ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1047×

42 examples

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
GroupIndrik Spider

Indrik Spider has used WMIC to execute commands on remote computers.

T1047
Windows Management Instrumentation
GroupBlackByte

BlackByte used WMI to delete Volume Shadow Copies on victim machines.

T1047
Windows Management Instrumentation
GroupGALLIUM

GALLIUM used WMI for execution to assist in lateral movement as well as for installing tools across multiple assets.

T1047
Windows Management Instrumentation
GroupVolt Typhoon

Volt Typhoon has leveraged WMIC for execution, remote system discovery, and to create and use temporary directories.

T1047
Windows Management Instrumentation
GroupAPT41

APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit. APT41 has executed files through Windows Management Instrumentation (WMI).

T1047
Windows Management Instrumentation
GroupmenuPass

menuPass has used a modified version of pentesting script wmiexec.vbs, which logs into a remote machine using WMI.

T1047
Windows Management Instrumentation
GroupAPT32

APT32 used WMI to deploy their tools on remote machines and to gather information about the Outlook process.

T1047
Windows Management Instrumentation
GroupMuddyWater

MuddyWater has used malware that leveraged WMI for execution and querying host information.

T1047
Windows Management Instrumentation
GroupNaikon

Naikon has used WMIC.exe for lateral movement.

T1047
Windows Management Instrumentation
GroupFIN6

FIN6 has used WMI to automate the remote execution of PowerShell scripts.

T1047
Windows Management Instrumentation
GroupGamaredon Group

Gamaredon Group has used WMI to execute scripts used for discovery and for determining the C2 IP address. Gamaredon Group has used the following WMI query to search for a ping record: `Select * From Win32_PingStatus where Address = 'mil.gov.ua'`.

T1047
Windows Management Instrumentation
GroupFIN7

FIN7 has used WMI to install malware on targeted systems.

T1047
Windows Management Instrumentation
GroupSandworm Team

Sandworm Team has used Impacket’s WMIexec module for remote code execution and VBScript to run WMI queries.

T1047
Windows Management Instrumentation
GroupMustang Panda

Mustang Panda has executed PowerShell scripts via WMI.

T1047
Windows Management Instrumentation
GroupTA2541

TA2541 has used WMI to query targeted systems for security products.

T1047
Windows Management Instrumentation
GroupOilRig

OilRig has used WMI for execution.

T1047
Windows Management Instrumentation
GroupAquatic Panda

Aquatic Panda used WMI for lateral movement in victim environments.

T1047
Windows Management Instrumentation
GroupLeviathan

Leviathan has used WMI for execution.

T1047
Windows Management Instrumentation
GroupBlue Mockingbird

Blue Mockingbird has used wmic.exe to set environment variables.

T1047
Windows Management Instrumentation
GroupLotus Blossom

Lotus Blossom has used WMI to enable lateral movement.

T1047
Windows Management Instrumentation
GroupStealth Falcon

Stealth Falcon malware gathers system information via Windows Management Instrumentation (WMI).

T1047
Windows Management Instrumentation
GroupAPT29

APT29 used WMI to steal credentials and execute backdoors at a future time.

T1047
Windows Management Instrumentation
GroupCinnamon Tempest

Cinnamon Tempest has used Impacket for lateral movement via WMI.

T1047
Windows Management Instrumentation
GroupChimera

Chimera has used WMIC to execute remote commands.

T1047
Windows Management Instrumentation
GroupMirrorFace

MirrorFace has leveraged WMIC on targeted systems post compromise.

T1047
Windows Management Instrumentation
GroupMedusa Group

Medusa Group has utilized Windows Management Instrumentation to query system information.

T1047
Windows Management Instrumentation
GroupDeep Panda

The Deep Panda group is known to utilize WMI for lateral movement.

T1047
Windows Management Instrumentation
GroupEmber Bear

Ember Bear has used WMI execution with password hashes for command execution and lateral movement.

T1047
Windows Management Instrumentation
GroupWindshift

Windshift has used WMI to collect information about target machines.

T1047
Windows Management Instrumentation
GroupToddyCat

ToddyCat has used WMI to execute scripts for post exploit document collection.

T1047
Windows Management Instrumentation
GroupAPT42

APT42 has used Windows Management Instrumentation (WMI) to query anti-virus products.

T1047
Windows Management Instrumentation
GroupAPT-C-36

APT-C-36 has used WMI to execute PowerShell.

T1047
Windows Management Instrumentation
GroupLazarus Group

Lazarus Group has used WMIC for discovery as well as to execute payloads for persistence and lateral movement.

T1047
Windows Management Instrumentation
GroupINC Ransom

INC Ransom has used WMIC to deploy ransomware.

T1047
Windows Management Instrumentation
GroupEarth Lusca

Earth Lusca used a VBA script to execute WMI.

T1047
Windows Management Instrumentation
GroupWizard Spider

Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware.

T1047
Windows Management Instrumentation
GroupVelvet Ant

Velvet Ant used the `wmiexec.py` tool within Impacket for remote process execution via WMI.

T1047
Windows Management Instrumentation
GroupVOID MANTICORE

VOID MANTICORE has utilized WMIC to log into the victim host and create a process `process call create “cmd.exe /c copy \\?\\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\windows\system32\config\system c:\users\public”`.

T1047
Windows Management Instrumentation
GroupMagic Hound

Magic Hound has used a tool to run `cmd /c wmic computersystem get domain` for discovery.

T1047
Windows Management Instrumentation
GroupThreat Group-3390

A Threat Group-3390 tool can use WMI to execute a binary.

T1047
Windows Management Instrumentation
GroupFIN8

FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities.

T1047
Windows Management Instrumentation
GroupFIN13

FIN13 has utilized `WMI` to execute commands and move laterally on compromised Windows machines.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.