Free kit

Free AI Tabletop Exercise Kit for SMBs

Sign up for the Cyber Defense & AI Brief and get it free.

Get the free kit

UC-L3-021

WMIC Process Creation

Sysmon Event ID 1

Use case development / Detect Malware Infections / Detect Malware Execution

sigma

Detection rule

title: WMIC Process Execution
status: experimental
description: Detects process creation via WMIC command
logsource:
  product: windows
  category: process_creation
detection:
  selection:
    Image|endswith: '\wmic.exe'
    CommandLine|contains: 'process call create'
  condition: selection
falsepositives:
  - Legitimate admin scripts
level: medium
tags:
  - attack.execution
  - attack.t1047

Test cases

  • Create process using WMIC

False positive guidance

Baseline WMIC usage by admin accounts.

Detection course