跳到主要内容
知仓学习社ZHICANG

detecting-wmi-persistence

Detect WMI event subscription persistence (MITRE T1546.003) by analyzing Sysmon

执行命令写文件严重 0 · 高危 2mukul975/Anthropic-Cybersecurity-Skills

它会碰到什么

扫了多少4 个文本文件,26 KB
它会碰到什么执行命令写文件
命中总数3 处
命中统计严重 0 · 高 2 · 中 1 · 低 0
逐条看命中(2 条严重或高危)
  • scripts/agent.py:41exec-spawn
    result = subprocess.run(cmd, capture_output=True, text=True, timeout=120)
  • scripts/agent.py:78exec-spawn
    result = subprocess.run(cmd, capture_output=True, text=True, timeout=120)

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Detecting WMI Persistence

When to Use

  • When hunting for WMI event subscription persistence (MITRE ATT&CK T1546.003)
  • After detecting suspicious WMI activity in endpoint telemetry
  • During incident response to identify attacker persistence mechanisms
  • When Sysmon alerts trigger on Event IDs 19, 20, or 21
  • During purple team exercises testing WMI-based persistence

Prerequisites

  • Sysmon v6.1+ deployed with WMI event logging enabled (Event IDs 19, 20, 21)
  • Windows Security Event Log forwarding configured
  • SIEM with Sysmon data ingested (Splunk, Elastic, Sentinel)
  • PowerShell access for WMI enumeration on endpoints
  • Sysinternals Autoruns for manual WMI subscription review

Workflow

  1. Collect Telemetry: Parse Sysmon Event IDs 19 (WmiEventFilter), 20 (WmiEventConsumer), 21 (WmiEventConsumerToFilter).
  2. Identify Suspicious Consumers: Flag CommandLineEventConsumer and ActiveScriptEventConsumer types executing code.
  3. Analyze Event Filters: Examine WQL queries in EventFilters for process start triggers or timer-based execution.
  4. Correlate Bindings: Match FilterToConsumerBindings linking suspicious filters to consumers.
  5. Check Persistence Locations: Query WMI namespaces root\subscription and root\default for active subscriptions.
  6. Validate Findings: Cross-reference with known-good WMI subscriptions (SCCM, AV products).
  7. Document and Remediate: Remove malicious subscriptions and update detection rules.

Key Concepts

| Concept | Description |

|---------|-------------|

| Sysmon Event 19 | WmiEventFilter creation detected |

| Sysmon Event 20 | WmiEventConsumer creation detected |

| Sysmon Event 21 | WmiEventConsumerToFilter binding detected |

| T1546.003 | Event Triggered Execution: WMI Event Subscription |

| CommandLineEventConsumer | Executes system commands when filter triggers |

| ActiveScriptEventConsumer | Runs VBScript/JScript when filter triggers |

Tools & Systems

| Tool | Purpose |

|------|---------|

| Sysmon | Windows event monitoring for WMI activity |

| WMI Explorer | GUI tool for browsing WMI namespaces |

| Autoruns | Sysinternals tool listing persistence mechanisms |

| PowerShell Get-WMIObject | Enumerate WMI event subscriptions |

| Splunk | SIEM analysis of Sysmon WMI events |

| Velociraptor | Endpoint WMI artifact collection |

Output Format

Hunt ID: TH-WMI-[DATE]-[SEQ]
Technique: T1546.003
Host: [Hostname]
Event Type: [EventFilter|EventConsumer|Binding]
Consumer Type: [CommandLine|ActiveScript]
WQL Query: [Filter query text]
Command: [Executed command or script]
Risk Level: [Critical/High/Medium/Low]
Recommended Action: [Remove subscription, investigate lateral movement]

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。