Windows WMI (wmic.exe) Sets User Password to Never Expire

Detects wmic.exe commands that set a Windows account password to never expire via WMI.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Daniel Koifman (KoifSec) (SigmaHQ), DRL 1.1
Published
2025-07-30
Updated
2026-07-30

ATT&CK techniques

Execution → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags use of wmic.exe to change a user account property that disables password expiration (passwordexpires set to false). Attackers may use this to maintain persistent access without needing password resets, which can reduce friction for long-term compromise. It relies on Windows process creation telemetry, matching on the process executable name and specific command-line arguments indicating the password expiration setting change.

Related detections9 linkedT1098 — drag to rearrange
Malicious UAT-8302 Remote Process Execution via wmic
Malicious Remote Encryptor Execution via WMIC Process Call Create (Chaos Ransomware)
Malicious Impacket Wmiexec Remote Command Execution Pattern
Malicious Shadow Copy Deletion Via WMI
Malicious Cluster-Admin Role Binding Creation (via audit)
Malicious User Password Change Using Current Hash Password - ChangeNTLM - Mimikatz (via security)
Suspicious Account Password Set to Never Expire. (via security)
Malicious Modification of a Computer Account SPN (via security)
Suspicious Massive Group Membership Changes (via security)
Windows WMI (wmic.exe) Sets User Password to Never Expire
Pivot detection · T1098 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.