SOP-30: Suspicious WMI / DCOM Execution Response

SOC analyst playbook for detecting and responding to lateral movement and persistence via WMI and DCOM. WmiPrvSE.exe spawning shells, wmic /node: remote execution, WMI event subscriptions, MMC20.Application DCOM abuse. KQL for Sentinel, SPL for Splunk.

2026-08-15T09:46:29.040Z
Rudra Verma, Senior Security Architect & Researcher