{"id":"0f06a3a5-6a09-413f-8743-e6cf35561297","title":"WMI Event Subscription","description":"Detects creation of WMI event subscription persistence method","author":"Tom Ueltschi (@c_APT_ure)","status":"test","level":"medium","date":"2019-01-12","modified":"2021-11-27","tags":["attack.privilege-escalation","attack.persistence","attack.t1546.003"],"technique_ids":["T1546.003"],"logsource":{"product":"windows","category":"wmi_event"},"falsepositives":["Exclude legitimate (vetted) use of WMI event subscription in your network"],"references":["https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon#event-id-19-wmievent-wmieventfilter-activity-detected","https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon#event-id-20-wmievent-wmieventconsumer-activity-detected","https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon#event-id-21-wmievent-wmieventconsumertofilter-activity-detected"],"source_path":"rules/windows/wmi_event/sysmon_wmi_event_subscription.yml","source_sha256":"afe8ac682c5d80d707e38a82fdb0e2a96b9db25a3d9c2b6f0fb9726a9bf26e42","source_url":"https://github.com/anpa1200/sigma/blob/b249e9683190cffdcaf188ccbfb90bf4759844e1/rules/windows/wmi_event/sysmon_wmi_event_subscription.yml","license":"Detection Rule License 1.1","license_url":"https://github.com/SigmaHQ/Detection-Rule-License/blob/main/LICENSE.Detection.Rules.md","yaml":"title: WMI Event Subscription\nid: 0f06a3a5-6a09-413f-8743-e6cf35561297\nstatus: test\ndescription: Detects creation of WMI event subscription persistence method\nreferences:\n    - https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon#event-id-19-wmievent-wmieventfilter-activity-detected\n    - https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon#event-id-20-wmievent-wmieventconsumer-activity-detected\n    - https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon#event-id-21-wmievent-wmieventconsumertofilter-activity-detected\nauthor: Tom Ueltschi (@c_APT_ure)\ndate: 2019-01-12\nmodified: 2021-11-27\ntags:\n    - attack.privilege-escalation\n    - attack.persistence\n    - attack.t1546.003\nlogsource:\n    product: windows\n    category: wmi_event\ndetection:\n    selection:\n        EventID:\n            - 19\n            - 20\n            - 21\n    condition: selection\nfalsepositives:\n    - Exclude legitimate (vetted) use of WMI event subscription in your network\nlevel: medium\n","validation":"yaml_parsed_not_backend_compiled_or_live_validated","techniques":[{"key":"enterprise/T1546.003","id":"T1546.003","name":"Windows Management Instrumentation Event Subscription","page":"techniques/enterprise/T1546.003/"}],"data_path":"data/detection-rules/0f06a3a5-6a09-413f-8743-e6cf35561297.json","kind":"sigma"}
