Detection: selection_img: Image|endswith:'\WMIC.exe'OriginalFileName:'wmic.exe'selection_cli: CommandLine|contains|all: -' service ' -'ChangeStartMode'
CommandLine|contains: -'Manual' -'Disabled'
condition:all of selection_* Falsepositives:
-Legitimate administrative changes to service startup types using WMIC, investigate accordingly. Level:medium