1200KM / detection
T1546.003 Windows Management Instrumentation Event Subscription — Detection Rules
Detection workspace for T1546.003 Windows Management Instrumentation Event Subscription: 11 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- WMI Persistence - Security · test · medium · {"product":"windows","service":"security"}
- WMI Persistence · test · medium · {"product":"windows","service":"wmi","definition":"WMI Namespaces Auditing and SACL should be configured, EventID 5861 and 5859 detection requires Windows 10, 2012 and higher"}
- WMI Persistence - Script Event Consumer File Write · test · high · {"product":"windows","category":"file_event"}
- WMI ActiveScriptEventConsumers Activity Via Scrcons.EXE DLL Load · test · medium · {"category":"image_load","product":"windows"}
- WMI Persistence - Command Line Event Consumer · test · high · {"category":"image_load","product":"windows"}
- Powershell WMI Persistence · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- WMI Backdoor Exchange Transport Agent · test · critical · {"category":"process_creation","product":"windows"}
- WMI Persistence - Script Event Consumer · test · medium · {"category":"process_creation","product":"windows"}
- NewActiveScriptEventConsumer Creation Attempt via Wmic.EXE · test · high · {"category":"process_creation","product":"windows"}
- WMI Event Subscription · test · medium · {"product":"windows","category":"wmi_event"}
- Suspicious Encoded Scripts in a WMI Consumer · test · high · {"product":"windows","category":"wmi_event"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0086 Detect WMI Event Subscription for Persistence via WmiPrvSE Process and MOF Compilation
AN0236 Analytic 0236
Monitor for creation of WMI EventFilter, EventConsumer, and FilterToConsumerBinding objects through WMI or MOF file execution. Detect command-line execution of `mofcomp.exe`, usage of `Register-WmiEvent` via PowerShell, and anomalous child processes of `WmiPrvSE.exe` that indicate triggered execution. Look for lateral anomalies in process lineage and WMI logging channels.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.