Powershell WMI Persistence — Detection Rule

Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription.

Read the full analysis on IntelFusions