T1047Windows Management Instrumentation
T1047 — Windows Management Instrumentation is a MITRE ATT&CK technique in the Execution tactic. Clankerusecase tracks 21 detection use cases covering it and 9 threat-intel articles citing it.
Execution
21Use cases
9Articles
0Sub-techniques
1Tactic
Use cases covering this technique (21)
Impacket Lateral Movement Commandline Parameters Impacket Lateral Movement smbexec CommandLine Parameters Impacket Lateral Movement WMIExec Commandline Parameters Possible Lateral Movement PowerShell Spawn PowerShell Invoke CIMMethod CIMSession PowerShell Invoke WmiExec Usage Process Execution via WMI Remote Process Instantiation via WMI Remote Process Instantiation via WMI and PowerShell Remote Process Instantiation via WMI and PowerShell Script Block Remote WMI Command Attempt Script Execution via WMI Windows WinRAR Launched Outside Default Installation Directory Windows WMI Impersonate Token Windows WMI Process And Service List Windows WMI Process Call Create Windows WMI Reconnaissance Class Query WMI Permanent Event Subscription WMI Temporary Event Subscription Wmiprvse LOLBAS Execution Process Spawn Wmiprsve LOLBAS Execution Process SpawnArticles citing this technique (9)
crit APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit art-48
crit Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers art-88