Suspicious execution via WMI from a Microsoft Office process
Identifies a suspicious process execution via Windows Management Instrumentation (WMI) originated from the Microsoft Office process loading an unusual WMI DLL. This technique can indicate code execution evading traditional parent/child processes spawned from Microsoft Office products.
- Platform: Windows
- Severity: High
- MITRE Tactic: Initial Access
- MITRE Techniques: T1566, T1566.001