PowerShell WMI event subscription persistence via New-CimInstance in ScriptBlockText
Finds PowerShell creating WMI __EventFilter and CommandLineEventConsumer objects for event-triggered persistence.
FreeUnreviewedSigmamediumv1
powershell-wmi-event-subscription-persistence-via-new-ciminstance-in-scriptblock-9e07f6e7
title: PowerShell WMI event subscription persistence via New-CimInstance in ScriptBlockText
id: 208ea252-9e36-4411-afd5-f232afd6db78
status: test
description: This rule identifies PowerShell script blocks that create WMI persistence by using New-CimInstance to write to the root\subscription namespace. It specifically looks for creation of an __EventFilter and a CommandLineEventConsumer, which can be used to trigger malicious commands in response to WMI events. The detection relies on Script Block Logging telemetry and matches on ScriptBlockText content strings indicating the WMI classes and parameters used.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.003/T1546.003.md
- https://github.com/EmpireProject/Empire/blob/08cbd274bef78243d7a8ed6443b8364acd1fc48b/data/module_source/persistence/Persistence.psm1#L545
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_wmi_persistence.yml
author: frack113, Huntrule Team
date: 2021-08-19
modified: 2022-12-25
tags:
- attack.persistence
- attack.privilege-escalation
- attack.t1546.003
logsource:
product: windows
category: ps_script
definition: "Requirements: Script Block Logging must be enabled"
detection:
selection_ioc:
- ScriptBlockText|contains|all:
- "New-CimInstance "
- "-Namespace root/subscription "
- "-ClassName __EventFilter "
- "-Property "
- ScriptBlockText|contains|all:
- "New-CimInstance "
- "-Namespace root/subscription "
- "-ClassName CommandLineEventConsumer "
- "-Property "
condition: selection_ioc
falsepositives:
- Unknown
level: medium
license: DRL-1.1
related:
- id: 9e07f6e7-83aa-45c6-998e-0af26efd0a85
type: derived
What it detects
This rule identifies PowerShell script blocks that create WMI persistence by using New-CimInstance to write to the root\subscription namespace. It specifically looks for creation of an __EventFilter and a CommandLineEventConsumer, which can be used to trigger malicious commands in response to WMI events. The detection relies on Script Block Logging telemetry and matches on ScriptBlockText content strings indicating the WMI classes and parameters used.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.