← Back to Feed

The Detection Gap: MITRE ATT&CK T1047

September 10, 2026 · Broadcom (Symantec) · Severity: MEDIUM

Broadcom/Symantec examines the detection gap in MITRE ATT&CK technique T1047, which covers Windows Management Instrumentation (WMI) for execution. The report highlights how many organizations fail to detect WMI-based attacks despite their prevalence in ransomware and APT campaigns.

Key Takeaways

  • Broadcom analyzes detection gap in MITRE ATT&CK T1047
  • WMI-based attacks under-detected despite prevalence
  • Recommendations for improving WMI detection coverage
☕ Buy a Coffee