<<< Hide Navigation Hide TOC >>>
WMI Creation (05645013-2fed-4066-8bdc-626b2e201dd4)
Initial construction of a WMI object, such as a filter, consumer, subscription, binding, or providers.
Data Collection Measures:
- Windows Security Event Logs:
- Event ID 5861 (WMI Permanent Event Subscription)
- Event ID 5860 (WMI Event Filter Activity)
- Event ID 5857 (WMI Event Consumer Activity)
- Sysmon Logs:
- Sysmon Event ID 19 – WMI Event Filter Created
- Sysmon Event ID 20 – WMI Event Consumer Created
- Sysmon Event ID 21 – WMI Event Binding Created
- Endpoint Detection & Response (EDR)
- Detects WMI-based persistence techniques.