Detecting WMI Exploitation

Detecting WMI Exploitation

via YouTube Direct link

Remote WMI Execution

15 of 28

15 of 28

Remote WMI Execution

Class Central Classrooms beta

YouTube videos curated by Class Central.

Classroom Contents

Detecting WMI Exploitation

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Whoami
  2. 2 Why care about WMI?
  3. 3 What is WMI
  4. 4 Where does WMI live?
  5. 5 Windows Sysinternals AutoRuns
  6. 6 Windows Sysinternals Sysmon
  7. 7 Do you have a tool that...
  8. 8 WMI PWNAGE TOOLS
  9. 9 Process Execution
  10. 10 Process Command Line tells all
  11. 11 WMI Activity
  12. 12 Authentication
  13. 13 Parent-Child Processes
  14. 14 Lateral Movement - Push Payloads
  15. 15 Remote WMI Execution
  16. 16 WMI Service Starting
  17. 17 Details - Sysmon is an option
  18. 18 Details - Windows Logging Service WLS
  19. 19 PowerShell
  20. 20 How do I Hunt for PS?
  21. 21 WMI Tools
  22. 22 WMIC Use
  23. 23 Hunting for WMI Pwnage
  24. 24 Recommendations
  25. 25 Monitor WMI
  26. 26 Conclusion
  27. 27 Additional Reading
  28. 28 Questions

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.