Skip to content

Conversation

CliffordCyber
Copy link

Adding Antivirus recon LOLBAS with WMIC.exe

Adding Antivirus recon LOLBAS
MitreID: T1105
OperatingSystem: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
- Command: WMIC.exe /Namespace:\\\\root\\SecurityCenter2 Path AntiVirusProduct Get displayName,productState
Description: Executes WMIC to gather the existing Antivirus or EDR solution installed on the machine.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tiny suggestion "Executes WMIC to gather enumerate the existing Antivirus or EDR solution installed on the machine."

@josehelps
Copy link
Contributor

@CliffordCyber had a tiny wording suggestion, but otherwise looks good, happy to approve and merge either way. Let me know.

@josehelps josehelps self-assigned this Jun 29, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants