T1546.003 Windows Management Instrumentation Event Subscription — ATT&CK Technique
Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription. WMI can be used to install event filters, providers, consumers, and bindings that execute code when a defined event occurs. Examples of events that may be subscribed to are the wall clock time, user login, or the computer's uptime. Adversaries may use the capabilities of WMI to subscribe to an event and execute arbitrary code when that event occurs, providing persistence on a system. Adversaries may also compile WMI scripts – using `mofcomp.exe` –into Windows Management Object (MOF) files (.mof extension) that can be used to create a malicious subscription. WMI subscription execution is proxied by the WMI Provider Host process (WmiPrvSe.exe) and thus may result in elevated SYSTEM privileges.
Detection coverage (15)
- Potential Remote WMI ActiveScriptEventConsumers Activity medium
- WMI Persistence - Security medium
- WMI Persistence medium
- WMI Persistence - Script Event Consumer File Write high
- WMI ActiveScriptEventConsumers Activity Via Scrcons.EXE DLL Load medium
- WMI Persistence - Command Line Event Consumer high
- Powershell WMI Persistence medium
- WMI Backdoor Exchange Transport Agent critical
- New ActiveScriptEventConsumer Created Via Wmic.EXE high
- WMI Persistence - Script Event Consumer medium
- Suspicious Encoded Scripts in a WMI Consumer high
- WMI Event Subscription medium
- Detect WMI Event Subscription Persistence
- Windows MOF Event Triggered Execution via WMI
- WMI Permanent Event Subscription - Sysmon
Malware using this technique
- Sardonic
- adbupd
- BADHATCH
- HOPLIGHT
- RegDuke
- POSHSPY
- SeaDuke
- TrailBlazer
- metaMain
- Kevin
- SILENTTRINITY
- PoshC2
- POWERTON