Real-world descriptions of how a group, tool or campaign used a technique.
12 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group used WMIC to executed a remote XSL script. |
| T1047 Windows Management Instrumentation |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used WMI for execution. |
| T1047 Windows Management Instrumentation |
CampaignFrankenstein | During Frankenstein, the threat actors used WMI queries to check if various security applications were running as well as to determine the operating system version. |
| T1047 Windows Management Instrumentation |
CampaignC0018 | During C0018, the threat actors used WMIC to modify administrative settings on both a local and a remote host, likely as part of the first stages for their lateral movement; they also used WMI Provider Host (`wmiprvse.exe`) to execute a variety of encoded PowerShell scripts using the `DownloadString` method. |
| T1047 Windows Management Instrumentation |
CampaignC0015 | During C0015, the threat actors used `wmic` and `rundll32` to load Cobalt Strike onto a target host. |
| T1047 Windows Management Instrumentation |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used WMI to modify Windows Defender settings. |
| T1047 Windows Management Instrumentation |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used WMI for the remote execution of files for lateral movement. |
| T1047 Windows Management Instrumentation |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace used WMI to proxy execution of UPPERCUT. |
| T1047 Windows Management Instrumentation |
CampaignFunnyDream | During FunnyDream, the threat actors used `wmiexec.vbs` to run remote commands. |
| T1047 Windows Management Instrumentation |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, WMI in scripts were used for remote execution and system surveys. |
| T1047 Windows Management Instrumentation |
CampaignOperation Wocao | During Operation Wocao, threat actors has used WMI to execute commands. |
| T1047 Windows Management Instrumentation |
CampaignC0027 | During C0027, Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.