Skip to content

Latest commit

 

History

History
16 lines (12 loc) · 338 Bytes

WMI_Notes.md

File metadata and controls

16 lines (12 loc) · 338 Bytes

Using WMIC

Some example commands to assist DFIR

Killing running processes by PID

wmic process where processid=[pid] call terminate
wmic process where processid=[pid] delete

Killing running processes by NAME

wmic process where name="evilprocess.exe" call terminate
wmic process where name="evilprocess.exe" delete