Detection of WMI Permanent Event Subscriptions for Persistence
This brief outlines the detection of potential persistence and privilege escalation via WMI permanent event subscriptions, which attackers use to trigger malicious payloads on system events.
Windows Management Instrumentation (WMI) is a powerful administrative feature that can be abused by adversaries to maintain persistence or elevate privileges. By creating permanent event subscriptions, attackers can configure the system to execute arbitrary commands, scripts, or binaries whenever a specific event occurs, such as a process start, a logon, or a system timer trigger. This technique allows malicious code to execute with SYSTEM-level privileges if the consumer is configured appropriately.
Defenders can identify this activity by monitoring WMI event binding events. Sysmon Event ID 21 specifically logs the creation, modification, or deletion of WMI permanent event subscriptions. Because legitimate administrative tools and software installers may occasionally create WMI subscriptions, security teams must establish a baseline of known-good activity to effectively reduce false positives during investigation.
Impact
Successful abuse of WMI permanent event subscriptions provides attackers with a stealthy, system-wide mechanism to execute payloads without requiring a persistent file on disk or a traditional service. This can lead to long-term unauthorized access, data exfiltration, or further system compromise across the target environment.
Recommendation
Detection engineering teams should focus on identifying unauthorized WMI event bindings.
- Enable Sysmon version 6.1 or later on all Windows endpoints.
- Configure Sysmon to capture Event ID 21 (WmiEventFilter activity, WmiEventConsumer activity, and WmiEventConsumerToFilter activity).
- Deploy the provided Sigma rule to your SIEM to monitor for any WMI subscription modifications and investigate the associated consumer and filter paths.
- Baseline common administrative activity to tune the detection logic and suppress known, legitimate software subscriptions.
Immediate actions
Deploy Sigma rule to monitor for Event ID 21 activity.
Threat Hunt
Identify all existing WMI permanent event subscriptions on critical servers.
Data: WMI Event Consumer and Filter details
Mitigations
Review and remove unauthorized or unknown WMI permanent event subscriptions.
Persistence via WMI
Detection coverage 1
Detect WMI Permanent Event Subscription Modification
mediumDetects the creation, modification, or deletion of a WMI permanent event subscription using Sysmon Event ID 21.
Detection queries are available on the platform. Get full rules →