> For the complete documentation index, see [llms.txt](https://f1rstbyt3.gitbook.io/hacking-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://f1rstbyt3.gitbook.io/hacking-notes/dfir/memory-analysis/windows/wmi-powershell.md).

# WMI/ PowerShell

### WMI

`WmiPrvSE.exe` is used to execute commands on a remote machine. WmiPrvSE facilitates the interface been WMI and operating system.&#x20;

WMI also will use the following Consumers:&#x20;

* `CommandLine` - cmd execution
* `ActiveScriptEventConsumer` - persistence&#x20;

When ActiveScriptEventConsumer is executed, it spawn a process called '`scrcons.exe`'  **worth digging into this process**

## PowerShell

`wsmprovhost.exe` is used to open PSRemoting sessions on the host

If '`PowerShell.exe`' is executed with a parent process of '`svchost.exe`' it is a good indicator that an admin session was spawned.&#x20;

If '`cmd.exe`' is a parent - it's worth looking at as likely code injection
