NewActiveScriptEventConsumer Creation Attempt via Wmic.EXE

 Original Source: [Sigma source]
Title: NewActiveScriptEventConsumer Creation Attempt via Wmic.EXE
Status: test
Description:Detects the attempt to create an ActiveScriptEventConsumer via WMIC.EXE. An ActiveScriptEventConsumer is a built-in Windows Management Instrumentation (WMI) class that automatically executes a predefined script (in VBScript or JScript) whenever a specific system event occurs. Adversaries often abuse ActiveScriptEventConsumer to maintain persistence on a compromised host by executing a malicious script whenever a specific event occurs.
References:
  -https://twitter.com/johnlatwc/status/1408062131321270282?s=12
  -https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf
Author: Florian Roth (Nextron Systems)
Date: 2021-06-25
modified:2026-06-19
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1546.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
OriginalFileName:'wmic.exe' Image|endswith:'\WMIC.exe'   selection_cli:
    CommandLine|contains|all:
      -'ActiveScriptEventConsumer'
      -' CREATE '

  condition:all of selection_*
Falsepositives:
  -Legitimate software creating script event consumers
Level: high