Windows Management Instrumentation Event Subscription

T1546.003

Sub-technique of T1546 Event Triggered Execution.View on attack.mitre.org

About this technique

Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription. WMI can be used to install event filters, providers, consumers, and bindings that execute code when a defined event occurs. Examples of events that may be subscribed to are the wall clock time, user login, or the computer's uptime.

Adversaries may use the capabilities of WMI to subscribe to an event and execute arbitrary code when that event occurs, providing persistence on a system. Adversaries may also compile WMI scripts – using `mofcomp.exe` –into Windows Management Object (MOF) files (.mof extension) that can be used to create a malicious subscription.

WMI subscription execution is proxied by the WMI Provider Host process (WmiPrvSe.exe) and thus may result in elevated SYSTEM privileges.

Detection rules14

Rules on DetectionCode tagged with T1546.003.

Sigma11

RuleLevelLog source
WMI Backdoor Exchange Transport Agentcriticalwindows / process_creation
NewActiveScriptEventConsumer Creation Attempt via Wmic.EXEhighwindows / process_creation
Suspicious Encoded Scripts in a WMI Consumerhighwindows / wmi_event
WMI Persistence - Command Line Event Consumerhighwindows / image_load
WMI Persistence - Script Event Consumer File Writehighwindows / file_event
Powershell WMI Persistencemediumwindows / ps_script
WMI ActiveScriptEventConsumers Activity Via Scrcons.EXE DLL Loadmediumwindows / image_load
WMI Event Subscriptionmediumwindows / wmi_event
WMI Persistencemediumwindows / NULL
WMI Persistence - Script Event Consumermediumwindows / process_creation
WMI Persistence - Securitymediumwindows / NULL

Splunk3

RuleTypeRiskData source
Detect WMI Event Subscription PersistenceTTPNULLSysmon EventID 20
Windows MOF Event Triggered Execution via WMITTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
WMI Permanent Event Subscription - SysmonTTPNULLSysmon EventID 21

Groups10

Software13

Campaigns2

Procedure examples25

Groups10

Used byProcedure example
GroupAPT29

APT29 has used WMI event subscriptions for persistence.

GroupAPT33

APT33 has attempted to use WMI event subscriptions to establish persistence on compromised hosts.

GroupBlue Mockingbird

Blue Mockingbird has used mofcomp.exe to establish WMI Event Subscription persistence mechanisms configured from a *.mof file.

GroupFIN8

FIN8 has used WMI event subscriptions for persistence.

GroupHEXANE

HEXANE has used WMI event subscriptions for persistence.

GroupLeviathan

Leviathan has used WMI for persistence.

GroupMetador

Metador has established persistence through the use of a WMI event subscription combined with unusual living-off-the-land binaries such as `cdb.exe`.

GroupMustang Panda

Mustang Panda's custom ORat tool uses a WMI event consumer to maintain persistence.

View all 10 groups examples

Software13

Used byProcedure example
Malwareadbupd

adbupd can use a WMI script to achieve persistence.

MalwareBADHATCH

BADHATCH can use WMI event subscriptions for persistence.

MalwareHOPLIGHT

HOPLIGHT can use WMI event subscriptions to create persistence.

MalwareKevin

Kevin can compile randomly-generated MOF files into the WMI repository to persistently run malware.

MalwaremetaMain

metaMain registered a WMI event subscription consumer called "hard_disk_stat" to establish persistence.

ToolPoshC2

PoshC2 has the ability to persist on a system using WMI events.

MalwarePOSHSPY

POSHSPY uses a WMI event subscription to establish persistence.

MalwarePOWERTON

POWERTON can use WMI for persistence.

View all 13 software examples

Campaigns2

Used byProcedure example
CampaignOperation Ghost

During Operation Ghost, APT29 used WMI event subscriptions to establish persistence for malware.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used a WMI event filter to invoke a command-line event consumer at system boot time to launch a backdoor with `rundll32.exe`.

References5

  1. Dell WMI Persistence Open source
    Dell SecureWorks Counter Threat Unit™ (CTU) Research Team. (2016, March 28). A Novel WMI Persistence Implementation. Retrieved March 30, 2016.
  2. FireEye WMI 2015 Open source
    Ballenthin, W., et al. (2015). Windows Management Instrumentation (WMI) Offense, Defense, and Forensics. Retrieved March 30, 2016.
  3. FireEye WMI SANS 2015 Open source
    Devon Kerr. (2015). There's Something About WMI. Retrieved November 17, 2024.
  4. Mandiant M-Trends 2015 Open source
    Mandiant. (2015, February 24). M-Trends 2015: A View from the Front Lines. Retrieved November 17, 2024.
  5. Microsoft MOF May 2018 Open source
    Satran, M. (2018, May 30). Managed Object Format (MOF). Retrieved January 24, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.