Detection rules › Kusto Query Language

Dev-0270 WMIC Discovery

Source
upstream

'The query below identifies dllhost.exe using WMIC to discover additional hosts and associated domains in the environment.'

MITRE ATT&CK coverage

TacticTechniques
DiscoveryT1482 Domain Trust Discovery

Event coverage

ProviderEvent IDTitle
Security-Auditing4688A new process has been created.

Stages and Predicates

Stage 1: source

<union>

Stage 2: union

union of 2 branches

Stage 3: extend

Stage 4: extend

Stage 5: extend