Sigma Rule Library

MITRE ATT&CK technique

Windows Management Instrumentation detection rulesT1047

Windows Management Instrumentation (T1047) is a MITRE ATT&CK technique in the Execution tactic. This page lists the 52 community-maintained Sigma detection rules in the library mapped to T1047 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, rpc_firewall, zeek.

Top products

Tactic