Microsoft Office file execution via WMI
Identifies the execution via Windows Management Instrumentation (WMI) of the binary file written by the Microsoft Office process. Attackers can exploit WMI to silently execute malicious code.
- Platform: Windows
- Severity: High
- MITRE Tactic: Initial Access
- MITRE Techniques: T1566, T1566.001