SOP-30: Suspicious WMI / DCOM Execution Response
SOC analyst playbook for detecting and responding to lateral movement and persistence via WMI and DCOM. WmiPrvSE.exe spawning shells, wmic /node: remote execution, WMI event subscriptions, MMC20.Application DCOM abuse. KQL for Sentinel, SPL for Splunk.
Rudra Verma, Senior Security Architect & Researcher