Abuse of WMI Permanent Event Subscriptions for Persistence
Adversaries leverage WMI permanent event subscriptions to achieve stealthy persistence and arbitrary code execution by binding system event filters to malicious consumers.
Windows Management Instrumentation (WMI) provides a powerful interface for system management that can be weaponized by threat actors to achieve persistence and facilitate lateral movement or defense evasion. By creating a permanent event subscription, an attacker can register an __EventFilter that monitors for specific system occurrences (such as system uptime, user logon, or process creation) and triggers a CommandLineEventConsumer or ActiveScriptEventConsumer when the conditions are met. These consumers allow for the execution of arbitrary commands or scripts with SYSTEM privileges. Because these subscriptions are stored in the WMI repository (CIM repository), they are highly resilient, often surviving reboots and potentially avoiding detection by traditional file-based security tools. Defenders must monitor the Microsoft-Windows-WMI-Activity/Operational event log, specifically Event ID 5861, to identify unauthorized binding operations that link these persistent event filters to suspicious consumers.
Attack Chain
- Attacker gains initial access and elevates privileges to local administrator or SYSTEM level.
- Attacker crafts a malicious
__EventFilterspecifying a trigger condition (e.g., system boot time). - Attacker crafts a
CommandLineEventConsumerorActiveScriptEventConsumercontaining the payload command or script path. - Attacker uses
wmicor PowerShellGet-WmiObject/Set-WmiInstanceto register the__EventFilterobject in theroot/subscriptionnamespace. - Attacker registers the
__EventConsumerobject containing the malicious payload instructions. - Attacker creates an
__FilterToConsumerBindinginstance to link the filter and the consumer. - The WMI service monitors the system for the filter condition specified in the
__EventFilter. - Once the condition is met, the WMI service automatically executes the malicious payload specified in the consumer.
Impact
Successful abuse of WMI permanent event subscriptions provides attackers with a robust, difficult-to-detect persistence mechanism that operates outside of typical user-mode startup locations. This allows for automated payload execution, credential dumping, or additional malware deployment across a wide range of Windows environments, potentially leading to full system compromise and long-term undetected access.
Recommendation
Prioritize the identification and investigation of permanent WMI event subscriptions through the following actions:
- Enable the
Microsoft-Windows-WMI-Activity/Operationalevent log and monitor specifically for Event ID 5861 to capture binding operations. - Implement the provided Sigma rules or equivalent logic in your SIEM to alert on the creation of
CommandLineEventConsumerorActiveScriptEventConsumertypes. - Establish a baseline of legitimate WMI subscriptions in your environment to facilitate the tuning of alerts and to reduce false positives from administrative or software-driven management tasks.
- Regularly audit the WMI repository for suspicious objects bound to event filters that are not associated with known system management processes.
Immediate actions
Enable Microsoft-Windows-WMI-Activity/Operational event logging on all endpoint assets.
Threat Hunt
Search historical logs for Event ID 5861 to identify existing permanent subscriptions.
Data: WMI-Activity Event Logs
Mitigations
Review and remove unauthorized permanent WMI event subscriptions.
T1546.003
Detection coverage 1
Detect WMI Permanent Event Subscription
mediumDetects permanent WMI event subscriptions containing CommandLineEventConsumer or ActiveScriptEventConsumer, which are commonly leveraged for persistence and execution.
Detection queries are available on the platform. Get full rules →