Hunting Rituals #4: Threat hunting for execution via Windows Management Instrumentation
ID: ee2ee313-da2f-5e4d-be79-d77db1b9a3d6
STIX ID: report--ee2ee313-da2f-5e4d-be79-d77db1b9a3d6
Feed Name: Group-IB Blog
The report outlines practical hunting methodologies for detecting WMI (T1047) execution abuse, highlighting EDR queries targeting wmic.exe command patterns and processes spawned by WmiPrvSe.exe, along with techniques to reduce noise via user/context filters and environment-specific statistics. It emphasizes identifying lateral movement and persistence via WMI and recommends balancing simple hypotheses with broader, noisier searches to improve detection coverage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
