WMI Persistence

 Original Source: [Sigma source]
Title: WMI Persistence
Status: test
Description:Detects suspicious WMI event filter and command line event consumer based on WMI and Security Logs.
References:
  -https://twitter.com/mattifestation/status/899646620148539397
  -https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/
Author: Florian Roth (Nextron Systems), Gleb Sukhodolskiy, Timur Zinniatullin oscd.community
Date: 2017-08-22
modified:2022-02-10
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.t1546.003'
Logsource:
  • product: windows
  • service: wmi
  • definition: WMI Namespaces Auditing and SACL should be configured, EventID 5861 and 5859 detection requires Windows 10, 2012 and higher
Detection:
  wmi_filter_to_consumer_binding:
    EventID: '5861'
  consumer_keywords:
    - 'ActiveScriptEventConsumer'
    - 'CommandLineEventConsumer'
    - 'CommandLineTemplate'
  wmi_filter_registration:
    EventID: '5859'
  filter_scmevent:
    Provider: 'SCM Event Provider'
    Query: 'select * from MSFT_SCMEventLogEvent'
    User: 'S-1-5-32-544'
    PossibleCause: 'Permanent'
  condition:( (wmi_filter_to_consumer_binding and consumer_keywords) or (wmi_filter_registration) ) and not filter_scmevent
Falsepositives:
  -Unknown (data set is too small; further testing needed)
Level: medium