Potentially Suspicious Mofcomp Execution
Detects execution of the "mofcomp" utility as a child of a suspicious shell or script running utility or by having a suspicious path in the commandline. The "mofcomp" utility parses a file containing MOF statements and adds the classes and class instances defined in the file to the WMI repository. Attackers abuse this utility to install malicious MOF scripts
Detection logic
selection_img
- Image|endswith: \mofcomp.exe
- OriginalFileName: mofcomp.exeselection_case
- ParentImage|endswith:
- \cmd.exe
- \powershell.exe
- \pwsh.exe
- \wsl.exe
- \wscript.exe
- \cscript.exe
- CommandLine|contains:
- \AppData\Local\Temp
- \Contacts\
- \Favorites\
- \Favourites\
- \Music\
- \Pictures\
- \Users\Public\
- \Videos\
- \WINDOWS\Temp\
- "%appdata%"
- "%temp%"
- "%tmp%"filter_main_wmiprvse
ParentImage: C:\Windows\System32\wbem\WmiPrvSE.exe
CommandLine|contains: C:\Windows\TEMP\
CommandLine|endswith: .moffilter_main_installutil
ParentCommandLine|endswith: \InstallUtil.exe /Uninstall C:\Windows\CCM\Microsoft.ConfigurationManager.SVProvider.dll
ParentImage|endswith: \InstallUtil.exe
CommandLine|contains|all:
- C:\Windows\TEMP
- .tmpfilter_optional_null_parent
ParentCommandLine: nullCondition
all of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*Raw YAML
title: Potentially Suspicious Mofcomp Execution
id: 1dd05363-104e-4b4a-b963-196a534b03a1
status: test
description: |
Detects execution of the "mofcomp" utility as a child of a suspicious shell or script running utility or by having a suspicious path in the commandline.
The "mofcomp" utility parses a file containing MOF statements and adds the classes and class instances defined in the file to the WMI repository.
Attackers abuse this utility to install malicious MOF scripts
references:
- https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/
- https://github.com/The-DFIR-Report/Sigma-Rules/blob/75260568a7ffe61b2458ca05f6f25914efb44337/win_mofcomp_execution.yml
- https://learn.microsoft.com/en-us/windows/win32/wmisdk/mofcomp
author: Nasreddine Bencherchali (Nextron Systems)
date: 2022-07-12
modified: 2026-08-06
tags:
- attack.stealth
- attack.t1218
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: '\mofcomp.exe'
- OriginalFileName: 'mofcomp.exe'
selection_case:
- ParentImage|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\wsl.exe'
- '\wscript.exe'
- '\cscript.exe'
- CommandLine|contains:
- '\AppData\Local\Temp'
- '\Contacts\'
- '\Favorites\'
- '\Favourites\'
- '\Music\'
- '\Pictures\'
- '\Users\Public\'
- '\Videos\'
- '\WINDOWS\Temp\'
- '%appdata%'
- '%temp%'
- '%tmp%'
filter_main_wmiprvse:
ParentImage: 'C:\Windows\System32\wbem\WmiPrvSE.exe'
CommandLine|contains: 'C:\Windows\TEMP\'
CommandLine|endswith: '.mof'
filter_main_installutil:
ParentCommandLine|endswith: '\InstallUtil.exe /Uninstall C:\Windows\CCM\Microsoft.ConfigurationManager.SVProvider.dll'
ParentImage|endswith: '\InstallUtil.exe'
CommandLine|contains|all:
- 'C:\Windows\TEMP'
- '.tmp'
filter_optional_null_parent:
ParentCommandLine: null
condition: all of selection_* and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Unknown
level: highFalse positives
- Unknown