Skip to content

Commit 18b1648

Browse files
saulpanderswietze
andauthored
Added wbemtest.exe (#430)
Co-authored-by: Wietze <wietze@users.noreply.github.com>
1 parent e15a9c3 commit 18b1648

File tree

1 file changed

+25
-0
lines changed

1 file changed

+25
-0
lines changed

yml/OSBinaries/Wbemtest.yml

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
---
2+
Name: wbemtest.exe
3+
Description: WMI/WBEM Test Binary
4+
Author: saulpanders
5+
Created: 2025-04-22
6+
Commands:
7+
- Command: wbemtest.exe
8+
Description: Execute arbitary commands through WMI through a GUI managment interface for Web Based Enterprise Management testing (WBEM). Uses WMI to Create and instance of a Win32_Process WMI class with a commandline argument of the target command to spawn. Spawns a GUI so it requires interactive access. For a demo, see link to blog in resources.
9+
Usecase: Execute arbitrary commands through WMI classes
10+
Category: Execute
11+
Privileges: Any
12+
MitreID: T1047
13+
OperatingSystem: Windows 10, Windows 11
14+
Tags:
15+
- Application: GUI
16+
- Execute: CMD
17+
Full_Path:
18+
- Path: c:\windows\system32\wbem\wbemtest.exe
19+
Detection:
20+
- IOC: wbemtest.exe binary spawned
21+
Resources:
22+
- Link: https://saulpanders.github.io/2025/01/20/lolbas-wbemtest.html
23+
Acknowledgement:
24+
- Person: Paul Sanders
25+
Handle: '@saulpanders'

0 commit comments

Comments
 (0)