Hide Navigation Hide TOC Suspicious WmiPrvSE Child Process (8a582fe2-0882-4b89-a82a-da6b2dc32937) Detects suspicious and uncommon child processes of WmiPrvSE Cluster A Galaxy A Cluster B Galaxy B Level Suspicious WmiPrvSE Child Process (8a582fe2-0882-4b89-a82a-da6b2dc32937) Sigma-Rules Malicious File - T1204.002 (232b7f21-adf9-4b42-b936-b9d6f7df856e) Attack Pattern 1 Suspicious WmiPrvSE Child Process (8a582fe2-0882-4b89-a82a-da6b2dc32937) Sigma-Rules Regsvr32 - T1218.010 (b97f1d35-4249-4486-a6b5-ee60ccf24fab) Attack Pattern 1 Suspicious WmiPrvSE Child Process (8a582fe2-0882-4b89-a82a-da6b2dc32937) Sigma-Rules Windows Management Instrumentation - T1047 (01a5a209-b94c-450b-b7f9-946497d91055) Attack Pattern 1 User Execution - T1204 (8c32eb4d-805f-4fc5-bf60-c4d476c131b5) Attack Pattern Malicious File - T1204.002 (232b7f21-adf9-4b42-b936-b9d6f7df856e) Attack Pattern 2 System Binary Proxy Execution - T1218 (457c7820-d331-465a-915e-42f85500ccc4) Attack Pattern Regsvr32 - T1218.010 (b97f1d35-4249-4486-a6b5-ee60ccf24fab) Attack Pattern 2