FORENSIA

ATT&CK · T1047

Windows Management Instrumentation

Tactics: execution

About

Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as Distributed Component Object Model and Windows Remote Management. Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS. An adversary can use WMI to interact with local and remote systems and use it as a means to execute various behaviors, such as gathering information for Discovery as well as Execution of commands and payloads. For example, `wmic.exe` can be abused by an adversary to delete shadow copies with the command `wmic.exe Shadowcopy Delete` (i.e., Inhibit System Recovery). **Note:** `wmic.exe` is deprecated as of January of 2024, with the WMIC feature being “disabled by default” on Windows 11+. WMIC will be removed from subsequent Windows releases and replaced by PowerShell as the primary WMI interface. In addition to PowerShell and tools like `wbemtool.exe`, COM APIs can also be used to programmatically interact with WMI via C++, .NET, VBScript, etc.

Platforms: WindowsMITRE ATT&CK ↗

Used by actors

42 known groups

Software

93 malware/tools implement this

DustySkyBlackEnergyHALFBAKEDCobalt StrikeKOMPROGOPOWRUNERPowerSploitPOWERSTATSGravityRATRATANKBAKoadicZebrocyMosquitoOopsIEKazuarFELIXROOTRogueRobinjRATAgent TeslaMicropsiaOctopusImpacketEmpireOlympic DestroyerWannaCryEmotetNotPetyaAstarothRemexiHOPLIGHTPoshC2StoneDrillFlawedAmmyyUrsnifEvilBunnyMazeNetwalkerValakIcedIDCrackMapExecREvilLuciferBazarSharpStageMoleNetSUNBURSTEVILNUMSibotStuxnetEKANSDEATHRANSOMHELLOKITTYFIVEHANDSAvaddonQakBotProLockSysUpdateDarkWatchmanCharmPowerMeteorSILENTTRINITYHermeticWizardAction RATPyDCryptBumblebeeFunnyDreamBrute Ratel C4SVCReadyDarkTortillaBlackCatBlack BastaBADHATCHSardonicSnip3DarkGateSocGholishAkiraRaspberry RobinINC RansomwareLunarWebIMAPLoaderCovenantLatrodectusShrinkLockerTAMECATLockBit 2.0PUBLOADTONESHELLQilinLODEINFOROAMINGHOUSEAshTagLAMEHUG

Corpus indicators tagged with this technique

130 indicators in the corpus carry T1047.

IndicatorTypeFamilySevSrc
31037a42ca048e06e69a78f55bc2eff5hash801
2c6f05f1f309d89b2236e6c8b59c88f9hash801
7ee17efef04bb7c9de90d5210263ed6993f867e5a11f86e65e3bb1362c7de237sha256ransomware801
9ca9432b0d29204cb5420a1a6b01533d4552130c2a8a5ecd7837efadefb4a046sha256ransomware801
0ba93109757776a44de9d8c88baa4963hash801
de1a114a2c5552387a1bbb61501bf129hashransomware801
a88daa62751c212b7579a57f1f4ae8f8hashransomware801
7a311b584497e8133cd85950fec6132904dd5b02388a9feed3f5e057fb891d09hashransomware801
e00293ce0eb534874efd615ae590cf6aa3858ba4hashransomware801
d6aaed67606d6dab0f652c755d3d363025f60adbhashransomware801
0b33a1a23b044beb5c9a63aafd35595chashransomware801
887ec87e4a19759cad25d4bc0956d2b965d3041dhash801
f4ae5b89db5a6a36dbd98287ab7c860ahashransomware801
36d968425629b10f38be17787f8afe4b8afa131ehashransomware801
30b49ae2f685d4403d3013410f80c2e2hashransomware801
5f5bf7fc7a9ac89ce0bbb07bd1160078hashransomware801
68225c5613afe2174ed46e074147676b0f9a3915hashransomware801
1e0f4cd09aa4464179933769b5009251hashransomware801
7b885b446bbd9b450146c88f84c64f30hashransomware801
716e39bbc93fd4b394d9e6ef7c29aef1adc7dcb5hashransomware801
83c6c1bb37c9071e569aa4b247e54ab763bbf5dahashransomware801
bd79aec521aa9f0cec374d57692b540b7b5a6ea8hashransomware801
d875d7e99f45c87e667dbebb8d8596182bdb94dfhashransomware801
ebddc99a00bd7a5dcaf7b73349309d970e5c69b8hashransomware801
00ff099e3cf7b548a7a0260cde8ac2f24a746da2hashransomware801
c277ae5a4dd62f51de5278790796cd2700de7f77ea17762e97729f27872d076bsha256ransomware801
4537b37b65e9dc35640d750f3fa7f4944534f6b1hash803
8468cb5888fb383d25f9144c2b2f61c414cea3f8hashransomware803
02bb20455cc592a69c080abac770ce90hash801
63ac85195b73753333316a889cf5880fhash801

Showing the top 30 by severity of 130.