WMI Abuse for Code Execution via WMIC

This rule detects the use of wmic.exe to execute commands or manage remote systems, specifically flagging indicators of lateral movement, credential usage, or command execution like 'node', 'user', 'password', and 'call create'.