SkillAgentSearch skills...

WMIProcessWatcher

A CIA tradecraft technique to asynchronously detect when a process is created using WMI.

Install / Use

/learn @hackerhouse-opensource/WMIProcessWatcher
About this skill

Quality Score

0/100

Supported Platforms

Universal

README

WMIProcessWatcher

This is the Central Intelligence Agency (CIA) Applied Engineering Department (AED) WMI Process Watcher tradecraft, re-created from the Vault7 description. It observes events for newly created processes using WMI as an alternative stealthy way to enumerate running processes.

License

These files are available under the 3-clause BSD license.

Related Skills

View on GitHub
GitHub Stars138
CategoryDevelopment
Updated1d ago
Forks31

Languages

C++

Security Score

95/100

Audited on Mar 30, 2026

No findings