ByteRay CQL Hub
← All queries

LOLBin WMIC

This query detects the use of WMIC.

CQL · Falcon Next-Gen SIEMCopy query
in(#event_simpleName, values=["ProcessRollup2","ProcessBlocked"])
| event_platform=Win and ImageFileName=/wmic.exe/i

Wmic.exe – A built-in Windows tool for scripting and remote system management, which adversaries exploit to run commands, load executables via alternate data streams, execute remote or XSL-formatted payloads, and move files stealthily.

LOLBAS - Wmic.exe

LOLBin_WMIC.yml
T1218, T1105, T1564.004
ByteRay GmbH
Hunting
Endpoint
Insight
2025-08-06
2025-08-26

Get this query running in your SIEM, with someone on call.

Our Managed SIEM team operates CrowdStrike Falcon Next-Gen SIEM in production, with over 350 battle-tested use cases and 24/7 incident response behind them.

Talk to the SIEM team