What it does. Hunts for adversary persistence via WMI event subscriptions (MITRE T1546.003) Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill hunting-for-persistence-via-wmi-subscriptions, or copy the skill folder into ~/.claude/skills/hunting-for-persistence-via-wmi-subscriptions/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/hunting-for-persistence-via-wmi-subscriptions/SKILL.md
SKILL.md (verbatim)
name: hunting-for-persistence-via-wmi-subscriptions
description: Hunts for adversary persistence via WMI event subscriptions (MITRE T1546.003)
by monitoring the creation of WMI event filters, consumers, and filter-to-consumer
bindings that trigger malicious code execution on system events. Use when investigating
fileless, trigger-based persistence on Windows hosts or auditing WMI repository
contents for malicious event subscriptions.
domain: cybersecurity
subdomain: threat-hunting
tags:
- threat-hunting
- wmi-persistence
- mitre-t1546-003
- event-subscription
- windows
- endpoint-detection
version: '1.0'
author: mahipal
license: Apache-2.0
d3fend_techniques:
- Application Protocol Command Analysis
- Network Isolation
- Network Traffic Analysis
- Client-server Payload Profiling
- Platform Monitoring
nist_csf:
- DE.CM-01
- DE.AE-02
- DE.AE-07
- ID.RA-05
mitre_attack:
- T1046
- T1057
- T1082
- T1083
- T1547
Hunting for Persistence via WMI Subscriptions
When to Use
- When proactively searching for fileless persistence mechanisms in Windows environments
- After threat intelligence reports indicate WMI-based persistence by APT groups (APT29, APT32, FIN8)
- When investigating systems where malware persists across reboots despite cleanup attempts
- During incident response when standard persistence locations (Run keys, scheduled tasks) are clean
- When WmiPrvSe.exe is observed spawning unexpected child processes
Prerequisites
- Sysmon Event ID 19, 20, 21 (WMI Event Filter/Consumer/Binding) enabled
- Windows Event ID 5861 (WMI activity logging) from Microsoft-Windows-WMI-Activity
- PowerShell logging enabled (Script Block Logging, Module Logging)
- WMI repository access for enumeration
- SIEM platform for event correlation
Workflow
- Enumerate Existing WMI Subscriptions: Query all permanent WMI event subscriptions on target systems. A clean system typically has very few or zero permanent subscriptions, making anomalies easy to spot.
- Monitor WMI Event Creation (Sysmon 19/20/21): Sysmon Event 19 captures WmiEventFilter activity, Event 20 captures WmiEventConsumer activity, and Event 21 captures WmiEventConsumerToFilter binding.
- Analyze Consumer Types: Focus on ActiveScriptEventConsumer (runs VBScript/JScript) and CommandLineEventConsumer (executes commands) -- these are the dangerous types used for persistence.
- Check Event Filter Triggers: Examine what triggers the subscription. Common malicious triggers include system startup (Win32_ProcessStartTrace), user logon, or timer-based execution intervals.
- Investigate WmiPrvSe.exe Child Processes: When a WMI subscription fires, the action is executed by WmiPrvSe.exe. Hunt for unusual child processes of WmiPrvSe.exe.
- Correlate with MOF Compilation: Detect
mofcomp.exe usage which compiles MOF files to create WMI subscriptions programmatically.
- Validate and Respond: Confirm malicious subscriptions, remove them, and trace back to the initial infection vector.
Key Concepts
| Concept |
Description |
| T1546.003 |
Event Triggered Execution: WMI Event Subscription |
| __EventFilter |
WMI class defining the trigger condition |
| __EventConsumer |
WMI class defining the action to perform |
| __FilterToConsumerBinding |
Links a filter to a consumer |
| ActiveScriptEventConsumer |
Consumer that runs VBScript or JScript |
| CommandLineEventConsumer |
Consumer that executes command lines |
| WmiPrvSe.exe |
WMI Provider Host that executes subscription actions |
| MOF File |
Managed Object Format used to define WMI objects |
Detection Queries
Splunk -- WMI Subscription Creation via Sysmon
index=sysmon (EventCode=19 OR EventCode=20 OR EventCode=21)
| eval event_type=case(EventCode=19, "EventFilter", EventCode=20, "EventConsumer", EventCode=21, "FilterToConsumerBinding")
| table _time Computer User event_type EventNamespace Name Query Destination Operation
Splunk -- WMI Subscription via Windows Event 5861
index=wineventlog source="Microsoft-Windows-WMI-Activity/Operational" EventCode=5861
| table _time Computer NamespaceName Operation PossibleCause
PowerShell -- Enumerate WMI Subscriptions
Get-WmiObject -Namespace root\subscription -Class __EventFilter
Get-WmiObject -Namespace root\subscription -Class __EventConsumer
Get-WmiObject -Namespace root\subscription -Class __FilterToConsumerBinding
KQL -- WmiPrvSe.exe Spawning Suspicious Children
DeviceProcessEvents
| where Timestamp > ago(7d)
| where InitiatingProcessFileName =~ "wmiprvse.exe"
| where FileName in~ ("cmd.exe", "powershell.exe", "wscript.exe", "cscript.exe", "mshta.exe", "rundll32.exe")
| project Timestamp, DeviceName, FileName, ProcessCommandLine
Sigma Rule
title: WMI Event Subscription Persistence
status: stable
logsource:
product: windows
category: wmi_event
detection:
selection_consumer:
EventID: 20
Destination|contains:
- 'ActiveScriptEventConsumer'
- 'CommandLineEventConsumer'
condition: selection_consumer
level: high
tags:
- attack.persistence
- attack.t1546.003
Common Scenarios
- APT29 WMI Persistence: Creates an ActiveScriptEventConsumer that executes a VBScript backdoor on system startup, surviving reboots and credential resets.
- Turla WMI Backdoor: Uses Win32_ProcessStartTrace filter combined with CommandLineEventConsumer for covert command execution.
- FIN8 WMI Timer: Interval-based __IntervalTimerEvent triggering encoded PowerShell downloads every 30 minutes.
- MOF-Based Installation: Adversary drops a .mof file and compiles it with
mofcomp.exe to silently create persistent subscriptions.
Hunt ID: TH-WMI-[DATE]-[SEQ]
Host: [Hostname]
Subscription Name: [Filter/Consumer name]
Filter Query: [WQL trigger condition]
Consumer Type: [ActiveScript/CommandLine]
Consumer Action: [Script content or command]
Binding: [Filter-to-Consumer link]
Created: [Timestamp]
User Context: [SYSTEM/User]
Risk Level: [Critical/High/Medium/Low]
Other files in this skill
assets/template.md (verbatim)
WMI Subscription Persistence Hunt Template
| Field |
Value |
| Hunt ID |
TH-WMI-YYYY-MM-DD-NNN |
| Analyst |
|
| Date |
|
| Status |
[ ] In Progress / [ ] Complete |
Hypothesis
Adversaries have established persistence via WMI permanent event subscriptions to execute malicious code triggered by system events such as startup or user logon.
WMI Subscription Findings
| # |
Host |
Subscription Name |
Filter Query |
Consumer Type |
Consumer Action |
Severity |
| 1 |
|
|
|
|
|
|
WmiPrvSe.exe Child Process Findings
| # |
Host |
Child Process |
Command Line |
User |
Timestamp |
| 1 |
|
|
|
|
|
Recommendations
- Remove: [Malicious WMI subscriptions]
- Investigate: [Initial infection vector]
- Harden: [Restrict WMI subscription creation]
- Monitor: [Deploy Sysmon Events 19/20/21 rules]
references/api-reference.md (verbatim)
API Reference — Hunting for Persistence via WMI Subscriptions
Libraries Used
- subprocess: Execute WMIC and PowerShell commands for WMI enumeration
- python-evtx (Evtx): Parse Sysmon EVTX for WMI-related events (IDs 19, 20, 21)
- re: Pattern matching for suspicious WMI consumer payloads
CLI Interface
python agent.py enumerate # WMIC-based WMI subscription enumeration
python agent.py powershell # PowerShell Get-WMIObject enumeration
python agent.py sysmon --evtx-file <path> # Scan Sysmon EVTX for WMI events
Core Functions
enumerate_wmi_subscriptions()
Queries four WMI subscription classes via WMIC and flags entries matching suspicious patterns.
Returns: dict with classes (EventFilter, EventConsumer, ActiveScriptEventConsumer, FilterToConsumerBinding) and suspicious list.
scan_sysmon_wmi_events(evtx_file)
Parses Sysmon EVTX for Event IDs 19 (WmiEventFilter), 20 (WmiEventConsumer), 21 (WmiEventBinding).
Parameters:
| Name |
Type |
Description |
evtx_file |
str |
Path to Sysmon .evtx file |
query_powershell_wmi()
Uses PowerShell Get-WMIObject to enumerate WMI subscriptions in root\Subscription namespace.
WMI Classes Enumerated
| Class |
Description |
__EventFilter |
Defines the WQL query that triggers the subscription |
CommandLineEventConsumer |
Executes a command when the filter matches |
ActiveScriptEventConsumer |
Runs VBScript/JScript when the filter matches |
__FilterToConsumerBinding |
Links a filter to its consumer |
Sysmon Event IDs
| Event ID |
Description |
| 19 |
WmiEvent - Filter activity detected |
| 20 |
WmiEvent - Consumer activity detected |
| 21 |
WmiEvent - Consumer-to-filter binding |
Dependencies
pip install python-evtx # Optional, for EVTX parsing
references/standards.md (verbatim)
Standards and References - WMI Event Subscription Persistence
MITRE ATT&CK References
| Technique |
Name |
Description |
| T1546.003 |
WMI Event Subscription |
Primary persistence technique |
| T1047 |
WMI |
WMI execution for lateral movement |
| T1059.005 |
Visual Basic |
VBScript in ActiveScriptEventConsumer |
| T1059.007 |
JavaScript |
JScript in ActiveScriptEventConsumer |
WMI Subscription Components
| Component |
WMI Class |
Purpose |
| Event Filter |
__EventFilter |
Defines the trigger (WQL query) |
| Event Consumer |
__EventConsumer |
Defines the action |
| Binding |
__FilterToConsumerBinding |
Links filter to consumer |
Consumer Types and Risk
| Consumer Class |
Risk Level |
Description |
| ActiveScriptEventConsumer |
Critical |
Executes VBScript/JScript code |
| CommandLineEventConsumer |
Critical |
Executes arbitrary commands |
| LogFileEventConsumer |
Low |
Writes to a log file |
| NTEventLogEventConsumer |
Low |
Writes to Windows Event Log |
| SMTPEventConsumer |
Medium |
Sends email notifications |
Common Malicious Filter Queries
| Filter Type |
WQL Query |
Usage |
| Process Start |
SELECT * FROM __InstanceCreationEvent WITHIN 5 WHERE TargetInstance ISA 'Win32_Process' |
Execute on specific process start |
| System Startup |
SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System' |
Execute shortly after boot |
| Timer-Based |
SELECT * FROM __TimerEvent WHERE TimerID='MyTimer' |
Execute at intervals |
| User Logon |
SELECT * FROM __InstanceCreationEvent WHERE TargetInstance ISA 'Win32_LogonSession' |
Execute on user logon |
Detection Events
| Source |
Event ID |
Description |
| Sysmon |
19 |
WmiEventFilter activity detected |
| Sysmon |
20 |
WmiEventConsumer activity detected |
| Sysmon |
21 |
WmiEventConsumerToFilter activity detected |
| WMI-Activity |
5861 |
WMI permanent event subscription created |
| Security |
4688 |
Process creation (mofcomp.exe, WmiPrvSe.exe children) |
Known APT Usage
| Group |
Technique Details |
| APT29 |
ActiveScriptEventConsumer with encoded VBScript backdoor |
| APT32 (OceanLotus) |
WMI subscription for persistence in targeted attacks |
| FIN8 |
CommandLineEventConsumer for PowerShell execution |
| Turla |
WMI event subscription combined with COM hijacking |
| HEXANE |
WMI persistence in Middle Eastern energy sector attacks |
references/workflows.md (verbatim)
Detailed Hunting Workflow - WMI Subscription Persistence
Phase 1: Enumerate Existing Subscriptions
Step 1.1 - PowerShell Enumeration
# List all event filters
Get-WMIObject -Namespace root\Subscription -Class __EventFilter | Select-Object Name, Query, QueryLanguage
# List all event consumers
Get-WMIObject -Namespace root\Subscription -Class __EventConsumer | Select-Object Name, __CLASS
# List all bindings
Get-WMIObject -Namespace root\Subscription -Class __FilterToConsumerBinding | Select-Object Filter, Consumer
# Detailed ActiveScriptEventConsumer inspection
Get-WMIObject -Namespace root\Subscription -Class ActiveScriptEventConsumer | Select-Object Name, ScriptingEngine, ScriptText
# Detailed CommandLineEventConsumer inspection
Get-WMIObject -Namespace root\Subscription -Class CommandLineEventConsumer | Select-Object Name, ExecutablePath, CommandLineTemplate
Step 1.2 - WMIC Enumeration
wmic /namespace:\\root\subscription path __EventFilter get Name, Query
wmic /namespace:\\root\subscription path __EventConsumer get Name, __CLASS
wmic /namespace:\\root\subscription path __FilterToConsumerBinding get Filter, Consumer
Phase 2: Monitor Creation Events
Step 2.1 - Sysmon WMI Event Detection
index=sysmon (EventCode=19 OR EventCode=20 OR EventCode=21)
| eval event_type=case(
EventCode=19, "EventFilter Created",
EventCode=20, "EventConsumer Created",
EventCode=21, "Binding Created"
)
| table _time Computer User event_type Name Query Consumer Destination
Step 2.2 - Windows WMI Activity Log
index=wineventlog source="Microsoft-Windows-WMI-Activity/Operational"
| where EventCode IN (5857, 5858, 5859, 5860, 5861)
| table _time Computer EventCode NamespaceName Query Operation PossibleCause
Phase 3: Hunt for WmiPrvSe.exe Suspicious Children
Step 3.1 - Process Tree Analysis
index=sysmon EventCode=1
| where match(ParentImage, "(?i)WmiPrvSe\.exe$")
| where match(Image, "(?i)(cmd|powershell|wscript|cscript|mshta|rundll32|regsvr32)\.exe$")
| table _time Computer Image CommandLine User ParentImage
Step 3.2 - MOF Compilation Detection
index=sysmon EventCode=1 Image="*\\mofcomp.exe"
| table _time Computer User CommandLine ParentImage
Phase 4: Removal and Cleanup
Step 4.1 - Remove Malicious Subscription
# Remove specific subscription components
Get-WMIObject -Namespace root\Subscription -Class __EventFilter -Filter "Name='MaliciousFilter'" | Remove-WmiObject
Get-WMIObject -Namespace root\Subscription -Class CommandLineEventConsumer -Filter "Name='MaliciousConsumer'" | Remove-WmiObject
Get-WMIObject -Namespace root\Subscription -Class __FilterToConsumerBinding -Filter "Filter=""__EventFilter.Name='MaliciousFilter'""" | Remove-WmiObject
Phase 5: Response
- Document all found subscriptions with full details
- Remove malicious subscriptions from all affected hosts
- Block WMI subscription creation via Group Policy where possible
- Deploy ongoing monitoring via Sysmon Events 19/20/21
- Investigate initial infection vector that created the subscription
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.