Service Started/Stopped Via Wmic.EXE (0b7163dc-7eee-4960-af17-c0cd517f92da)
Detects usage of wmic to start or stop a service
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Service Started/Stopped Via Wmic.EXE (0b7163dc-7eee-4960-af17-c0cd517f92da) | Sigma-Rules | Windows Management Instrumentation - T1047 (01a5a209-b94c-450b-b7f9-946497d91055) | Attack Pattern | 1 |