WMI
File Location:
Network Connections:
Audit Logs:
WMI Persistence:



Remote WMIC Evidence:






Last updated









Last updated
Microsoft-Windows-WMI-Activity/Operational###Command Used####
> wmic /USER:pekora /node:shuba process call create "cmd.exe"> wevtutil.exe sl Microsoft-Windows-WMI-Activity/Trace /e:true