{"id":"T1546.003","name":"Windows Management Instrumentation Event Subscription","url":"https://attack.mitre.org/techniques/T1546/003","tactics":["privilege-escalation","persistence"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0086","stix_id":"x-mitre-detection-strategy--99e60eb7-f2fa-4423-8c51-29832cd6e7ef","name":"Detect WMI Event Subscription for Persistence via WmiPrvSE Process and MOF Compilation","url":"https://attack.mitre.org/detectionstrategies/DET0086","analytics":[{"id":"AN0236","stix_id":"x-mitre-analytic--1a0640f0-e286-405f-9ab3-507c1abb77da","name":"Analytic 0236","description":"Monitor for creation of WMI EventFilter, EventConsumer, and FilterToConsumerBinding objects through WMI or MOF file execution. Detect command-line execution of `mofcomp.exe`, usage of `Register-WmiEvent` via PowerShell, and anomalous child processes of `WmiPrvSE.exe` that indicate triggered execution. Look for lateral anomalies in process lineage and WMI logging channels.","url":"https://attack.mitre.org/detectionstrategies/DET0086#AN0236","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:WMI","channel":"EventCode=5857, 5858, 5860, 5861","data_component":"DC0008","data_component_name":"WMI Creation","log_source_slug":"wineventlog-wmi"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TimeWindow","description":"Defines temporal correlation range between WMI creation and child process execution"},{"field":"UserContext","description":"Tune for specific accounts (e.g., SYSTEM or attacker-controlled users)"},{"field":"ProcessNameAllowlist","description":"Used to exclude known benign consumers triggered via WMI (e.g., backup tools)"},{"field":"ParentProcessAnomalyThreshold","description":"Defines what constitutes anomalous spawning from WmiPrvSE.exe"}],"live":true,"detection_strategies":["DET0086"],"techniques":["T1546.003"]}],"live":true,"version":"1.0","techniques":["T1546.003"]}],"sigma_rules":[{"id":"05936ce2-ee05-4dae-9d03-9a391cf2d2c6","title":"WMI Persistence - Command Line Event Consumer","author":"Thomas Patzke","status":"test","level":"high","date":"2018-03-07","modified":"2021-11-27","description":"Detects WMI command line event consumers","references":["https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.privilege-escalation","attack.t1546.003","attack.persistence"],"path":"rules/windows/image_load/image_load_wmi_persistence_commandline_event_consumer.yml","techniques":["T1546.003"],"cves":[]},{"id":"0b7889b4-5577-4521-a60a-3376ee7f9f7b","title":"WMI Persistence","author":"Florian Roth (Nextron Systems), Gleb Sukhodolskiy, Timur Zinniatullin oscd.community","status":"test","level":"medium","date":"2017-08-22","modified":"2022-02-10","description":"Detects suspicious WMI event filter and command line event consumer based on WMI and Security Logs.","references":["https://twitter.com/mattifestation/status/899646620148539397","https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/"],"logsource":{"product":"windows","service":"wmi"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1546.003"],"path":"rules/windows/builtin/wmi/win_wmi_persistence.yml","techniques":["T1546.003"],"cves":[]},{"id":"0f06a3a5-6a09-413f-8743-e6cf35561297","title":"WMI Event Subscription","author":"Tom Ueltschi (@c_APT_ure)","status":"test","level":"medium","date":"2019-01-12","modified":"2021-11-27","description":"Detects creation of WMI event subscription persistence method","references":["https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon#event-id-19-wmievent-wmieventfilter-activity-detected","https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon#event-id-20-wmievent-wmieventconsumer-activity-detected","https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon#event-id-21-wmievent-wmieventconsumertofilter-activity-detected"],"logsource":{"product":"windows","category":"wmi_event"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.003"],"path":"rules/windows/wmi_event/sysmon_wmi_event_subscription.yml","techniques":["T1546.003"],"cves":[]},{"id":"33f41cdd-35ac-4ba8-814b-c6a4244a1ad4","title":"WMI Persistence - Script Event Consumer File Write","author":"Thomas Patzke","status":"test","level":"high","date":"2018-03-07","modified":"2021-11-27","description":"Detects file writes of WMI script event consumer","references":["https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.privilege-escalation","attack.t1546.003","attack.persistence"],"path":"rules/windows/file/file_event/file_event_win_wmi_persistence_script_event_consumer_write.yml","techniques":["T1546.003"],"cves":[]},{"id":"797011dc-44f4-4e6f-9f10-a8ceefbe566b","title":"WMI Backdoor Exchange Transport Agent","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2019-10-11","modified":"2023-02-08","description":"Detects a WMI backdoor in Exchange Transport Agents via WMI event filters","references":["https://twitter.com/cglyer/status/1182389676876980224","https://twitter.com/cglyer/status/1182391019633029120"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.003"],"path":"rules/windows/process_creation/proc_creation_win_wmi_backdoor_exchange_transport_agent.yml","techniques":["T1546.003"],"cves":[]},{"id":"83844185-1c5b-45bc-bcf3-b5bf3084ca5b","title":"Suspicious Encoded Scripts in a WMI Consumer","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-09-01","modified":"2022-10-09","description":"Detects suspicious encoded payloads in WMI Event Consumers","references":["https://github.com/RiccardoAncarani/LiquidSnake"],"logsource":{"product":"windows","category":"wmi_event"},"tags":["attack.privilege-escalation","attack.execution","attack.t1047","attack.persistence","attack.t1546.003"],"path":"rules/windows/wmi_event/sysmon_wmi_susp_encoded_scripts.yml","techniques":["T1047","T1546.003"],"cves":[]},{"id":"9599c180-e3a8-4743-8f92-7fb96d3be648","title":"Potential Remote WMI ActiveScriptEventConsumers Activity","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)","status":"test","level":"medium","date":"2020-09-02","modified":"2024-09-02","description":"Detect potential adversaries leveraging WMI ActiveScriptEventConsumers remotely to move laterally in a network.\nThis event is best correlated and used as an enrichment to determine the potential lateral movement activity.\n","references":["https://threathunterplaybook.com/hunts/windows/200902-RemoteWMIActiveScriptEventConsumers/notebook.html"],"logsource":{"product":"windows","service":"security"},"tags":["attack.lateral-movement","attack.privilege-escalation","detection.threat-hunting","attack.persistence","attack.t1546.003"],"path":"rules-threat-hunting/windows/builtin/security/account_management/win_security_scrcons_remote_wmi_scripteventconsumer.yml","techniques":["T1546.003"],"cves":[]},{"id":"9e07f6e7-83aa-45c6-998e-0af26efd0a85","title":"Powershell WMI Persistence","author":"frack113","status":"test","level":"medium","date":"2021-08-19","modified":"2022-12-25","description":"Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.003/T1546.003.md","https://github.com/EmpireProject/Empire/blob/08cbd274bef78243d7a8ed6443b8364acd1fc48b/data/module_source/persistence/Persistence.psm1#L545"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1546.003"],"path":"rules/windows/powershell/powershell_script/posh_ps_wmi_persistence.yml","techniques":["T1546.003"],"cves":[]},{"id":"b439f47d-ef52-4b29-9a2f-57d8a96cb6b8","title":"WMI ActiveScriptEventConsumers Activity Via Scrcons.EXE DLL Load","author":"Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)","status":"test","level":"medium","date":"2020-09-02","modified":"2023-02-22","description":"Detects signs of the WMI script host process \"scrcons.exe\" loading scripting DLLs which could indicates WMI ActiveScriptEventConsumers EventConsumers activity.","references":["https://twitter.com/HunterPlaybook/status/1301207718355759107","https://www.mdsec.co.uk/2020/09/i-like-to-move-it-windows-lateral-movement-part-1-wmi-event-subscription/","https://threathunterplaybook.com/hunts/windows/200902-RemoteWMIActiveScriptEventConsumers/notebook.html"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.lateral-movement","attack.privilege-escalation","attack.persistence","attack.t1546.003"],"path":"rules/windows/image_load/image_load_scrcons_wmi_scripteventconsumer.yml","techniques":["T1546.003"],"cves":[]},{"id":"ebef4391-1a81-4761-a40a-1db446c0e625","title":"NewActiveScriptEventConsumer Creation Attempt via Wmic.EXE","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-06-25","modified":"2026-06-19","description":"Detects the attempt to create an ActiveScriptEventConsumer via WMIC.EXE.\nAn ActiveScriptEventConsumer is a built-in Windows Management Instrumentation (WMI) class that\nautomatically executes a predefined script (in VBScript or JScript) whenever a specific system event occurs.\nAdversaries often abuse ActiveScriptEventConsumer to maintain persistence on a compromised host by executing a malicious script whenever a specific event occurs.\n","references":["https://twitter.com/johnlatwc/status/1408062131321270282?s=12","https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1546.003"],"path":"rules/windows/process_creation/proc_creation_win_wmic_eventconsumer_creation.yml","techniques":["T1546.003"],"cves":[]},{"id":"ec1d5e28-8f3b-4188-a6f8-6e8df81dc28e","title":"WMI Persistence - Script Event Consumer","author":"Thomas Patzke","status":"test","level":"medium","date":"2018-03-07","modified":"2022-10-11","description":"Detects the execution of a script event consumer. When scrcons.exe launches, it does so in response to the creation of an ActiveScriptEventConsumer instance\nand will execute registered JScript or VBScript code as a result.\nScript event consumers are a built-in Windows Management Instrumentation (WMI) class that\nautomatically executes a predefined script (in VBScript or JScript) whenever a specific system event occurs.\nAdversaries often abuse script event consumers to maintain persistence on a compromised host\nby executing a malicious script whenever a specific event occurs.\n","references":["https://redcanary.com/blog/threat-detection/child-processes/","https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1546.003"],"path":"rules/windows/process_creation/proc_creation_win_wmi_persistence_script_event_consumer.yml","techniques":["T1546.003"],"cves":[]},{"id":"f033f3f3-fd24-4995-97d8-a3bb17550a88","title":"WMI Persistence - Security","author":"Florian Roth (Nextron Systems), Gleb Sukhodolskiy, Timur Zinniatullin oscd.community","status":"test","level":"medium","date":"2017-08-22","modified":"2022-11-29","description":"Detects suspicious WMI event filter and command line event consumer based on WMI and Security Logs.","references":["https://twitter.com/mattifestation/status/899646620148539397","https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/"],"logsource":{"product":"windows","service":"security"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1546.003"],"path":"rules/windows/builtin/security/win_security_wmi_persistence.yml","techniques":["T1546.003"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}