[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f8F22aQ2BlC4ut4QDw6wisIzRl1u1aXTdsk3PX5Kjcpo":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":52,"_status":50},91,"What is wbemtest and how does it relate to wmic commands?","wbemtest is a GUI tool installed by default on Windows that allows you to connect to WMI namespaces and interact with WMI objects. It can enumerate classes, execute queries using WQL, and invoke methods. The operations performed in wbemtest can be directly translated into wmic commands; for example, invoking the `Create` method of `Win32_Process` in wbemtest corresponds to `wmic process call create \"calc\"`. For more details, see the [Penetration Basics - Usage of WMIC](\u002Fnews\u002Fpenetration-basics-usage-of-wmic) article.","\u003Cp>wbemtest is a GUI tool installed by default on Windows that allows you to connect to WMI namespaces and interact with WMI objects. It can enumerate classes, execute queries using WQL, and invoke methods. The operations performed in wbemtest can be directly translated into wmic commands; for example, invoking the `Create` method of `Win32_Process` in wbemtest corresponds to `wmic process call create &quot;calc&quot;`. For more details, see the [Penetration Basics - Usage of WMIC](\u002Fnews\u002Fpenetration-basics-usage-of-wmic) article.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-usage-of-wmic\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-wbemtest-and-how-does-it-relate-to-wmic-commands-1777485297366","wbemtest, WMI, wmic, WQL, Win32_Process",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},24,"Penetration Basics - Usage of WMIC","penetration-basics-usage-of-wmic","Learn WMIC basics for penetration testing: info gathering, lateral movement, remote access, and defense tips using wbemtest and wmic commands.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>WMI (Windows Management Instrumentation) is a management feature that provides a unified environment for accessing Windows system components, supporting both local and remote access. Previous articles such as \"WMI Attacks,\" \"WMI Backdoor,\" \"WMI Defense,\" and \"Study Notes of WMI Persistence using wmic.exe\" have covered related content. This article will analyze common methods of wmic from the perspectives of information gathering and lateral movement, combining exploitation ideas to provide defense recommendations.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Usage of wbemtest\u003C\u002Fli>\u003Cli>Querying host information via wmic\u003C\u002Fli>\u003Cli>Modifying the registry via wmic\u003C\u002Fli>\u003Cli>Executing programs via wmic\u003C\u002Fli>\u003Cli>Local and remote access to WMI services\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Usage of wbemtest\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fmem\u002Fconfigmgr\u002Fdevelop\u002Fcore\u002Funderstand\u002Fintroduction-to-wbemtest\u003C\u002Fp>\u003Cp>Installed by default on Windows systems, it can be used to connect to WMI namespaces and access WMI services.\u003C\u002Fp>\u003Cp>With wbemtest, we can obtain complete functional details and usage methods of WMI.\u003C\u002Fp>\u003Cp>The interface is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019788722_0_cc9f37aa13.jpeg\">\u003C\u002Fp>\u003Cp>Click Connect..., enter the WMI namespace root\\cimv2, and after connecting to root\\cimv2, you can enter the main page, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019799047_1_4264315814.jpeg\">\u003C\u002Fp>\u003Cp>Common function examples are as follows:\u003C\u002Fp>\u003Ch4>(1) Enum Classes...\u003C\u002Fh4>\u003Cp>Enumerate classes, which can be used to enumerate all objects and query the definition of each class.\u003C\u002Fp>\u003Cp>Here, taking the query of the Win32_Process object as an example:\u003C\u002Fp>\u003Cp>Select Enum Classes... -&gt; Recursive -&gt; OK in sequence, select Win32_Process, double-click to enter the object editor, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019811822_2_da0f70868e.jpeg\">\u003C\u002Fp>\u003Cp>The Properties bar can be used to view properties, for example, here is Handle, which can be queried via Query... mentioned later.\u003C\u002Fp>\u003Cp>The Methods bar can be used to view methods, for example, here is Create, which can be invoked via Execute Method... mentioned later.\u003C\u002Fp>\u003Ch4>(2)Query...\u003C\u002Fh4>\u003Cp>Query attributes, requires input of WMI Query Language (WQL)\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fwmisdk\u002Fwql-sql-for-wmi\u003C\u002Fp>\u003Cp>Syntax example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SELECT Handle FROM Win32_Process\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019822691_3_c4185450d3.jpeg\">\u003C\u002Fp>\u003Cp>This query statement converted to wmic command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnamespace:\"\\\\root\\cimv2\" PATH Win32_Process get Handle\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3)Execute Method...\u003C\u002Fh4>\u003Cp>Invoke method, here taking the Create method of the Win32_Process object as an example\u003C\u002Fp>\u003Cp>Set Object Path to Win32_Process, click OK\u003C\u002Fp>\u003Cp>In the pop-up interface, set Method to Create\u003C\u002Fp>\u003Cp>Click Edit in Parameters..., in the pop-up interface, sequentially select CommandLine -&gt; Edit Property\u003C\u002Fp>\u003Cp>Set Valve to calc, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019832496_4_fad1c4f95d.jpeg\">\u003C\u002Fp>\u003Cp>Click Save Object -&gt; Execute! to pop up the calculator\u003C\u002Fp>\u003Cp>The complete command replaced with wmic is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnamespace:\"\\\\root\\cimv2\" PATH Win32_Process call create \"calc\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The abbreviated command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic process call create \"calc\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Local and Remote Access to WMI Services\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Query Host Name\u003C\u002Fh3>\u003Cp>Local:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnamespace:\"\\\\root\\cimv2\" PATH Win32_ComputerSystem get Name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remote:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnode:192.168.1.1 \u002Fuser:\"administrator\" \u002Fpassword:\"123456\" \u002Fnamespace:\"\\\\root\\cimv2\" PATH Win32_ComputerSystem get Name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Registry Operations\u003C\u002Fh3>\u003Cp>For specific details, please refer to \"Study Notes of WMI Persistence using wmic.exe\".\u003C\u002Fp>\u003Cp>Here are several commonly used commands:\u003C\u002Fp>\u003Ch4>(1) Retrieve the remote desktop connection history of the current user\u003C\u002Fh4>\u003Cp>Enumerate the registry key value HKCU:\\Software\\Microsoft\\Terminal Server Client\\Servers, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnamespace:\"\\\\root\\cimv2\" path stdregprov call EnumKey ^&amp;h80000001,\"Software\\Microsoft\\Terminal Server Client\\Servers\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Remotely query and modify Restricted Admin Mode\u003C\u002Fh4>\u003Cp>For content related to Restricted Admin Mode, please refer to \"Penetration Techniques – Pass the Hash with Remote Desktop (Restricted Admin mode)\".\u003C\u002Fp>\u003Cp>For C Sharp implementation of remotely querying and modifying Restricted Admin Mode, please refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FGhostPack\u002FRestrictedAdmin\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fairzero24\u002FWMIReg\u003C\u002Fp>\u003Cp>The wmic command for remotely querying Restricted Admin Mode is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnode:192.168.1.1 \u002Fuser:\"administrator\" \u002Fpassword:\"123456\" \u002Fnamespace:\"\\\\root\\cimv2\" path stdregprov call GetDWORDValue ^&amp;H80000002,\"System\\CurrentControlSet\\Control\\Lsa\",\"DisableRestrictedAdmin\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The wmic command for remotely enabling Restricted Admin Mode is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnode:192.168.1.1 \u002Fuser:\"administrator\" \u002Fpassword:\"123456\" \u002Fnamespace:\"\\\\root\\cimv2\" path stdregprov call SetDWORDValue ^&amp;H80000002,\"System\\CurrentControlSet\\Control\\Lsa\",\"DisableRestrictedAdmin\",\"0\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The wmic command for remotely disabling Restricted Admin Mode is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnode:192.168.1.1 \u002Fuser:\"administrator\" \u002Fpassword:\"123456\" \u002Fnamespace:\"\\\\root\\cimv2\" path stdregprov call SetDWORDValue ^&amp;H80000002,\"System\\CurrentControlSet\\Control\\Lsa\",\"DisableRestrictedAdmin\",\"1\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Execute Program\u003C\u002Fh3>\u003Cp>Local:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic process call create \"calc\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remote:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnode:192.168.1.1 \u002Fuser:\"administrator\" \u002Fpassword:\"123456\" process call create \"calc\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Process Operations\u003C\u002Fh3>\u003Cp>Query all local processes:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnamespace:\"\\\\root\\cimv2\" PATH Win32_Process get name,processid,commandline \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query all remote host processes:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnode:192.168.1.1 \u002Fuser:\"administrator\" \u002Fpassword:\"123456\" \u002Fnamespace:\"\\\\root\\cimv2\" PATH Win32_Process get name,processid,commandline \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Other usage can also refer to: https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Farchive\u002Fblogs\u002Fjhoward\u002Fwmic-samples\u003C\u002Fp>\u003Ch2>0x04 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>It should be noted that WMI logging is minimal by default and cannot record command details of WMI.\u003C\u002Fp>\u003Cp>WMI-Activity trace logs can record basic logs but cannot capture WMI command details. The enabling method is as follows:\u003C\u002Fp>\u003Cp>Open Event Viewer, select View -&gt; Show Analytic and Debug Logs\u003C\u002Fp>\u003Cp>Navigate to Applications and Services Logs -&gt; Microsoft -&gt; Windows -&gt; WMI-Activity -&gt; Trace, then click Enable Log\u003C\u002Fp>\u003Cp>When using the wmic command, the default process c:\\windows\\system32\\wbem\\wmic.exe is launched. Sysmon can be chosen here to record process creation details, allowing inspection of CommandLine to obtain WMI command specifics\u003C\u002Fp>\u003Cp>For detailed log information, refer to: https:\u002F\u002Fjpcertcc.github.io\u002FToolAnalysisResultSheet\u002Fdetails\u002Fwmic.htm\u003C\u002Fp>\u003Cp>Alternatively, the open-source digital forensics tool Velociraptor can be used to record process creation details, including CommandLine\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces fundamental knowledge of wmic, combines exploitation approaches, and provides defense recommendations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>WMI (Windows Management Instrumentation) is a management feature that provides a unified environment for accessing Windows system components, supporting both local and remote access. Previous articles such as \"WMI Attacks,\" \"WMI Backdoor,\" \"WMI Defense,\" and \"Study Notes of WMI Persistence using wmic.exe\" have covered related content. This article will analyze common methods of wmic from the perspectives of information gathering and lateral movement, combining exploitation ideas to provide defense recommendations.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Usage of wbemtest\u003C\u002Fli>\u003Cli>Querying host information via wmic\u003C\u002Fli>\u003Cli>Modifying the registry via wmic\u003C\u002Fli>\u003Cli>Executing programs via wmic\u003C\u002Fli>\u003Cli>Local and remote access to WMI services\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Usage of wbemtest\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fmem\u002Fconfigmgr\u002Fdevelop\u002Fcore\u002Funderstand\u002Fintroduction-to-wbemtest\u003C\u002Fp>\u003Cp>Installed by default on Windows systems, it can be used to connect to WMI namespaces and access WMI services.\u003C\u002Fp>\u003Cp>With wbemtest, we can obtain complete functional details and usage methods of WMI.\u003C\u002Fp>\u003Cp>The interface is shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019788722_0_cc9f37aa13-1.jpeg\">\u003C\u002Fp>\u003Cp>Click Connect..., enter the WMI namespace root\\cimv2, and after connecting to root\\cimv2, you can enter the main page, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019799047_1_4264315814-1.jpeg\">\u003C\u002Fp>\u003Cp>Common function examples are as follows:\u003C\u002Fp>\u003Ch4>(1) Enum Classes...\u003C\u002Fh4>\u003Cp>Enumerate classes, which can be used to enumerate all objects and query the definition of each class.\u003C\u002Fp>\u003Cp>Here, taking the query of the Win32_Process object as an example:\u003C\u002Fp>\u003Cp>Select Enum Classes... -&gt; Recursive -&gt; OK in sequence, select Win32_Process, double-click to enter the object editor, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019811822_2_da0f70868e-1.jpeg\">\u003C\u002Fp>\u003Cp>The Properties bar can be used to view properties, for example, here is Handle, which can be queried via Query... mentioned later.\u003C\u002Fp>\u003Cp>The Methods bar can be used to view methods, for example, here is Create, which can be invoked via Execute Method... mentioned later.\u003C\u002Fp>\u003Ch4>(2)Query...\u003C\u002Fh4>\u003Cp>Query attributes, requires input of WMI Query Language (WQL)\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fwmisdk\u002Fwql-sql-for-wmi\u003C\u002Fp>\u003Cp>Syntax example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>SELECT Handle FROM Win32_Process\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019822691_3_c4185450d3-1.jpeg\">\u003C\u002Fp>\u003Cp>This query statement converted to wmic command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnamespace:\"\\\\root\\cimv2\" PATH Win32_Process get Handle\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3)Execute Method...\u003C\u002Fh4>\u003Cp>Invoke method, here taking the Create method of the Win32_Process object as an example\u003C\u002Fp>\u003Cp>Set Object Path to Win32_Process, click OK\u003C\u002Fp>\u003Cp>In the pop-up interface, set Method to Create\u003C\u002Fp>\u003Cp>Click Edit in Parameters..., in the pop-up interface, sequentially select CommandLine -&gt; Edit Property\u003C\u002Fp>\u003Cp>Set Valve to calc, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019832496_4_fad1c4f95d-1.jpeg\">\u003C\u002Fp>\u003Cp>Click Save Object -&gt; Execute! to pop up the calculator\u003C\u002Fp>\u003Cp>The complete command replaced with wmic is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnamespace:\"\\\\root\\cimv2\" PATH Win32_Process call create \"calc\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The abbreviated command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic process call create \"calc\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Local and Remote Access to WMI Services\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Query Host Name\u003C\u002Fh3>\u003Cp>Local:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnamespace:\"\\\\root\\cimv2\" PATH Win32_ComputerSystem get Name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remote:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnode:192.168.1.1 \u002Fuser:\"administrator\" \u002Fpassword:\"123456\" \u002Fnamespace:\"\\\\root\\cimv2\" PATH Win32_ComputerSystem get Name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Registry Operations\u003C\u002Fh3>\u003Cp>For specific details, please refer to \"Study Notes of WMI Persistence using wmic.exe\".\u003C\u002Fp>\u003Cp>Here are several commonly used commands:\u003C\u002Fp>\u003Ch4>(1) Retrieve the remote desktop connection history of the current user\u003C\u002Fh4>\u003Cp>Enumerate the registry key value HKCU:\\Software\\Microsoft\\Terminal Server Client\\Servers, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnamespace:\"\\\\root\\cimv2\" path stdregprov call EnumKey ^&amp;h80000001,\"Software\\Microsoft\\Terminal Server Client\\Servers\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Remotely query and modify Restricted Admin Mode\u003C\u002Fh4>\u003Cp>For content related to Restricted Admin Mode, please refer to \"Penetration Techniques – Pass the Hash with Remote Desktop (Restricted Admin mode)\".\u003C\u002Fp>\u003Cp>For C Sharp implementation of remotely querying and modifying Restricted Admin Mode, please refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FGhostPack\u002FRestrictedAdmin\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fairzero24\u002FWMIReg\u003C\u002Fp>\u003Cp>The wmic command for remotely querying Restricted Admin Mode is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnode:192.168.1.1 \u002Fuser:\"administrator\" \u002Fpassword:\"123456\" \u002Fnamespace:\"\\\\root\\cimv2\" path stdregprov call GetDWORDValue ^&amp;H80000002,\"System\\CurrentControlSet\\Control\\Lsa\",\"DisableRestrictedAdmin\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The wmic command for remotely enabling Restricted Admin Mode is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnode:192.168.1.1 \u002Fuser:\"administrator\" \u002Fpassword:\"123456\" \u002Fnamespace:\"\\\\root\\cimv2\" path stdregprov call SetDWORDValue ^&amp;H80000002,\"System\\CurrentControlSet\\Control\\Lsa\",\"DisableRestrictedAdmin\",\"0\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The wmic command for remotely disabling Restricted Admin Mode is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnode:192.168.1.1 \u002Fuser:\"administrator\" \u002Fpassword:\"123456\" \u002Fnamespace:\"\\\\root\\cimv2\" path stdregprov call SetDWORDValue ^&amp;H80000002,\"System\\CurrentControlSet\\Control\\Lsa\",\"DisableRestrictedAdmin\",\"1\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Execute Program\u003C\u002Fh3>\u003Cp>Local:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic process call create \"calc\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Remote:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnode:192.168.1.1 \u002Fuser:\"administrator\" \u002Fpassword:\"123456\" process call create \"calc\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Process Operations\u003C\u002Fh3>\u003Cp>Query all local processes:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnamespace:\"\\\\root\\cimv2\" PATH Win32_Process get name,processid,commandline \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query all remote host processes:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wmic \u002Fnode:192.168.1.1 \u002Fuser:\"administrator\" \u002Fpassword:\"123456\" \u002Fnamespace:\"\\\\root\\cimv2\" PATH Win32_Process get name,processid,commandline \u002FFORMAT:list\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Other usage can also refer to: https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Farchive\u002Fblogs\u002Fjhoward\u002Fwmic-samples\u003C\u002Fp>\u003Ch2>0x04 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>It should be noted that WMI logging is minimal by default and cannot record command details of WMI.\u003C\u002Fp>\u003Cp>WMI-Activity trace logs can record basic logs but cannot capture WMI command details. The enabling method is as follows:\u003C\u002Fp>\u003Cp>Open Event Viewer, select View -&gt; Show Analytic and Debug Logs\u003C\u002Fp>\u003Cp>Navigate to Applications and Services Logs -&gt; Microsoft -&gt; Windows -&gt; WMI-Activity -&gt; Trace, then click Enable Log\u003C\u002Fp>\u003Cp>When using the wmic command, the default process c:\\windows\\system32\\wbem\\wmic.exe is launched. Sysmon can be chosen here to record process creation details, allowing inspection of CommandLine to obtain WMI command specifics\u003C\u002Fp>\u003Cp>For detailed log information, refer to: https:\u002F\u002Fjpcertcc.github.io\u002FToolAnalysisResultSheet\u002Fdetails\u002Fwmic.htm\u003C\u002Fp>\u003Cp>Alternatively, the open-source digital forensics tool Velociraptor can be used to record process creation details, including CommandLine\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces fundamental knowledge of wmic, combines exploitation approaches, and provides defense recommendations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1726,"Onedaysec",4,"published","2026-02-02T08:20:05.024Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"WMIC Penetration Testing: Basics, Usage, and Remote Access Techniques","WMIC, WMI, penetration testing, Windows management, remote access, wbemtest, lateral movement, registry, Win32_Process, WQL",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],94,93,92,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.492Z","2026-07-23T16:01:00.458Z","draft","2026-07-23T16:03:31.367Z","2026-07-23T16:03:31.366Z"]