LoFP LoFP / t1047

t1047

TitleTags
administrative scripts that use the same keywords.
appvclient
ccm
false positives are expected (e.g. in environments where winrm is used legitimately)
legitimate administrative activity or software installations
legitimate administrative changes to service startup types using wmic, investigate accordingly.
legitimate system administration
legitimate system administrators enabling rdp for remote support
legitimate use of wmic.exe for reconnaissance of firewall, antivirus and antispywware products.
monitoring tools
security audits, maintenance, and network administrative scripts may trigger this alert only when parent context, child identity, command scope, service identity, and available artifact or destination evidence align to the same bounded workflow.
some administrative tasks on remote host
static format arguments - https://petri.com/command-line-wmi-part-3
system configuration scripts during deployment
the build engine is commonly used by windows developers but use by non-engineers is unusual.
unknown
unlikely
windows administrator tasks or troubleshooting
windows management scripts or software
winrm
wmic.exe fp depend on scripts and administrative methods used in the monitored environment.