1200KM / simulation
T1546.003 Windows Management Instrumentation Event Subscription — Attack Simulation
Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription. WMI can be used to install event filters, providers, consumers, and bindings that execute code when a defined event occurs. Examples of events that may be subscribed to are the wall clock time, user login, or the computer's uptime. Adversaries may use the capabilities of WMI to…
Technique description
Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription. WMI can be used to install event filters, providers, consumers, and bindings that execute code when a defined event occurs. Examples of events that may be subscribed to are the wall clock time, user login, or the computer's uptime. Adversaries may use the capabilities of WMI to…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Windows MOFComp.exe Load MOF File
Procedure 29786d7e-8916-4de6-9c55-be7b093b2706; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Persistence via WMI Event Subscription - CommandLineEventConsumer
Procedure 3c64f177-28e2-49eb-a799-d767b24dd1e0; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Turla WMI Persistence - Dual Filter with Base64 Payload
Procedure 67cee1c5-8c9b-460b-a4c3-76a6c69bcd15; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Persistence via WMI Event Subscription - ActiveScriptEventConsumer
Procedure fecd0dfd-fb55-45fa-a10b-6250272d0832; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.