Windows Defender Exploit Guard blocks PSExec/WMI process creations (PsExec service and WMI provider)

Flags ASR blocks (windefend 1121) of process creations tied to WMI (wmiprvse.exe) or PSExec (psexesvc.exe).

FreeReviewedSigma · High · v2
Product
windows
Service
windefend
Author
Bhabesh Raj (SigmaHQ), DRL 1.1
Published
2020-07-14
Updated
2026-07-31

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies when Windows Defender Exploit Guard (Attack Surface Reduction) blocks process creation events tied to PSExec and WMI execution. Attackers commonly use PSExec or WMI to run commands remotely for lateral movement while attempting to evade standard application controls, so blocking these paths is security-relevant. It relies on windefend telemetry for EventID 1121 and matches blocked process creation activity involving the WMI provider host (wmiprvse.exe) or the PSExec service process (psexesvc.exe).

Related detections9 linkedT1047 — drag to rearrange
Zeek DCE-RPC Execution Indicators: JobAdd, Task Scheduler RPC, WMI ExecMethod, and Service Creation/Start
Lateral Movement via WMIC Remote Process Creation
Suspicious PsExec Service Named Sliver
Malicious UAT-8302 Remote Process Execution via wmic
Malicious Remote Encryptor Execution via WMIC Process Call Create (Chaos Ransomware)
Malicious Impacket Wmiexec Remote Command Execution Pattern
Malicious Shadow Copy Deletion Via WMI
PsExec Remote Service Execution on Target Host (via process_creation)
Suspicious Remote Process Creation via WMIC Process Call Create (via process_creation)
Windows Defender Exploit Guard blocks PSExec/WMI process creations (PsExec service and WMI provider)
Pivot detection · T1047 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.