T1047Tactic: ExecutionOfficial MITRE ATT&CK Page

T1047: Windows Management Instrumentation

Adversaries may abuse WMI or wmic.exe to execute malicious commands and query system information on local and remote systems.

Total Capable Binaries: 3
Windows: 3
Linux: 0
macOS: 0

Living-off-the-Land Matrix for T1047

Across 3 verified binaries
Windows1 payloads

wmic.exe

Windows Management Instrumentation Command-line (WMIC) provides a command-line interface for WMI. Abused for process execution, remote lateral movement, process creation, and running XSL stylesheets.

Sample Attack Vector:
wmic.exe process call create "powershell.exe -w hidden -enc ..."
Windows1 payloads

Mofcomp.exe

Compiler that parses a file containing MOF statements and adds the classes and class instances defined in the file to the WMI repository. Threat actors can leverage this binary to install malicious MOF scripts

Sample Attack Vector:
mofcomp.exe {PATH_ABSOLUTE:.mof}
Windows1 payloads

wbemtest.exe

WMI/WBEM Test Binary

Sample Attack Vector:
wbemtest.exe
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point