asset_type: Endpoint confidence: medium creation_date: '2018-10-23' data_metadata: data_models: - Endpoint data_source: - Endpoint Intel providing_technologies: - Carbon Black Response - Sysmon - Tanium - Ziften description: This search looks for processes launched via WMI. detect: splunk: correlation_rule: notable: nes_fields: dest, user, process rule_description: This search looks for child processes of WmiPrvSE.exe, which indicates that a process was launched via WMI. rule_title: Process launched via WMI on $dest$ risk: risk_object: dest risk_object_type: - system risk_score: 70 macros: - wmi_process_launch_filter schedule: cron_schedule: 0 * * * * earliest_time: -70m@m latest_time: -10m@m search: '| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.parent_process_name = *WmiPrvSE.exe by Processes.user Processes.dest Processes.process_name | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `wmi_process_launch_filter`' suppress: suppress_fields: dest, user suppress_period: 28800s eli5: Attackers are increasingly abusing Windows Management Infrastructure (WMI) for stealth, persistence, lateral movement, or just to leverage its functionality. This search looks for processes launched via WMI, either remotely or locally, by looking for processes launched by WmiPrvSE.exe, which is the process WMI uses to execute new processes and commands. entities: - dest how_to_implement: You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. id: 24869767-8579-485d-9a4f-d9ddfd8f0cac investigations: - id: 155e0571-7db6-42f2-aa62-9a3a4cf35c94 name: Get Sysmon WMI Activity for Host type: splunk - id: bc91a8cf-35e7-4bb2-8140-e756cc06fd76 name: Get Authentication Logs For Endpoint type: splunk - id: fdcfb369-1725-4c24-824a-22972d7f0d55 name: Get Risk Modifiers For User type: splunk - id: bc91a8cf-35e7-4bb2-8140-e756cc06fd71 name: Get Process Info type: splunk - id: 3d6c3213-5fff-4a1e-b57d-b24c262171e7 name: Get Notable History type: splunk - id: f3fb4d1b-5f33-4b01-b541-c7af9534c242 name: Get Notable Info type: splunk - id: fdcfb369-1725-4c24-824a-22972d7f0d65 name: Get Risk Modifiers For Endpoint type: splunk - id: bc91a8cf-35e7-4bb2-8140-e756cc06fd74 name: Get User Information from Identity Table type: splunk known_false_positives: Although unlikely, administrators may use wmi to execute commands for legitimate purposes. maintainers: - company: Splunk email: rvaldez@splunk.com name: Rico Valdez mappings: cis20: - CIS 3 - CIS 5 kill_chain_phases: - Actions on Objectives mitre_attack: - Execution - Windows Management Instrumentation nist: - PR.PT - PR.AT - PR.AC - PR.IP modification_date: '2020-03-16' name: Process Execution via WMI original_authors: - company: Splunk email: rvaldez@splunk.com name: Rico Valdez references: [] security_domain: endpoint spec_version: 2 type: splunk version: '3.0'