Application Terminated Via Wmic.EXE (49d9671b-0a0a-4c09-8280-d215bfd30662)
Detects calls to the "terminate" function via wmic in order to kill an application
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Windows Management Instrumentation - T1047 (01a5a209-b94c-450b-b7f9-946497d91055) | Attack Pattern | Application Terminated Via Wmic.EXE (49d9671b-0a0a-4c09-8280-d215bfd30662) | Sigma-Rules | 1 |