New Process Created Via Wmic.EXE (526be59f-a573-4eea-b5f7-f0973207634d)
Detects new process creation using WMIC via the "process call create" flag
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
New Process Created Via Wmic.EXE (526be59f-a573-4eea-b5f7-f0973207634d) | Sigma-Rules | Windows Management Instrumentation - T1047 (01a5a209-b94c-450b-b7f9-946497d91055) | Attack Pattern | 1 |