This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Potential Tampering With Security Products Via WMIC
Original Source:
[Sigma source]
Title:
Potential Tampering With Security Products Via WMIC
Status:
test
Description:
Detects uninstallation or termination of security products using the WMIC utility
References:
-https://twitter.com/cglyer/status/1355171195654709249
-https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/
-https://www.mandiant.com/resources/unc2165-shifts-to-evade-sanctions
-https://research.nccgroup.com/2022/08/19/back-in-black-unlocking-a-lockbit-3-0-ransomware-attack/
-https://www.trendmicro.com/en_us/research/23/a/vice-society-ransomware-group-targets-manufacturing-companies.html
Author:
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date:
2021-01-30
modified:
2025-12-15
Tags:
-'attack.defense-impairment'
-'attack.t1685'
Logsource:
category: process_creation
product: windows
Detection:
selection_cli_1:
CommandLine|contains|all
:
-'wmic'
-'product '
-'uninstall'
CommandLine|contains|windash
:
'/nointeractive'
selection_cli_2:
CommandLine|contains|all
:
-'wmic'
-'caption like '
CommandLine|contains
:
-'call delete'
-'call terminate'
selection_cli_3:
CommandLine|contains|all
:
-'process '
-'where '
-'delete'
selection_product:
CommandLine|contains
:
-'%carbon%'
-'%cylance%'
-'%endpoint%'
-'%eset%'
-'%malware%'
-'%Sophos%'
-'%symantec%'
-'Antivirus'
-'AVG '
-'Carbon Black'
-'CarbonBlack'
-'Cb Defense Sensor 64-bit'
-'Crowdstrike Sensor'
-'Cylance '
-'Dell Threat Defense'
-'DLP Endpoint'
-'Endpoint Detection'
-'Endpoint Protection'
-'Endpoint Security'
-'Endpoint Sensor'
-'ESET File Security'
-'LogRhythm System Monitor Service'
-'Malwarebytes'
-'McAfee Agent'
-'Microsoft Security Client'
-'Sophos Anti-Virus'
-'Sophos AutoUpdate'
-'Sophos Credential Store'
-'Sophos Management Console'
-'Sophos Management Database'
-'Sophos Management Server'
-'Sophos Remote Management System'
-'Sophos Update Manager'
-'Threat Protection'
-'VirusScan'
-'Webroot SecureAnywhere'
-'Windows Defender'
condition
:
1 of selection_cli_* and selection_product
Falsepositives:
-Legitimate administration
Level:
high