Sub-technique of T1546 Event Triggered Execution.View on attack.mitre.org
Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription. WMI can be used to install event filters, providers, consumers, and bindings that execute code when a defined event occurs. Examples of events that may be subscribed to are the wall clock time, user login, or the computer's uptime.
Adversaries may use the capabilities of WMI to subscribe to an event and execute arbitrary code when that event occurs, providing persistence on a system. Adversaries may also compile WMI scripts – using `mofcomp.exe` –into Windows Management Object (MOF) files (.mof extension) that can be used to create a malicious subscription.
WMI subscription execution is proxied by the WMI Provider Host process (WmiPrvSe.exe) and thus may result in elevated SYSTEM privileges.
Rules on DetectionCode tagged with T1546.003.
| Rule | Level | Log source |
|---|---|---|
| WMI Backdoor Exchange Transport Agent | critical | windows / process_creation |
| NewActiveScriptEventConsumer Creation Attempt via Wmic.EXE | high | windows / process_creation |
| Suspicious Encoded Scripts in a WMI Consumer | high | windows / wmi_event |
| WMI Persistence - Command Line Event Consumer | high | windows / image_load |
| WMI Persistence - Script Event Consumer File Write | high | windows / file_event |
| Powershell WMI Persistence | medium | windows / ps_script |
| WMI ActiveScriptEventConsumers Activity Via Scrcons.EXE DLL Load | medium | windows / image_load |
| WMI Event Subscription | medium | windows / wmi_event |
| WMI Persistence | medium | windows / NULL |
| WMI Persistence - Script Event Consumer | medium | windows / process_creation |
| WMI Persistence - Security | medium | windows / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Detect WMI Event Subscription Persistence | TTP | NULL | Sysmon EventID 20 |
| Windows MOF Event Triggered Execution via WMI | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| WMI Permanent Event Subscription - Sysmon | TTP | NULL | Sysmon EventID 21 |
| Used by | Procedure example |
|---|---|
| GroupAPT29 | APT29 has used WMI event subscriptions for persistence. |
| GroupAPT33 | APT33 has attempted to use WMI event subscriptions to establish persistence on compromised hosts. |
| GroupBlue Mockingbird | Blue Mockingbird has used mofcomp.exe to establish WMI Event Subscription persistence mechanisms configured from a *.mof file. |
| GroupFIN8 | FIN8 has used WMI event subscriptions for persistence. |
| GroupHEXANE | HEXANE has used WMI event subscriptions for persistence. |
| GroupLeviathan | Leviathan has used WMI for persistence. |
| GroupMetador | Metador has established persistence through the use of a WMI event subscription combined with unusual living-off-the-land binaries such as `cdb.exe`. |
| GroupMustang Panda | Mustang Panda's custom ORat tool uses a WMI event consumer to maintain persistence. |
| Used by | Procedure example |
|---|---|
| Malwareadbupd | adbupd can use a WMI script to achieve persistence. |
| MalwareBADHATCH | BADHATCH can use WMI event subscriptions for persistence. |
| MalwareHOPLIGHT | HOPLIGHT can use WMI event subscriptions to create persistence. |
| MalwareKevin | Kevin can compile randomly-generated MOF files into the WMI repository to persistently run malware. |
| MalwaremetaMain | metaMain registered a WMI event subscription consumer called "hard_disk_stat" to establish persistence. |
| ToolPoshC2 | PoshC2 has the ability to persist on a system using WMI events. |
| MalwarePOSHSPY | POSHSPY uses a WMI event subscription to establish persistence. |
| MalwarePOWERTON | POWERTON can use WMI for persistence. |
| Used by | Procedure example |
|---|---|
| CampaignOperation Ghost | During Operation Ghost, APT29 used WMI event subscriptions to establish persistence for malware. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used a WMI event filter to invoke a command-line event consumer at system boot time to launch a backdoor with `rundll32.exe`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.