Suspicious Lateral Movement via Invoke-WMIExec or Invoke-SMBExec (via ps_script)

PremiumReviewedSigma · High · v1
Product
windows
Category
ps_script
Author
HuntRule
Published
2026-07-14
Updated
2026-08-28

ATT&CK techniques

Defense Evasion → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects PowerShell use of the Invoke-WMIExec or Invoke-SMBExec pass-the-hash tooling observed alongside the ThrottleStop AV-killer intrusion. These functions authenticate to remote hosts with an NTLM hash and run commands such as local account creation without a plaintext password. Their presence indicates hands-on lateral movement using stolen credential material.

Related detections6 linkedT1550.002 — drag to rearrange
Suspicious Registry Modification Disabling RestrictedAdmin Mode (via process_creation)
Windows LsaSrv Events Indicating NTLMv1 Logon Between Client and Server
Windows Pass-the-Hash Activity via Security Event 4624 (LogonType 3 or 9)
Windows NTLM authentication events (Event ID 8002)
Windows Successful Logon Type 9 (NewCredentials) Matching Overpass-the-Hash
Windows Security: Detects RULER workstation using NTLM and login events (Event IDs 4776, 4624/4625)
Suspicious Lateral Movement via Invoke-WMIExec or Invoke-SMBExec (via ps_script)
Pivot detection · T1550.002 · 6 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.