Hardware Model Reconnaissance Via Wmic.EXE

Rule Info

Name
Hardware Model Reconnaissance Via Wmic.EXE
Author
Florian Roth (Nextron Systems)
Description
Detects the execution of WMIC with the "csproduct" which is used to obtain information such as hardware models and vendor information
Date
2023-02-14 00:00:00
Modified
None
Id
3e3ceccd-6c06-48b8-b5ff-ab1d25db8c1d
Tags
attack.execution attack.t1047 car.2016-03-002
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
github-actions[bot]
chore: promote older rules status from `experimental` to `test` (#4651)
2024-01-01
Nasreddine Bencherchali
fix: apply suggestions from code review
2023-02-16
Nasreddine Bencherchali
feat: update wmic rules
2023-02-14