Prefer hash-based or publisher-based deny rules when possible.
You can use PowerShell command:
New-CIPolicyRule -FilePath "C:\Windows\System32\wmic.exe" -Deny
After deploying via Intune, use this on a client to verify what policy is applied:
Get-WdacPolicy -PolicyType Base | Format-List