ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1047×

12 examples

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group used WMIC to executed a remote XSL script.

T1047
Windows Management Instrumentation
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors used WMI for execution.

T1047
Windows Management Instrumentation
CampaignFrankenstein

During Frankenstein, the threat actors used WMI queries to check if various security applications were running as well as to determine the operating system version.

T1047
Windows Management Instrumentation
CampaignC0018

During C0018, the threat actors used WMIC to modify administrative settings on both a local and a remote host, likely as part of the first stages for their lateral movement; they also used WMI Provider Host (`wmiprvse.exe`) to execute a variety of encoded PowerShell scripts using the `DownloadString` method.

T1047
Windows Management Instrumentation
CampaignC0015

During C0015, the threat actors used `wmic` and `rundll32` to load Cobalt Strike onto a target host.

T1047
Windows Management Instrumentation
CampaignHomeLand Justice

During HomeLand Justice, threat actors used WMI to modify Windows Defender settings.

T1047
Windows Management Instrumentation
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used WMI for the remote execution of files for lateral movement.

T1047
Windows Management Instrumentation
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used WMI to proxy execution of UPPERCUT.

T1047
Windows Management Instrumentation
CampaignFunnyDream

During FunnyDream, the threat actors used `wmiexec.vbs` to run remote commands.

T1047
Windows Management Instrumentation
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, WMI in scripts were used for remote execution and system surveys.

T1047
Windows Management Instrumentation
CampaignOperation Wocao

During Operation Wocao, threat actors has used WMI to execute commands.

T1047
Windows Management Instrumentation
CampaignC0027

During C0027, Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.