The Detection Gap: MITRE ATT&CK T1047
ID: 00d71d70-13aa-546f-952a-ac7bc773f900
STIX ID: report--00d71d70-13aa-546f-952a-ac7bc773f900
Feed Name: security.com
Threat Score
This Detection Gap post details how Windows Management Instrumentation (WMI) is frequently abused for execution, lateral movement, and persistence; it contrasts legitimate administrative use with malicious patterns, highlights a high-confidence IOC (a fresh remote logon followed by wmiprvse.exe spawning a suspicious child), and recommends correlating logon and process creation events or using tools such as Symantec Threat Tracer to speed detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
