Windows WMI StdRegProv Registry Enumeration via wmic.exe

Flags wmic.exe usage invoking WMI StdRegProv registry read/enumeration methods for discovery.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-07-30
Updated
2026-07-30

ATT&CK techniques

Execution → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies process executions of wmic.exe where the command line includes WMI StdRegProv calls to enumerate or read registry data using methods such as EnumKey, EnumValues, GetStringValue, and related read operations. Attackers may use this approach for discovery, retrieving sensitive configuration or credential-adjacent values and installed software details while blending in with legitimate administrative tooling. The detection relies on process creation telemetry, specifically the image path/original filename and the presence of StdRegProv call method strings in the command line.

Related detections9 linkedT1047 — drag to rearrange
Malicious UAT-8302 Remote Process Execution via wmic
Malicious Remote Encryptor Execution via WMIC Process Call Create (Chaos Ransomware)
Malicious Impacket Wmiexec Remote Command Execution Pattern
Malicious Shadow Copy Deletion Via WMI
Suspicious Remote Process Creation via WMIC Process Call Create (via process_creation)
Registry Query for WDigest
Suspicious System Reconnaissance via WMI Command-Line Queries (via process_creation)
Malicious Impacket WMIexec Process Execution (via process_creation)
Suspicious Child Process Spawned by WMI Provider Host (via process_creation)
Windows WMI StdRegProv Registry Enumeration via wmic.exe
Pivot detection · T1047 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.