Rare fixation techniques. Part 3

More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
Rare persistence techniques. Part 3
Also read about: Zabbix Agent, TimeProvider, COM Hijacking.
4️⃣ WMICLNT
This persistence technique is based on hijacking a DLL loaded by the legitimate Windows Management Instrumentation (WMI) service, and in MITRE ATT&CK it is classified as T1546.008 (Event Triggered Execution: Accessibility Features) or as a special case of DLL Hijacking.
Attackers exploit a quirk of how the WMIC console (wmic.exe) starts up, which is a standard system administration tool. When WMIC launches, it attempts to load the wmiclnt.dll library, but this library may be absent from a standard Windows installation.
The stock wmic.exe works without it as well — functionality may be limited, but the mere fact of the load attempt allows an attacker to place their malicious library in the DLL search path.
The attacker places the malicious wmiclnt.dll in C:\Windows\System32\wbem. Any trigger convenient for the attacker can be used for activation — whether a specific scheduled task or a restart of the system service.
In the first case, a Scheduled Task is created that periodically invokes the legitimate utility (for example, wmic os get name), which leads to the DLL being loaded and malicious code executing in DllMain.
In the second case, a cyclic restart of the WMI service is used with the commands net stop winmgmt /y and net start winmgmt, which also triggers a call to the substituted library and ensures persistence.
⬇️ For successful loading and stealthy operation, the malicious wmiclnt.dll must satisfy the following conditions:
• Export functions: the malicious DLL must implement and export all the same functions that wmic.exe attempts to import (screenshot 3), so that the process does not crash with an error.
• Most often, the malicious logic executes directly in DllMain (the DLL_PROCESS_ATTACH function), as this guarantees code execution immediately after the library is loaded without the need to call specific exported procedures.
• Proxying: for maximum disguise, the malicious DLL can act as a “proxy,” forwarding calls to the real system API so that wmic.exe runs normally and does not raise suspicion.
👀 Indicators of compromise:
• The appearance of the wmiclnt.dll file in the C:\Windows\System32\wbem\ directory (in a clean system this file is absent, although it may have existed on older versions; in modern Windows 10/11 and Server 20xx the file is located in the C:\Windows\System32\ directory).
• Non-standard child processes of wmic.exe (for example, if powershell.exe or rundll32.exe with network interaction suddenly launches from under WMIC).
• Another indicator of compromise may be the Event ID 11 event (Image Load), where the "SignatureLevel": 1 field indicates an unsigned/untrusted image.
{"Event"…"EventID":11,"Version":0,"Level":0,"Task":6,"Opcode":0,"Keywords":"0x8000000000000000","TimeCreated":{"#att
ributes":{"SystemTime":"2026-02-27T10:26:15.414597Z"}},…,"Channel":"Microsoft-Windows-SecurityMitigations/KernelMode","Computer":“REDACTED","Security":{"#attributes":{"UserID":"S-1-5-
18"}}},"EventData":{"ProcessPathLength":52,"ProcessPath":"\\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe
","ProcessCommandLineLength":56,"ProcessCommandLine":"C:\\Windows\\system32\\svchost.exe -k netsvcs -p -s
Winmgmt","ProcessId":37383,"ProcessCreateTime":"2026-02-
27T10:26:15.254827Z","ProcessStartKey":19140298416383003,"ProcessSignatureLevel":0,"ProcessSectionSignatureLevel":0,
"ProcessProtection":0,"TargetThreadId":29700,"TargetThreadCreateTime":"2026-02-
25T08:24:13.276875Z","RequiredSignatureLevel":8,"SignatureLevel":1,"ImageNameLength":34,"ImageName":"\\Windows\
\System32\\wbem\\wmiclnt.dll"}}}
To be continued in the next post 🔽
#ir #dfir #tips
@ptescalator
More in General
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…



