PowerShell WMI Service Enumeration for Unquoted Service Path Recon
Flags PowerShell WMI queries for Win32_Service fields to enumerate potential unquoted service path issues.
- Product
- windows
- Category
- ps_script
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2022-06-20
- Updated
- 2026-07-31
ATT&CK techniques
ExecutionRecon
Resource Dev
Initial Access
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags PowerShell script blocks that use WMI queries (Get-WmiObject/gwmi) targeting Win32_Service fields used for service path analysis. Attackers and testers use this to enumerate service properties such as Name, DisplayName, PathName, and StartMode to identify potentially exploitable unquoted service paths. Telemetry relies on PowerShell Script Block Logging capturing the query and selected field names in the script block text.
Reporting behind it
- github.comhttps://github.com/nccgroup/redsnarf/blob/35949b30106ae543dc6f2bc3f1be10c6d9a8d40e/redsnarf.py
- github.comhttps://github.com/S3cur3Th1sSh1t/Creds/blob/eac23d67f7f90c7fc8e3130587d86158c22aa398/PowershellScripts/jaws-enum.ps1
- absolomb.comhttps://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_wmi_unquoted_service_search.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: PowerShell WMI Service Enumeration for Unquoted Service Path Recon
id: 80b07b9c-b5ae-410a-8d74-cc0fa7497364
related:
- id: 68bcd73b-37ef-49cb-95fc-edc809730be6
type: similar
- id: 09658312-bc27-4a3b-91c5-e49ab9046d1b
type: derived
status: test
description: This rule flags PowerShell script blocks that use WMI queries (Get-WmiObject/gwmi) targeting Win32_Service fields used for service path analysis. Attackers and testers use this to enumerate service properties such as Name, DisplayName, PathName, and StartMode to identify potentially exploitable unquoted service paths. Telemetry relies on PowerShell Script Block Logging capturing the query and selected field names in the script block text.
references:
- https://github.com/nccgroup/redsnarf/blob/35949b30106ae543dc6f2bc3f1be10c6d9a8d40e/redsnarf.py
- https://github.com/S3cur3Th1sSh1t/Creds/blob/eac23d67f7f90c7fc8e3130587d86158c22aa398/PowershellScripts/jaws-enum.ps1
- https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_wmi_unquoted_service_search.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-06-20
modified: 2022-11-25
tags:
- attack.execution
- attack.t1047
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection:
ScriptBlockText|contains:
- "Get-WmiObject "
- "gwmi "
ScriptBlockText|contains|all:
- " Win32_Service "
- Name
- DisplayName
- PathName
- StartMode
condition: selection
falsepositives:
- Unknown
level: medium
license: DRL-1.1