LOLBin WMIC
This query detects the use of WMIC.
CQL · Falcon Next-Gen SIEMCopy query
in(#event_simpleName, values=["ProcessRollup2","ProcessBlocked"])
| event_platform=Win and ImageFileName=/wmic.exe/iWmic.exe – A built-in Windows tool for scripting and remote system management, which adversaries exploit to run commands, load executables via alternate data streams, execute remote or XSL-formatted payloads, and move files stealthily.
LOLBin_WMIC.yml
T1218, T1105, T1564.004
ByteRay GmbH
Hunting
Endpoint
Insight
2025-08-06
2025-08-26
