T1047: Windows Management Instrumentation
Adversaries may abuse WMI or wmic.exe to execute malicious commands and query system information on local and remote systems.
Total Capable Binaries: 3
•
Windows: 3
•
Linux: 0
•
macOS: 0
Living-off-the-Land Matrix for T1047
Across 3 verified binariesWindows1 payloads
wmic.exe
Windows Management Instrumentation Command-line (WMIC) provides a command-line interface for WMI. Abused for process execution, remote lateral movement, process creation, and running XSL stylesheets.
Sample Attack Vector:
wmic.exe process call create "powershell.exe -w hidden -enc ..."Windows1 payloads
Mofcomp.exe
Compiler that parses a file containing MOF statements and adds the classes and class instances defined in the file to the WMI repository. Threat actors can leverage this binary to install malicious MOF scripts
Sample Attack Vector:
mofcomp.exe {PATH_ABSOLUTE:.mof}Windows1 payloads
wbemtest.exe
WMI/WBEM Test Binary
Sample Attack Vector:
wbemtest.exeCurated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection Engineer • Check Point