logo

Hunting Rituals #4: Threat hunting for execution via Windows Management Instrumentation

ID: ee2ee313-da2f-5e4d-be79-d77db1b9a3d6

STIX ID: report--ee2ee313-da2f-5e4d-be79-d77db1b9a3d6

Feed Name: Group-IB Blog

Date Published: 2024-03-29

Date Updated: 2026-04-27

...
...

The report outlines practical hunting methodologies for detecting WMI (T1047) execution abuse, highlighting EDR queries targeting wmic.exe command patterns and processes spawned by WmiPrvSe.exe, along with techniques to reduce noise via user/context filters and environment-specific statistics. It emphasizes identifying lateral movement and persistence via WMI and recommends balancing simple hypotheses with broader, noisier searches to improve detection coverage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.