Kaspersky Anti Targeted Attack Platform

Information about the "WMI" event

The window displaying information about WMI events contains the following details:

  • Tree of events.
  • Actions that can be performed to handle an event.

    Depending on the type of the operation, one of the following section names is displayed in the event information:

    • WMI activity
    • WMI event consumer name

    The WMI activity section displays the following information:

    • IOA tags—Information about the results of file analysis using the Targeted Attack Analyzer technology: name of the TAA (IOA) rule that was used to create the alert.

      Click the link to display information about the TAA (IOA) rule. If the rule was provided by Kaspersky experts, it contains information about the triggered

      as well as recommendations for reacting to the event.

      The field is displayed if a TAA (IOA) rule was triggered when the event was created.

    • Connection to remote host—Remote start of the WMI service. If the service was started remotely, the field displays Yes.
    • Machine name—Name of the host on which the WMI service was started.
    • User name—Name of the user that started the WMI service.
    • Namespace—WMI namespace.
    • Query—Command that was used to start the WMI service.

    The WMI activity section displays the following information:

    • Connection to remote host—Remote start of the WMI service. If the service was started remotely, the field displays Yes.
    • Namespace—Namespace of the event consumer.
    • Event filter name—Name of the filter of the event consumer. This field is displayed for the WMI activity event type.
    • Event consumer name—Name of the created event consumer.
    • Event consumer description—Description of the created event consumer. This field is displayed for the WMI event consumer name event type.
  • Event initiator section:
    • File—Name of the parent process file.
    • Launch parameters—Parent process startup settings.
    • MD5—MD5 hash of the parent process file.
    • SHA256—SHA256 hash of the parent process file.
  • System info section:
    • Host name—Name of the host on which the WMI service was started or the event consumer was created.
    • Host IP—IP address of the host on which the WMI service was started or the event consumer was created.
    • User name—Name of the user that started the WMI service or created the event consumer.
    • OS version—Version of the operating system that is being used on the host.