Technique.View on attack.mitre.org
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components.
The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as Distributed Component Object Model and Windows Remote Management. Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS.
An adversary can use WMI to interact with local and remote systems and use it as a means to execute various behaviors, such as gathering information for Discovery as well as Execution of commands and payloads. For example, `wmic.exe` can be abused by an adversary to delete shadow copies with the command `wmic.exe Shadowcopy Delete` (i.e., Inhibit System Recovery).
**Note:** `wmic.exe` is deprecated as of January of 2024, with the WMIC feature being “disabled by default” on Windows 11+. WMIC will be removed from subsequent Windows releases and replaced by PowerShell as the primary WMI interface. In addition to PowerShell and tools like `wbemtool.exe`, COM APIs can also be used to programmatically interact with WMI via C++, .NET, VBScript, etc.
Rules on DetectionCode tagged with T1047.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Impacket Lateral Movement Commandline Parameters | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Impacket Lateral Movement smbexec CommandLine Parameters | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Impacket Lateral Movement WMIExec Commandline Parameters | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Possible Lateral Movement PowerShell Spawn | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| PowerShell Invoke CIMMethod CIMSession | Anomaly | NULL | Powershell Script Block Logging 4104 |
| PowerShell Invoke WmiExec Usage | TTP | NULL | Powershell Script Block Logging 4104 |
| Process Execution via WMI | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Remote Process Instantiation via WMI | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Remote Process Instantiation via WMI and PowerShell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Remote Process Instantiation via WMI and PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 |
| Remote WMI Command Attempt | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Script Execution via WMI | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows WinRAR Launched Outside Default Installation Directory | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows WMI Impersonate Token | Anomaly | NULL | Sysmon EventID 10 |
| Windows WMI Process And Service List | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows WMI Process Call Create | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows WMI Reconnaissance Class Query | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| WMI Permanent Event Subscription | TTP | NULL | |
| WMI Temporary Event Subscription | TTP | NULL | |
| Wmiprsve LOLBAS Execution Process Spawn | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Wmiprvse LOLBAS Execution Process Spawn | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAPT-C-36 | APT-C-36 has used WMI to execute PowerShell. |
| GroupAPT29 | APT29 used WMI to steal credentials and execute backdoors at a future time. |
| GroupAPT32 | APT32 used WMI to deploy their tools on remote machines and to gather information about the Outlook process. |
| GroupAPT41 | APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit. APT41 has executed files through Windows Management Instrumentation (WMI). |
| GroupAPT42 | APT42 has used Windows Management Instrumentation (WMI) to query anti-virus products. |
| GroupAquatic Panda | Aquatic Panda used WMI for lateral movement in victim environments. |
| GroupBlackByte | BlackByte used WMI to delete Volume Shadow Copies on victim machines. |
| GroupBlue Mockingbird | Blue Mockingbird has used wmic.exe to set environment variables. |
| Used by | Procedure example |
|---|---|
| MalwareAction RAT | Action RAT can use WMI to gather AV products installed on an infected host. |
| MalwareAgent Tesla | Agent Tesla has used wmi queries to gather information from the system. |
| MalwareAkira | Akira will leverage COM objects accessed through WMI during execution to evade detection. |
| MalwareAshTag | AshTag can use a .NET program to execute WMI queries and send unique victim IDs to C2. |
| MalwareAstaroth | Astaroth uses WMIC to execute payloads. |
| MalwareAvaddon | Avaddon uses wmic.exe to delete shadow copies. |
| MalwareBADHATCH | BADHATCH can utilize WMI to collect system information, create new processes, and run malicious PowerShell scripts on a compromised machine. |
| MalwareBazar | Bazar can execute a WMI query to gather information about the installed antivirus engine. |
| Used by | Procedure example |
|---|---|
| Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, WMI in scripts were used for remote execution and system surveys. |
| CampaignC0015 | During C0015, the threat actors used `wmic` and `rundll32` to load Cobalt Strike onto a target host. |
| CampaignC0018 | During C0018, the threat actors used WMIC to modify administrative settings on both a local and a remote host, likely as part of the first stages for their lateral movement; they also used WMI Provider Host (`wmiprvse.exe`) to execute a variety of encoded PowerShell scripts using the `DownloadString` method. |
| CampaignC0027 | During C0027, Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket. |
| CampaignFrankenstein | During Frankenstein, the threat actors used WMI queries to check if various security applications were running as well as to determine the operating system version. |
| CampaignFunnyDream | During FunnyDream, the threat actors used `wmiexec.vbs` to run remote commands. |
| CampaignHomeLand Justice | During HomeLand Justice, threat actors used WMI to modify Windows Defender settings. |
| CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used WMI to proxy execution of UPPERCUT. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.