42
Groups Using This
1
Tactics
1
Platforms
23
Prevalence Rank
Description

Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems. WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access, though the latter is facilitated by Remote Services such as Distributed Component Object Model and Windows Remote Management. Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS. An adversary can use WMI to interact with local and remote systems and use it as a means to execute various behaviors, such as gathering information for Discovery as well as Execution of commands and payloads. For example, `wmic.exe` can be abused by an adversary to delete shadow copies with the command `wmic.exe Shadowcopy Delete` (i.e., Inhibit System Recovery). **Note:** `wmic.exe` is deprecated as of January of 2024, with the WMIC feature being “disabled by default” on Windows 11+. WMIC will be removed from subsequent Windows releases and replaced by PowerShell as the primary WMI interface. In addition to PowerShell and tools like `wbemtool.exe`, COM APIs can also be used to programmatically interact with WMI via C++, .NET, VBScript, etc.

View MITRE record ↗

Platforms
Windows
Groups Using T1047 (42)
G0032
Lazarus Group
🇰🇵 North Korea93 techniques26 software
G0129
Mustang Panda
🇷🇺 Russia85 techniques23 software
G0096
APT41
🇨🇳 China82 techniques32 software
G1017
Volt Typhoon
🇨🇳 China81 techniques17 software
G0034
Sandworm Team
🇷🇺 Russia79 techniques27 software
G0050
APT32
🇻🇳 Vietnam78 techniques15 software
G0059
Magic Hound
🇮🇷 Iran78 techniques13 software
G0049
OilRig
🇮🇷 Iran76 techniques30 software
G0047
Gamaredon Group
🇷🇺 Russia70 techniques6 software
G0069
MuddyWater
🇮🇷 Iran68 techniques21 software
G0046
FIN7
67 techniques19 software
G0016
APT29
🇷🇺 Russia66 techniques49 software
G0102
Wizard Spider
🇷🇺 Russia64 techniques22 software
G1055
VOID MANTICORE
🇮🇷 Iran63 techniques0 software
G0114
Chimera
🇨🇳 China59 techniques6 software
G0027
Threat Group-3390
🇨🇳 China57 techniques24 software
G1051
Medusa Group
57 techniques5 software
G1016
FIN13
53 techniques4 software
G0065
Leviathan
🇨🇳 China50 techniques17 software
G1043
BlackByte
48 techniques8 software
G1003
Ember Bear
🇷🇺 Russia47 techniques11 software
G0045
menuPass
🇨🇳 China46 techniques25 software
G1006
Earth Lusca
🇨🇳 China44 techniques9 software
G1054
MirrorFace
🇨🇳 China43 techniques16 software
G0037
FIN6
40 techniques12 software
G0099
APT-C-36
38 techniques9 software
G0061
FIN8
36 techniques11 software
G0143
Aquatic Panda
🇨🇳 China35 techniques6 software
G0119
Indrik Spider
🇷🇺 Russia33 techniques8 software
G1044
APT42
🇮🇷 Iran32 techniques2 software
G0093
GALLIUM
🇷🇺 Russia31 techniques16 software
G1018
TA2541
28 techniques9 software
G1022
ToddyCat
25 techniques9 software
G1032
INC Ransom
25 techniques8 software
G1047
Velvet Ant
22 techniques2 software
G0108
Blue Mockingbird
22 techniques2 software
G0030
Lotus Blossom
21 techniques9 software
G1021
Cinnamon Tempest
🇨🇳 China19 techniques8 software
G0112
Windshift
19 techniques1 software
G0038
Stealth Falcon
16 techniques0 software
G0019
Naikon
🇨🇳 China14 techniques15 software
G0009
Deep Panda
🇨🇳 China10 techniques7 software
↑