Windows WMIC System Information Discovery via WMI Command-Line Queries

Flags WMIC command-line queries that pull OS, hardware, disk, memory, BIOS, and GPU details while excluding VMware Tools discovery scripts.

FreeReviewedSigma · Low · v5
Product
windows
Category
process_creation
Author
Joseliyo Sanchez, @Joseliyo_Jstnk (SigmaHQ), DRL 1.1
Published
2023-12-19
Updated
2026-07-31
title: Windows WMIC System Information Discovery via WMI Command-Line Queries
id: 04a161d1-4e83-4896-b853-e46d66816de8
related:
  - id: 9d5a1274-922a-49d0-87f3-8c653483b909
    type: derived
  - id: d85ecdd7-b855-4e6e-af59-d9c78b5b861e
    type: derived
status: test
description: This rule identifies process executions of wmic.exe (WMIC.exe) where the command line includes the "get" operation and queries specific WMI classes such as OS, CPU, diskdrive, memory (memphysical), baseboard, BIOS, and video controller details. Attackers often use WMIC for system inventory and discovery to tailor follow-on activity to the host’s hardware and software configuration. Telemetry relies on Windows process creation events capturing the executable name/path and command-line contents, excluding VMware Tools serviceDiscovery scripts to reduce noise.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/a2ccd19c37d0278b4ffa8583add3cf52060a5418/atomics/T1082/T1082.md#atomic-test-25---system-information-discovery-with-wmic
  - https://nwgat.ninja/getting-system-information-with-wmic-on-windows/
  - https://blog.sekoia.io/aurora-a-rising-stealer-flying-under-the-radar
  - https://blog.cyble.com/2023/01/18/aurora-a-stealer-using-shapeshifting-tactics/
  - https://app.any.run/tasks/a6aa0057-82ec-451f-8f99-55650ca537da/
  - https://www.virustotal.com/gui/file/d6f6bc10ae0e634ed4301d584f61418cee18e5d58ad9af72f8aa552dc4aaeca3/behavior
  - https://github.com/SigmaHQ/sigma/blob/master/rules-threat-hunting/windows/process_creation/proc_creation_win_wmic_recon_system_info.yml
author: Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule Team
date: 2023-12-19
modified: 2024-01-15
tags:
  - attack.discovery
  - attack.t1082
  - detection.threat-hunting
logsource:
  category: process_creation
  product: windows
detection:
  selection_wmic:
    - Description: WMI Commandline Utility
    - OriginalFileName: wmic.exe
    - Image|endswith: \WMIC.exe
  selection_get:
    CommandLine|contains: get
  selection_classes:
    CommandLine|contains:
      - baseboard
      - bios
      - cpu
      - diskdrive
      - logicaldisk
      - memphysical
      - os
      - path
      - startup
      - win32_videocontroller
  selection_attributes:
    CommandLine|contains:
      - caption
      - command
      - driverversion
      - maxcapacity
      - name
      - osarchitecture
      - product
      - size
      - smbiosbiosversion
      - version
      - videomodedescription
  filter_optional_vmtools:
    ParentCommandLine|contains: \VMware\VMware Tools\serviceDiscovery\scripts\
  condition: all of selection_* and not 1 of filter_optional_*
falsepositives:
  - VMWare Tools serviceDiscovery scripts
level: low
license: DRL-1.1