call create “cmd.exe /c copy \\?\\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\windows\system32\config\system c:\users\public”`.

T1047
Windows Management Instrumentation
GroupMagic Hound

Magic Hound has used a tool to run `cmd /c wmic computersystem get domain` for discovery.

T1047
Windows Management Instrumentation
GroupThreat Group-3390

A Threat Group-3390 tool can use WMI to execute a binary.

T1047
Windows Management Instrumentation
GroupFIN8

FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities.

T1047
Windows Management Instrumentation
GroupFIN13

FIN13 has utilized `WMI` to execute commands and move laterally on compromised Windows machines.

T1047
Windows Management Instrumentation
MalwareEKANS

EKANS can use Windows Mangement Instrumentation (WMI) calls to execute operations.

T1047
Windows Management Instrumentation
MalwareBumblebee

Bumblebee can use WMI to gather system information and to spawn processes for code injection.

T1047
Windows Management Instrumentation
MalwareStuxnet

Stuxnet used WMI with an explorer.exe token to execute on a remote share.

T1047
Windows Management Instrumentation
MalwarePOWRUNER

POWRUNER may use WMI when collecting information about a victim.

T1047
Windows Management Instrumentation
MalwareSharpStage

SharpStage can use WMI for execution.

T1047
Windows Management Instrumentation
MalwareSardonic

Sardonic can use WMI to execute PowerShell commands on a compromised machine.

T1047
Windows Management Instrumentation
MalwareHALFBAKED

HALFBAKED can use WMI queries to gather system information.

T1047
Windows Management Instrumentation
MalwareTAMECAT

TAMECAT has used Windows Management Instrumentation (WMI) to query anti-virus products.

T1047
Windows Management Instrumentation
MalwareUrsnif

Ursnif droppers have used WMI classes to execute PowerShell commands.

T1047
Windows Management Instrumentation
MalwareGravityRAT

GravityRAT collects various information via WMI requests, including CPU information in the Win32_Processor entry (Processor ID, Name, Manufacturer and the clock speed).

T1047
Windows Management Instrumentation
MalwareROAMINGHOUSE

ROAMINGHOUSE can use WMI to launch a legitimate executable later used to enable DLL sideloading.

T1047
Windows Management Instrumentation
MalwareTONESHELL

TONESHELL has used WMI queries to gather information from the system.

T1047
Windows Management Instrumentation
MalwarePyDCrypt

PyDCrypt has attempted to execute with WMIC.

T1047
Windows Management Instrumentation
MalwareIMAPLoader

IMAPLoader uses WMI queries to query system information on victim hosts.

T1047
Windows Management Instrumentation
MalwareEmotet

Emotet has used WMI to execute powershell.exe.

T1047
Windows Management Instrumentation
MalwareOlympic Destroyer

Olympic Destroyer uses WMI to help propagate itself across a network.

T1047
Windows Management Instrumentation
MalwareBADHATCH

BADHATCH can utilize WMI to collect system information, create new processes, and run malicious PowerShell scripts on a compromised machine.

T1047
Windows Management Instrumentation
MalwareAction RAT

Action RAT can use WMI to gather AV products installed on an infected host.

T1047
Windows Management Instrumentation
MalwarePUBLOAD

PUBLOAD has used `wmic` to gather information from the victim device.

T1047
Windows Management Instrumentation
MalwareShrinkLocker

ShrinkLocker uses WMI to query information about the victim operating system.

T1047
Windows Management Instrumentation
MalwareFlawedAmmyy

FlawedAmmyy leverages WMI to enumerate anti-virus on the victim.

T1047
Windows Management Instrumentation
MalwareSnip3

Snip3 can query the WMI class `Win32_ComputerSystem` to gather information.

T1047
Windows Management Instrumentation
MalwareHOPLIGHT

HOPLIGHT has used WMI to recompile the Managed Object Format (MOF) files in the WMI repository.

T1047
Windows Management Instrumentation
MalwareProLock

ProLock can use WMIC to execute scripts on targeted hosts.

T1047
Windows Management Instrumentation
MalwareRaspberry Robin

Raspberry Robin can execute via LNK containing a command to run a legitimate executable, such as wmic.exe, to download a malicious Windows Installer (MSI) package.

T1047
Windows Management Instrumentation
MalwareBlackCat

BlackCat can use `wmic.exe` to delete shadow copies on compromised networks.

T1047
Windows Management Instrumentation
MalwareIcedID

IcedID has used WMI to execute binaries.

T1047
Windows Management Instrumentation
MalwareKazuar

Kazuar obtains a list of running processes through WMI querying.

T1047
Windows Management Instrumentation
MalwareLucifer

Lucifer can use WMI to log into remote machines for propagation.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.