Windows Management Instrumentation

T1047

Technique.View on attack.mitre.org

About this technique

Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components.

The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as Distributed Component Object Model and Windows Remote Management. Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS.

An adversary can use WMI to interact with local and remote systems and use it as a means to execute various behaviors, such as gathering information for Discovery as well as Execution of commands and payloads. For example, `wmic.exe` can be abused by an adversary to delete shadow copies with the command `wmic.exe Shadowcopy Delete` (i.e., Inhibit System Recovery).

**Note:** `wmic.exe` is deprecated as of January of 2024, with the WMIC feature being “disabled by default” on Windows 11+. WMIC will be removed from subsequent Windows releases and replaced by PowerShell as the primary WMI interface. In addition to PowerShell and tools like `wbemtool.exe`, COM APIs can also be used to programmatically interact with WMI via C++, .NET, VBScript, etc.

Detection rules69

Rules on DetectionCode tagged with T1047.

Sigma48

RuleLevelLog source
Wmiexec Default Output Filecriticalwindows / file_event
Wmiprvse Wbemcomn DLL Hijack - Filecriticalwindows / file_event
Blue Mockingbird - Registryhighwindows / registry_set
HackTool - CrackMapExec Executionhighwindows / process_creation
HackTool - CrackMapExec Execution Patternshighwindows / process_creation
HackTool - Potential Impacket Lateral Movement Activityhighwindows / process_creation
HTML Help HH.EXE Suspicious Child Processhighwindows / process_creation
Potential Remote SquiblyTwo Technique Executionhighwindows / process_creation
Potential Windows Defender Tampering Via Wmic.EXEhighwindows / process_creation
PSExec and WMI Process Creations Blockhighwindows / NULL
Remote DCOM/WMI Lateral Movementhighrpc_firewall / application
Script Event Consumer Spawning Processhighwindows / process_creation
Suspicious Autorun Registry Modified via WMIhighwindows / process_creation
Suspicious Encoded Scripts in a WMI Consumerhighwindows / wmi_event
Suspicious HH.EXE Executionhighwindows / process_creation

Splunk21

RuleTypeRiskData source
Impacket Lateral Movement Commandline ParametersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Impacket Lateral Movement smbexec CommandLine ParametersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Impacket Lateral Movement WMIExec Commandline ParametersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Possible Lateral Movement PowerShell SpawnAnomalyNULLSysmon EventID 1, CrowdStrike ProcessRollup2
PowerShell Invoke CIMMethod CIMSessionAnomalyNULLPowershell Script Block Logging 4104
PowerShell Invoke WmiExec UsageTTPNULLPowershell Script Block Logging 4104
Process Execution via WMITTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Remote Process Instantiation via WMITTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Remote Process Instantiation via WMI and PowerShellTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Remote Process Instantiation via WMI and PowerShell Script BlockTTPNULLPowershell Script Block Logging 4104
Remote WMI Command AttemptTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Script Execution via WMITTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows WinRAR Launched Outside Default Installation DirectoryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows WMI Impersonate TokenAnomalyNULLSysmon EventID 10
Windows WMI Process And Service ListAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups42

Show 18 more

Software93

Show 69 more

Campaigns12

Procedure examples147

Groups42

Used byProcedure example
GroupAPT-C-36

APT-C-36 has used WMI to execute PowerShell.

GroupAPT29

APT29 used WMI to steal credentials and execute backdoors at a future time.

GroupAPT32

APT32 used WMI to deploy their tools on remote machines and to gather information about the Outlook process.

GroupAPT41

APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit. APT41 has executed files through Windows Management Instrumentation (WMI).

GroupAPT42

APT42 has used Windows Management Instrumentation (WMI) to query anti-virus products.

GroupAquatic Panda

Aquatic Panda used WMI for lateral movement in victim environments.

GroupBlackByte

BlackByte used WMI to delete Volume Shadow Copies on victim machines.

GroupBlue Mockingbird

Blue Mockingbird has used wmic.exe to set environment variables.

View all 42 groups examples

Software93

Used byProcedure example
MalwareAction RAT

Action RAT can use WMI to gather AV products installed on an infected host.

MalwareAgent Tesla

Agent Tesla has used wmi queries to gather information from the system.

MalwareAkira

Akira will leverage COM objects accessed through WMI during execution to evade detection.

MalwareAshTag

AshTag can use a .NET program to execute WMI queries and send unique victim IDs to C2.

MalwareAstaroth

Astaroth uses WMIC to execute payloads.

MalwareAvaddon

Avaddon uses wmic.exe to delete shadow copies.

MalwareBADHATCH

BADHATCH can utilize WMI to collect system information, create new processes, and run malicious PowerShell scripts on a compromised machine.

MalwareBazar

Bazar can execute a WMI query to gather information about the installed antivirus engine.

View all 93 software examples

Campaigns12

Used byProcedure example
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, WMI in scripts were used for remote execution and system surveys.

CampaignC0015

During C0015, the threat actors used `wmic` and `rundll32` to load Cobalt Strike onto a target host.

CampaignC0018

During C0018, the threat actors used WMIC to modify administrative settings on both a local and a remote host, likely as part of the first stages for their lateral movement; they also used WMI Provider Host (`wmiprvse.exe`) to execute a variety of encoded PowerShell scripts using the `DownloadString` method.

CampaignC0027

During C0027, Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.

CampaignFrankenstein

During Frankenstein, the threat actors used WMI queries to check if various security applications were running as well as to determine the operating system version.

CampaignFunnyDream

During FunnyDream, the threat actors used `wmiexec.vbs` to run remote commands.

CampaignHomeLand Justice

During HomeLand Justice, threat actors used WMI to modify Windows Defender settings.

CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used WMI to proxy execution of UPPERCUT.

View all 12 campaigns examples

References4

  1. Mandiant WMI Open source
    Mandiant. (n.d.). Retrieved February 13, 2024.
  2. WMI 1-3 Open source
    Microsoft. (2023, March 7). Retrieved February 13, 2024.
  3. WMI 6 Open source
    Microsoft. (2022, June 13). BlackCat. Retrieved February 13, 2024.
  4. WMI 7,8 Open source
    Microsoft. (2024, January 26). WMIC Deprecation. Retrieved February 13, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.