cuckoosandbox / community

Repository of modules and signatures contributed by the community
323 stars 175 forks source link

Added signature that hits on when winmgmts is used #479

Closed cccs-kevin closed 2 years ago

cccs-kevin commented 4 years ago

As per https://docs.microsoft.com/en-us/windows/win32/wmisdk/connecting-to-wmi-with-vbscript, this is a sys admin toolkit who's use is suspicious.