WMIC Remote Command Execution (7773b877-5abb-4a3e-b9c9-fd0369b59b00)
Detects the execution of WMIC to query information on a remote system
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Windows Management Instrumentation - T1047 (01a5a209-b94c-450b-b7f9-946497d91055) | Attack Pattern | WMIC Remote Command Execution (7773b877-5abb-4a3e-b9c9-fd0369b59b00) | Sigma-Rules | 1 |