detecting-wmi-persistence skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. Detect WMI event subscription persistence (MITRE T1546.003) by analyzing Sysmon Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/detecting-wmi-persistence/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-wmi-persistence, or copy the skill folder into ~/.claude/skills/detecting-wmi-persistence/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/detecting-wmi-persistence/SKILL.md

SKILL.md (verbatim)

name: detecting-wmi-persistence
description: Detect WMI event subscription persistence (MITRE T1546.003) by analyzing Sysmon
  Event IDs 19, 20, and 21 for malicious EventFilter, EventConsumer, and FilterToConsumerBinding
  creation, cross-referenced against root\subscription namespace contents and Sysinternals
  Autoruns. Use when hunting WMI-based persistence, triaging a Sysmon alert on these event
  IDs, or during incident response and purple-team validation of WMI defenses.
domain: cybersecurity
subdomain: threat-hunting
tags:
- threat-hunting
- wmi
- persistence
- sysmon
- t1546.003
- mitre-attack
- windows
- dfir
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Application Protocol Command Analysis
- Network Isolation
- Network Traffic Analysis
- Client-server Payload Profiling
- Platform Monitoring
nist_csf:
- DE.CM-01
- DE.AE-02
- DE.AE-07
- ID.RA-05
mitre_attack:
- T1546.003
- T1047
- T1059.001

Detecting WMI Persistence

When to Use

  • When hunting for WMI event subscription persistence (MITRE ATT&CK T1546.003)
  • After detecting suspicious WMI activity in endpoint telemetry
  • During incident response to identify attacker persistence mechanisms
  • When Sysmon alerts trigger on Event IDs 19, 20, or 21
  • During purple team exercises testing WMI-based persistence

Prerequisites

  • Sysmon v6.1+ deployed with WMI event logging enabled (Event IDs 19, 20, 21)
  • Windows Security Event Log forwarding configured
  • SIEM with Sysmon data ingested (Splunk, Elastic, Sentinel)
  • PowerShell access for WMI enumeration on endpoints
  • Sysinternals Autoruns for manual WMI subscription review

Workflow

  1. Collect Telemetry: Parse Sysmon Event IDs 19 (WmiEventFilter), 20 (WmiEventConsumer), 21 (WmiEventConsumerToFilter).
  2. Identify Suspicious Consumers: Flag CommandLineEventConsumer and ActiveScriptEventConsumer types executing code.
  3. Analyze Event Filters: Examine WQL queries in EventFilters for process start triggers or timer-based execution.
  4. Correlate Bindings: Match FilterToConsumerBindings linking suspicious filters to consumers.
  5. Check Persistence Locations: Query WMI namespaces root\subscription and root\default for active subscriptions.
  6. Validate Findings: Cross-reference with known-good WMI subscriptions (SCCM, AV products).
  7. Document and Remediate: Remove malicious subscriptions and update detection rules.

Key Concepts

Concept Description
Sysmon Event 19 WmiEventFilter creation detected
Sysmon Event 20 WmiEventConsumer creation detected
Sysmon Event 21 WmiEventConsumerToFilter binding detected
T1546.003 Event Triggered Execution: WMI Event Subscription
CommandLineEventConsumer Executes system commands when filter triggers
ActiveScriptEventConsumer Runs VBScript/JScript when filter triggers

Tools & Systems

Tool Purpose
Sysmon Windows event monitoring for WMI activity
WMI Explorer GUI tool for browsing WMI namespaces
Autoruns Sysinternals tool listing persistence mechanisms
PowerShell Get-WMIObject Enumerate WMI event subscriptions
Splunk SIEM analysis of Sysmon WMI events
Velociraptor Endpoint WMI artifact collection

Output Format

Hunt ID: TH-WMI-[DATE]-[SEQ]
Technique: T1546.003
Host: [Hostname]
Event Type: [EventFilter|EventConsumer|Binding]
Consumer Type: [CommandLine|ActiveScript]
WQL Query: [Filter query text]
Command: [Executed command or script]
Risk Level: [Critical/High/Medium/Low]
Recommended Action: [Remove subscription, investigate lateral movement]

Other files in this skill

references/api-reference.md (verbatim)

WMI Persistence Detection Reference

Sysmon Event IDs

Event ID Type Description
19 WmiEventFilter Logs WMI EventFilter creation with WQL query
20 WmiEventConsumer Logs WMI EventConsumer creation (command/script)
21 WmiEventConsumerToFilter Logs binding of EventFilter to EventConsumer

Sysmon Configuration

Enable WMI event logging in sysmonconfig.xml:

<RuleGroup groupRelation="or">
  <WmiEvent onmatch="include">
    <Operation condition="is">Created</Operation>
  </WmiEvent>
</RuleGroup>

Install: sysmon64.exe -accepteula -i sysmonconfig.xml

PowerShell WMI Enumeration

# List all EventFilters
Get-WmiObject -Namespace root\subscription -Class __EventFilter

# List all EventConsumers
Get-WmiObject -Namespace root\subscription -Class __EventConsumer

# List all Bindings
Get-WmiObject -Namespace root\subscription -Class __FilterToConsumerBinding

# Remove specific subscription
Get-WmiObject -Namespace root\subscription -Class __EventFilter -Filter "Name='MalFilter'" | Remove-WmiObject
Get-WmiObject -Namespace root\subscription -Class CommandLineEventConsumer -Filter "Name='MalConsumer'" | Remove-WmiObject
Get-WmiObject -Namespace root\subscription -Class __FilterToConsumerBinding | Where-Object {$_.Filter -like '*MalFilter*'} | Remove-WmiObject

Suspicious Consumer Types

Consumer Class Risk Description
CommandLineEventConsumer Critical Executes arbitrary system commands
ActiveScriptEventConsumer Critical Runs embedded VBScript or JScript
LogFileEventConsumer Low Writes to log file
NTEventLogEventConsumer Low Creates Windows event log entry
SMTPEventConsumer Medium Sends email notification

Splunk Detection Query

index=sysmon EventCode IN (19, 20, 21)
| eval event_type=case(EventCode=19, "EventFilter", EventCode=20, "EventConsumer", EventCode=21, "Binding")
| where Consumer_Type IN ("CommandLineEventConsumer", "ActiveScriptEventConsumer")
| stats count by Computer, event_type, Consumer_Type, Destination, User
| where count > 0

Elastic Detection Rule

{
  "rule": {
    "name": "WMI Persistence via Event Subscription",
    "query": "event.code:(\"19\" OR \"20\" OR \"21\") AND winlog.event_data.EventType:\"WmiConsumerEvent\" AND winlog.event_data.Type:(\"CommandLineEventConsumer\" OR \"ActiveScriptEventConsumer\")",
    "severity": "high",
    "risk_score": 73,
    "tags": ["ATT&CK T1546.003"]
  }
}

MITRE ATT&CK Mapping

  • Technique: T1546.003 - Event Triggered Execution: WMI Event Subscription
  • Tactic: Persistence, Privilege Escalation
  • Data Sources: WMI Objects (WMI Creation), Command Execution, Process Creation

Autoruns WMI Tab

autorunsc64.exe -accepteula -w -nobanner -c

Output includes WMI subscriptions under "WMI" category with filter name, consumer, and command details.

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.