WMI Spawning Suspicious Child Process (Living off the Land)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Detects WmiPrvSE.exe (the WMI Provider Host) spawning high-risk processes such as PowerShell, cmd.exe, cscript, or other LOLBins. WMI requires no external tools, generates minimal disk artifacts, and can execute code on remote systems over DCOM/RPC while bypassing many controls. Tune AllowlistedCmdPatterns for known-safe management tools such as SCCM.

Attribute Value
Type Analytic Rule
Solution Windows Security Events
ID 3c8e5f0b-1d4a-4b69-9c2e-7f0d3a5e8b1f
Severity High
Status Available
Kind Scheduled
Tactics Execution, LateralMovement, Persistence
Techniques T1047, T1021.006, T1059.001, T1059.003, T1059.005
Required Connectors MicrosoftThreatProtection, SecurityEvents
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
DeviceProcessEvents ✓ ✗ ✓
SecurityEvent EventID == "4688" ✓ ✓ ✓

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Analytic Rules · Back to Windows Security Events