Detection rules › Kusto Query Language
Dev-0270 WMIC Discovery
'The query below identifies dllhost.exe using WMIC to discover additional hosts and associated domains in the environment.'
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Discovery | T1482 Domain Trust Discovery |
Event coverage
| Provider | Event ID | Title |
|---|---|---|
| Security-Auditing | 4688 | A new process has been created. |
Stages and Predicates
Stage 1: source
<union>
Stage 2: union
union of 2 branches