The Detection Series: Windows Management Instrumentation (Part 2) | Red Canary

Опубликовано: 07 Сентябрь 2026
на канале: Red Canary, a Zscaler company
728
19

In this installment of The Detection Series (recorded in 2021), we focus on what to look out for detecting malicious WMI tradecraft and how to investigate using Microsoft Defender for Endpoint.

Learn how attackers use WMI for lateral movement: https://redcanary.com/blog/threat-det...

Follow us:
  / redcanary  
  / redcanary  

---
Red Canary stops cyber threats no one else does, so organizations can fearlessly pursue their missions. We do it by delivering managed detection and response (MDR) across enterprise endpoints, cloud workloads, network, identities, and SaaS apps. As a security ally, we define MDR in our own terms with unlimited 24×7 support, deep threat expertise, hands-on remediation, and by doing what’s right for customers and partners.

Subscribe to our YouTube channel for frequently updated, how-to content about Atomic Red Team, threat hunting in security operations, MDR or Managed Detection and Response, and using the MITRE ATT&CK® framework.