Title:Wmiprvse Wbemcomn DLL Hijack - File Status:test Description:Detects a threat actor creating a file named `wbemcomn.dll` in the `C:\Windows\System32\wbem\` directory over the network and loading it for a WMI DLL Hijack scenario. References: -https://threathunterplaybook.com/hunts/windows/201009-RemoteWMIWbemcomnDLLHijack/notebook.html Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) Date: 2020-10-12 modified:2022-12-02 Tags: