logo

The Detection Gap: MITRE ATT&CK T1047

ID: 00d71d70-13aa-546f-952a-ac7bc773f900

STIX ID: report--00d71d70-13aa-546f-952a-ac7bc773f900

Feed Name: security.com

Threat Score
60/100

Date Published: 2026-09-10

Date Updated: 2026-09-10

Author: Kirk Hasty

...
...

This Detection Gap post details how Windows Management Instrumentation (WMI) is frequently abused for execution, lateral movement, and persistence; it contrasts legitimate administrative use with malicious patterns, highlights a high-confidence IOC (a fresh remote logon followed by wmiprvse.exe spawning a suspicious child), and recommends correlating logon and process creation events or using tools such as Symantec Threat Tracer to speed detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.