Computer System Reconnaissance Via Wmic.EXE

 Original Source: [Sigma source]
Title: Computer System Reconnaissance Via Wmic.EXE
Status: test
Description:Detects execution of wmic utility with the "computersystem" flag in order to obtain information about the machine such as the domain, username, model, etc.
References:
  -https://www.microsoft.com/security/blog/2022/09/07/profiling-dev-0270-phosphorus-ransomware-operations/
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-09-08
modified:2023-02-14
Tags:
  • -'attack.discovery'
  • -'attack.execution'
  • -'attack.t1047'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_img:
Image|endswith:'\wmic.exe' OriginalFileName:'wmic.exe'   selection_cli:
    CommandLine|contains: 'computersystem'
  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium