Real-world descriptions of how a group, tool or campaign used a technique.
93 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareEKANS | EKANS can use Windows Mangement Instrumentation (WMI) calls to execute operations. |
| T1047 Windows Management Instrumentation |
MalwareBumblebee | Bumblebee can use WMI to gather system information and to spawn processes for code injection. |
| T1047 Windows Management Instrumentation |
MalwareStuxnet | Stuxnet used WMI with an |
| T1047 Windows Management Instrumentation |
MalwarePOWRUNER | POWRUNER may use WMI when collecting information about a victim. |
| T1047 Windows Management Instrumentation |
MalwareSharpStage | SharpStage can use WMI for execution. |
| T1047 Windows Management Instrumentation |
MalwareSardonic | Sardonic can use WMI to execute PowerShell commands on a compromised machine. |
| T1047 Windows Management Instrumentation |
MalwareHALFBAKED | HALFBAKED can use WMI queries to gather system information. |
| T1047 Windows Management Instrumentation |
MalwareTAMECAT | TAMECAT has used Windows Management Instrumentation (WMI) to query anti-virus products. |
| T1047 Windows Management Instrumentation |
MalwareUrsnif | Ursnif droppers have used WMI classes to execute PowerShell commands. |
| T1047 Windows Management Instrumentation |
MalwareGravityRAT | GravityRAT collects various information via WMI requests, including CPU information in the Win32_Processor entry (Processor ID, Name, Manufacturer and the clock speed). |
| T1047 Windows Management Instrumentation |
MalwareROAMINGHOUSE | ROAMINGHOUSE can use WMI to launch a legitimate executable later used to enable DLL sideloading. |
| T1047 Windows Management Instrumentation |
MalwareTONESHELL | TONESHELL has used WMI queries to gather information from the system. |
| T1047 Windows Management Instrumentation |
MalwarePyDCrypt | PyDCrypt has attempted to execute with WMIC. |
| T1047 Windows Management Instrumentation |
MalwareIMAPLoader | IMAPLoader uses WMI queries to query system information on victim hosts. |
| T1047 Windows Management Instrumentation |
MalwareEmotet | Emotet has used WMI to execute powershell.exe. |
| T1047 Windows Management Instrumentation |
MalwareOlympic Destroyer | Olympic Destroyer uses WMI to help propagate itself across a network. |
| T1047 Windows Management Instrumentation |
MalwareBADHATCH | BADHATCH can utilize WMI to collect system information, create new processes, and run malicious PowerShell scripts on a compromised machine. |
| T1047 Windows Management Instrumentation |
MalwareAction RAT | Action RAT can use WMI to gather AV products installed on an infected host. |
| T1047 Windows Management Instrumentation |
MalwarePUBLOAD | PUBLOAD has used `wmic` to gather information from the victim device. |
| T1047 Windows Management Instrumentation |
MalwareShrinkLocker | ShrinkLocker uses WMI to query information about the victim operating system. |
| T1047 Windows Management Instrumentation |
MalwareFlawedAmmyy | FlawedAmmyy leverages WMI to enumerate anti-virus on the victim. |
| T1047 Windows Management Instrumentation |
MalwareSnip3 | Snip3 can query the WMI class `Win32_ComputerSystem` to gather information. |
| T1047 Windows Management Instrumentation |
MalwareHOPLIGHT | HOPLIGHT has used WMI to recompile the Managed Object Format (MOF) files in the WMI repository. |
| T1047 Windows Management Instrumentation |
MalwareProLock | ProLock can use WMIC to execute scripts on targeted hosts. |
| T1047 Windows Management Instrumentation |
MalwareRaspberry Robin | Raspberry Robin can execute via LNK containing a command to run a legitimate executable, such as wmic.exe, to download a malicious Windows Installer (MSI) package. |
| T1047 Windows Management Instrumentation |
MalwareBlackCat | BlackCat can use `wmic.exe` to delete shadow copies on compromised networks. |
| T1047 Windows Management Instrumentation |
MalwareIcedID | IcedID has used WMI to execute binaries. |
| T1047 Windows Management Instrumentation |
MalwareKazuar | Kazuar obtains a list of running processes through WMI querying. |
| T1047 Windows Management Instrumentation |
MalwareLucifer | Lucifer can use WMI to log into remote machines for propagation. |
| T1047 Windows Management Instrumentation |
MalwareBlackEnergy | A BlackEnergy 2 plug-in uses WMI to gather victim host details. |
| T1047 Windows Management Instrumentation |
MalwareNotPetya | NotPetya can use |
| T1047 Windows Management Instrumentation |
MalwareAvaddon | Avaddon uses wmic.exe to delete shadow copies. |
| T1047 Windows Management Instrumentation |
MalwareSocGholish | SocGholish has used WMI calls for script execution and system profiling. |
| T1047 Windows Management Instrumentation |
MalwareHELLOKITTY | HELLOKITTY can use WMI to delete volume shadow copies. |
| T1047 Windows Management Instrumentation |
MalwareDarkTortilla | DarkTortilla can use WMI queries to obtain system information. |
| T1047 Windows Management Instrumentation |
MalwareDarkWatchman | DarkWatchman can use WMI to execute commands. |
| T1047 Windows Management Instrumentation |
MalwareDustySky | The DustySky dropper uses Windows Management Instrumentation to extract information about the operating system and whether an anti-virus is active. |
| T1047 Windows Management Instrumentation |
MalwareDEATHRANSOM | DEATHRANSOM has the ability to use WMI to delete volume shadow copies. |
| T1047 Windows Management Instrumentation |
MalwareAkira | Akira will leverage COM objects accessed through WMI during execution to evade detection. |
| T1047 Windows Management Instrumentation |
MalwareDarkGate | DarkGate has used WMI to execute files over the network and to obtain information about the domain. |
| T1047 Windows Management Instrumentation |
MalwareSVCReady | SVCReady can use `WMI` queries to detect the presence of a virtual machine environment. |
| T1047 Windows Management Instrumentation |
MalwareNetwalker | Netwalker can use WMI to delete Shadow Volumes. |
| T1047 Windows Management Instrumentation |
MalwareWannaCry | WannaCry utilizes |
| T1047 Windows Management Instrumentation |
MalwareLatrodectus | Latrodectus has used WMI in malicious email infection chains to facilitate the installation of remotely-hosted files. |
| T1047 Windows Management Instrumentation |
MalwareLODEINFO | LODEINFO can execute commands with WMI. |
| T1047 Windows Management Instrumentation |
MalwareCharmPower | CharmPower can use `wmic` to gather information from a system. |
| T1047 Windows Management Instrumentation |
MalwareEVILNUM | EVILNUM has used the Windows Management Instrumentation (WMI) tool to enumerate infected machines. |
| T1047 Windows Management Instrumentation |
MalwareKOMPROGO | KOMPROGO is capable of running WMI queries. |
| T1047 Windows Management Instrumentation |
MalwareMoleNet | MoleNet can perform WMI commands on the system. |
| T1047 Windows Management Instrumentation |
MalwareMicropsia | Micropsia searches for anti-virus software and firewall products installed on the victim’s machine using WMI. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.