← Back to Feed
The Detection Gap: MITRE ATT&CK T1047
September 10, 2026 · Broadcom (Symantec) · Severity: MEDIUM
Broadcom/Symantec examines the detection gap in MITRE ATT&CK technique T1047, which covers Windows Management Instrumentation (WMI) for execution. The report highlights how many organizations fail to detect WMI-based attacks despite their prevalence in ransomware and APT campaigns.
Key Takeaways
- Broadcom analyzes detection gap in MITRE ATT&CK T1047
- WMI-based attacks under-detected despite prevalence
- Recommendations for improving WMI detection coverage