PowerShell WMI Event Subscription Persistence via New-CimInstance
Finds PowerShell creating WMI __EventFilter and CommandLineEventConsumer objects for event-triggered persistence.
- Product
- windows
- Category
- ps_script
- Author
- frack113 (SigmaHQ), DRL 1.1
- Published
- 2021-08-19
- Updated
- 2026-07-31
ATT&CK techniques
Persistence → Priv EscRecon
Resource Dev
Initial Access
Execution
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies PowerShell script block content that creates WMI event subscription components using New-CimInstance. It looks for creation of an __EventFilter and a CommandLineEventConsumer under the root/subscription namespace, which can be used by attackers to establish persistence and execute payloads triggered by WMI events. The detection relies on Script Block Logging telemetry containing the relevant parameter strings in the executed PowerShell code.
Reporting behind it
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.003/T1546.003.md
- github.comhttps://github.com/EmpireProject/Empire/blob/08cbd274bef78243d7a8ed6443b8364acd1fc48b/data/module_source/persistence/Persistence.psm1#L545
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_wmi_persistence.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: PowerShell WMI Event Subscription Persistence via New-CimInstance
id: 208ea252-9e36-4411-afd5-f232afd6db78
status: test
description: This rule identifies PowerShell script block content that creates WMI event subscription components using New-CimInstance. It looks for creation of an __EventFilter and a CommandLineEventConsumer under the root/subscription namespace, which can be used by attackers to establish persistence and execute payloads triggered by WMI events. The detection relies on Script Block Logging telemetry containing the relevant parameter strings in the executed PowerShell code.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.003/T1546.003.md
- https://github.com/EmpireProject/Empire/blob/08cbd274bef78243d7a8ed6443b8364acd1fc48b/data/module_source/persistence/Persistence.psm1#L545
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_wmi_persistence.yml
author: frack113, Huntrule Team
date: 2021-08-19
modified: 2022-12-25
tags:
- attack.persistence
- attack.privilege-escalation
- attack.t1546.003
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection_ioc:
- ScriptBlockText|contains|all:
- "New-CimInstance "
- "-Namespace root/subscription "
- "-ClassName __EventFilter "
- "-Property "
- ScriptBlockText|contains|all:
- "New-CimInstance "
- "-Namespace root/subscription "
- "-ClassName CommandLineEventConsumer "
- "-Property "
condition: selection_ioc
falsepositives:
- Unknown
level: medium
license: DRL-1.1
related:
- id: 9e07f6e7-83aa-45c6-998e-0af26efd0a85
type: derived