WMI Abuse for Code Execution via WMIC
This rule detects the use of wmic.exe to execute commands or manage remote systems, specifically flagging indicators of lateral movement, credential usage, or command execution like 'node', 'user', 'password', and 'call create'.
Microsoft Sentinel (KQL)

