Windows Process Creation: Office-Launched WMIC with LOLBIN-Style Command Arguments

Alerts on Office spawning WMIC.exe with process/create/call arguments and LOLBIN-like tool references.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Vadim Khrykov, Cyb3rEng (SigmaHQ), DRL 1.1
Published
2021-08-23
Updated
2026-07-30

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags cases where a Microsoft Office application spawns WMIC.exe and supplies command-line arguments consistent with process creation via scripted/LOLBIN-like behavior (for example, containing combinations such as process, create, and call along with tools like regsvr32, rundll32, msiexec, mshta, verclsid, wscript, or cscript). Such activity is suspicious because attackers commonly use Office as an initial foothold and WMIC as an execution proxy to obscure the true parent-child relationship. It relies on Windows process creation telemetry, including parent process image paths, WMIC image/original filename, and WMIC command line contents.

Related detections9 linkedT1047 — drag to rearrange
Windows WmiPrvSE.exe Spawning Suspicious Script and LOLBIN Child Processes
Windows: Suspicious Process Spawning from Microsoft Office Applications
Malicious Office Application Loading a User-Path DLL via Regsvr32 or Rundll32 (via process_creation)
Windows Process Creation: Maze Ransomware Doc Dropper and Shadow Copy Deletion Indicators
Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Windows: Alert on Suspicious HH.EXE Process Execution
Suspicious OneNote Spawning Script Interpreter (via process_creation)
Lateral Movement via WMIC Remote Process Creation
Suspicious vbc.exe Spawned by Installer Process
Windows Process Creation: Office-Launched WMIC with LOLBIN-Style Command Arguments
Pivot detection · T1047 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.