<<< Hide Navigation Hide TOC >>>
WMI Persistence (0b7889b4-5577-4521-a60a-3376ee7f9f7b)
Detects suspicious WMI event filter and command line event consumer based on WMI and Security Logs.
Cluster A![]() |
Galaxy A![]() |
Cluster B![]() |
Galaxy B![]() |
Level![]() |
---|---|---|---|---|
WMI Persistence (0b7889b4-5577-4521-a60a-3376ee7f9f7b) | Sigma-Rules | Windows Management Instrumentation Event Subscription - T1546.003 (910906dd-8c0a-475a-9cc1-5e029e2fad58) | Attack Pattern | 1 |
Event Triggered Execution - T1546 (b6301b64-ef57-4cce-bb0b-77026f14a8db) | Attack Pattern | Windows Management Instrumentation Event Subscription - T1546.003 (910906dd-8c0a-475a-9cc1-5e029e2fad58) | Attack Pattern | 2 |