WMI Event Subscription

 Original Source: [Sigma source]
Title: WMI Event Subscription
Status: test
Description:Detects creation of WMI event subscription persistence method
References:
  -https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon#event-id-19-wmievent-wmieventfilter-activity-detected
  -https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon#event-id-20-wmievent-wmieventconsumer-activity-detected
  -https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon#event-id-21-wmievent-wmieventconsumertofilter-activity-detected
Author: Tom Ueltschi (@c_APT_ure)
Date: 2019-01-12
modified:2021-11-27
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1546.003'
Logsource:
  • product: windows
  • category: wmi_event
Detection:
  selection:
    EventID:
      -'19'
      -'20'
      -'21'

  condition:selection
Falsepositives:
  -Exclude legitimate (vetted) use of WMI event subscription in your network
Level: medium