fe9b91c504
changed to the following to follow rule creation guidelines:
- Image|endswith: '\wbem\WMIC.exe'
- ProcessCommandLine|contains: 'wmic '