Catalog LOLBAS

LOL · Binary

Mofcomp.exe

1 technique WindowsLOLBAS GPL-3.0

Execute

Execution Windows

Abuse of mofcomp.exe to parse a file which contains MOF statements in order create new classes as part of the WMI repository

Use Threat actors can use mofcomp.exe to register a malicious MOF file as a new class in the WMI repository

mofcomp.exe {PATH_ABSOLUTE:.mof}
Context
user
Native
Execute
MITRE
T1047
Detection
IOC: strange parent processes spawning mofcomp.exe like cmd.exe or powershell.exe