Suspicious Command Shell Spawned by WMI Provider Host Targeting ADMIN Share (via process_creation)

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-06-10
Updated
2026-08-28

ATT&CK techniques

Execution → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects cmd.exe spawned by the WMI provider host with a command line referencing the ADMIN administrative share, a remote execution pattern Volt Typhoon uses to run commands and stage output over WMI. Combining a WMI parent with administrative share access reflects remote lateral movement rather than routine local scripting, making it a strong signal of interactive intrusion activity.

Related detections9 linkedT1021.002 — drag to rearrange
Malicious Remote Process Creation via WMIC Node
Malicious Impacket WMIExec ADMIN Share Output Redirection
Malicious Remote Process Creation via wmic node call create
Malicious Impacket wmiexec Output Redirection via ADMIN Share
Windows WMI DLL Hijack via Network-placed wbemcomn.dll in System32\wbem
Windows WMIPRVSE DLL Hijack via Network-Created wbemcomn.dll in System32\wbem
Windows Security Log: Network Write of wbemcomn.dll in System32\wbem for WMI DLL Hijack (T1047)
Malicious Network Share Manipulation via Commandline (via process_creation)
Suspicious Remote Process Creation via WMIC Process Call Create (via process_creation)
Suspicious Command Shell Spawned by WMI Provider Host Targeting ADMIN Share (via process_creation)
Pivot detection · T1021.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.