Windows Security Log: Network Write of wbemcomn.dll in System32\wbem for WMI DLL Hijack (T1047)

Flags remote creation of wbemcomn.dll in System32\wbem associated with WMI DLL hijack activity.

FreeReviewedSigma · High · v2
Product
windows
Service
security
Author
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR) (SigmaHQ), DRL 1.1
Published
2020-10-12
Updated
2026-07-31

ATT&CK techniques

Execution → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags creation of a file named wbemcomn.dll within C:\Windows\System32\wbem\ when the file operation is sourced over the network (EventID 5145). Attackers may use this placement to enable WMI DLL Hijacking via DLL search order or hijacking patterns. The detection relies on Windows Security auditing for network file access and specifically matches the target filename ending with \wbem\wbemcomn.dll while excluding machine accounts ending with '$'.

Related detections9 linkedT1021.002 — drag to rearrange
Malicious Impacket Wmiexec Remote Command Execution Pattern
Malicious Remote Process Creation via WMIC Node
Malicious Impacket WMIExec ADMIN Share Output Redirection
Suspicious Command Shell Spawned by WMI Provider Host Targeting ADMIN Share (via process_creation)
Malicious Remote Process Creation via wmic node call create
Malicious Impacket wmiexec Output Redirection via ADMIN Share
Windows WMI DLL Hijack via Network-placed wbemcomn.dll in System32\wbem
Windows WMIPRVSE DLL Hijack via Network-Created wbemcomn.dll in System32\wbem
Suspicious Access to Citrix Session Evidence Registry Keys
Windows Security Log: Network Write of wbemcomn.dll in System32\wbem for WMI DLL Hijack (T1047)
Pivot detection · T1021.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.