Skip to content
Threat Feed
medium advisory

Abuse of WMI Permanent Event Subscriptions for Persistence

Adversaries leverage WMI permanent event subscriptions to achieve stealthy persistence and arbitrary code execution by binding system event filters to malicious consumers.

Windows Management Instrumentation (WMI) provides a powerful interface for system management that can be weaponized by threat actors to achieve persistence and facilitate lateral movement or defense evasion. By creating a permanent event subscription, an attacker can register an __EventFilter that monitors for specific system occurrences (such as system uptime, user logon, or process creation) and triggers a CommandLineEventConsumer or ActiveScriptEventConsumer when the conditions are met. These consumers allow for the execution of arbitrary commands or scripts with SYSTEM privileges. Because these subscriptions are stored in the WMI repository (CIM repository), they are highly resilient, often surviving reboots and potentially avoiding detection by traditional file-based security tools. Defenders must monitor the Microsoft-Windows-WMI-Activity/Operational event log, specifically Event ID 5861, to identify unauthorized binding operations that link these persistent event filters to suspicious consumers.

Attack Chain

  1. Attacker gains initial access and elevates privileges to local administrator or SYSTEM level.
  2. Attacker crafts a malicious __EventFilter specifying a trigger condition (e.g., system boot time).
  3. Attacker crafts a CommandLineEventConsumer or ActiveScriptEventConsumer containing the payload command or script path.
  4. Attacker uses wmic or PowerShell Get-WmiObject / Set-WmiInstance to register the __EventFilter object in the root/subscription namespace.
  5. Attacker registers the __EventConsumer object containing the malicious payload instructions.
  6. Attacker creates an __FilterToConsumerBinding instance to link the filter and the consumer.
  7. The WMI service monitors the system for the filter condition specified in the __EventFilter.
  8. Once the condition is met, the WMI service automatically executes the malicious payload specified in the consumer.

Impact

Successful abuse of WMI permanent event subscriptions provides attackers with a robust, difficult-to-detect persistence mechanism that operates outside of typical user-mode startup locations. This allows for automated payload execution, credential dumping, or additional malware deployment across a wide range of Windows environments, potentially leading to full system compromise and long-term undetected access.

Recommendation

Prioritize the identification and investigation of permanent WMI event subscriptions through the following actions:

  • Enable the Microsoft-Windows-WMI-Activity/Operational event log and monitor specifically for Event ID 5861 to capture binding operations.
  • Implement the provided Sigma rules or equivalent logic in your SIEM to alert on the creation of CommandLineEventConsumer or ActiveScriptEventConsumer types.
  • Establish a baseline of legitimate WMI subscriptions in your environment to facilitate the tuning of alerts and to reduce false positives from administrative or software-driven management tasks.
  • Regularly audit the WMI repository for suspicious objects bound to event filters that are not associated with known system management processes.

Immediate actions

Enable Microsoft-Windows-WMI-Activity/Operational event logging on all endpoint assets.

IT Operations 48h

Threat Hunt

Search historical logs for Event ID 5861 to identify existing permanent subscriptions.

T1546.003 high high confidence hunt now

Data: WMI-Activity Event Logs

Mitigations

Review and remove unauthorized permanent WMI event subscriptions.

medium_term IT Operations

T1546.003

Detection coverage 1

Detect WMI Permanent Event Subscription

medium

Detects permanent WMI event subscriptions containing CommandLineEventConsumer or ActiveScriptEventConsumer, which are commonly leveraged for persistence and execution.

sigma tactics: persistence techniques: T1546.003 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →