Files
blue-team-tools/rules/windows/process_creation/win_pc_wmic_remove_application.yml
T
2022-01-28 16:12:38 +01:00

23 lines
591 B
YAML

title: WMI Uninstall An Application
id: b53317a0-8acf-4fd1-8de8-a5401e776b96
status: experimental
description: Uninstall an application with wmic
author: frac113
references:
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1047/T1047.md#atomic-test-10---application-uninstall-using-wmic
date: 2022/01/28
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: \WMIC.exe
CommandLine|contains: call uninstall
condition: selection
falsepositives:
- Unknown
level: medium
tags:
- attack.execution
- attack.t1047