Skip to content
Threat Feed
medium advisory

Detection of WMI Permanent Event Subscriptions for Persistence

This brief outlines the detection of potential persistence and privilege escalation via WMI permanent event subscriptions, which attackers use to trigger malicious payloads on system events.

Windows Management Instrumentation (WMI) is a powerful administrative feature that can be abused by adversaries to maintain persistence or elevate privileges. By creating permanent event subscriptions, attackers can configure the system to execute arbitrary commands, scripts, or binaries whenever a specific event occurs, such as a process start, a logon, or a system timer trigger. This technique allows malicious code to execute with SYSTEM-level privileges if the consumer is configured appropriately.

Defenders can identify this activity by monitoring WMI event binding events. Sysmon Event ID 21 specifically logs the creation, modification, or deletion of WMI permanent event subscriptions. Because legitimate administrative tools and software installers may occasionally create WMI subscriptions, security teams must establish a baseline of known-good activity to effectively reduce false positives during investigation.

Impact

Successful abuse of WMI permanent event subscriptions provides attackers with a stealthy, system-wide mechanism to execute payloads without requiring a persistent file on disk or a traditional service. This can lead to long-term unauthorized access, data exfiltration, or further system compromise across the target environment.

Recommendation

Detection engineering teams should focus on identifying unauthorized WMI event bindings.

  • Enable Sysmon version 6.1 or later on all Windows endpoints.
  • Configure Sysmon to capture Event ID 21 (WmiEventFilter activity, WmiEventConsumer activity, and WmiEventConsumerToFilter activity).
  • Deploy the provided Sigma rule to your SIEM to monitor for any WMI subscription modifications and investigate the associated consumer and filter paths.
  • Baseline common administrative activity to tune the detection logic and suppress known, legitimate software subscriptions.

Immediate actions

Deploy Sigma rule to monitor for Event ID 21 activity.

Detection Engineering 72h

Threat Hunt

Identify all existing WMI permanent event subscriptions on critical servers.

T1546.003 medium high confidence hunt now

Data: WMI Event Consumer and Filter details

Mitigations

Review and remove unauthorized or unknown WMI permanent event subscriptions.

medium IT Operations

Persistence via WMI

Detection coverage 1

Detect WMI Permanent Event Subscription Modification

medium

Detects the creation, modification, or deletion of a WMI permanent event subscription using Sysmon Event ID 21.

sigma tactics: persistence, privilege-escalation techniques: T1546.003 sources: process_creation, windows

Detection queries are available on the platform. Get full rules →