Windows Process Creation Attempt Using wmic.exe process call create
Alerts on Windows process creation attempts invoking wmic.exe with “process call create”, a common pattern for WMI-based execution.
- Product
- windows
- Category
- process_creation
- Author
- Michael Haag, Florian Roth (Nextron Systems), juju4, oscd.community (SigmaHQ), DRL 1.1
- Published
- 2019-01-16
- Updated
- 2026-07-30
ATT&CK techniques
ExecutionRecon
Resource Dev
Initial Access
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process creation events where the executable is wmic.exe and the command line contains the components “process”, “call”, and “create”, consistent with attempting to create a process through WMI. Such execution matters because wmic can be used to run commands on the host, potentially enabling attacker-controlled process execution. The detection relies on Windows process creation telemetry, using fields that identify wmic.exe and match required command-line substrings.
Reporting behind it
- sans.orghttps://www.sans.org/blog/wmic-for-incident-response/
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/84215139ee5127f8e3a117e063b604812bd71928/atomics/T1047/T1047.md#atomic-test-5---wmi-execute-local-process
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_wmic_process_creation.yml
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Process Creation Attempt Using wmic.exe process call create
id: fb2a9cc8-d186-4bf1-b1bd-3943c8637cfe
related:
- id: 3c89a1e8-0fba-449e-8f1b-8409d6267ec8
type: derived
- id: 526be59f-a573-4eea-b5f7-f0973207634d
type: derived
status: test
description: This rule flags process creation events where the executable is wmic.exe and the command line contains the components “process”, “call”, and “create”, consistent with attempting to create a process through WMI. Such execution matters because wmic can be used to run commands on the host, potentially enabling attacker-controlled process execution. The detection relies on Windows process creation telemetry, using fields that identify wmic.exe and match required command-line substrings.
references:
- https://www.sans.org/blog/wmic-for-incident-response/
- https://github.com/redcanaryco/atomic-red-team/blob/84215139ee5127f8e3a117e063b604812bd71928/atomics/T1047/T1047.md#atomic-test-5---wmi-execute-local-process
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_wmic_process_creation.yml
author: Michael Haag, Florian Roth (Nextron Systems), juju4, oscd.community, Huntrule Team
date: 2019-01-16
modified: 2023-02-14
tags:
- attack.execution
- attack.t1047
- car.2016-03-002
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \wmic.exe
- OriginalFileName: wmic.exe
selection_cli:
CommandLine|contains|all:
- process
- call
- create
condition: all of selection_*
falsepositives:
- Unknown
level: medium
simulation:
- type: atomic red team
name: WMI Execute Local Process
technique: T1047
atomic_guid: b3bdfc91-b33e-4c6d-a5c8-d64bee0276b3
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_wmic_process_creation/info.yml
license: DRL-1.1