Potential Product Reconnaissance Via Wmic.EXE (15434e33-5027-4914-88d5-3d4145ec25a9)
Detects the execution of WMIC in order to get a list of firewall and antivirus products
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Potential Product Reconnaissance Via Wmic.EXE (15434e33-5027-4914-88d5-3d4145ec25a9) | Sigma-Rules | Windows Management Instrumentation - T1047 (01a5a209-b94c-450b-b7f9-946497d91055) | Attack Pattern | 1 |