PowerShell WMI event subscription persistence via New-CimInstance in ScriptBlockText

Finds PowerShell creating WMI __EventFilter and CommandLineEventConsumer objects for event-triggered persistence.

FreeUnreviewedSigmamediumv1
title: PowerShell WMI event subscription persistence via New-CimInstance in ScriptBlockText
id: 208ea252-9e36-4411-afd5-f232afd6db78
status: test
description: This rule identifies PowerShell script blocks that create WMI persistence by using New-CimInstance to write to the root\subscription namespace. It specifically looks for creation of an __EventFilter and a CommandLineEventConsumer, which can be used to trigger malicious commands in response to WMI events. The detection relies on Script Block Logging telemetry and matches on ScriptBlockText content strings indicating the WMI classes and parameters used.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1546.003/T1546.003.md
  - https://github.com/EmpireProject/Empire/blob/08cbd274bef78243d7a8ed6443b8364acd1fc48b/data/module_source/persistence/Persistence.psm1#L545
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_wmi_persistence.yml
author: frack113, Huntrule Team
date: 2021-08-19
modified: 2022-12-25
tags:
  - attack.persistence
  - attack.privilege-escalation
  - attack.t1546.003
logsource:
  product: windows
  category: ps_script
  definition: "Requirements: Script Block Logging must be enabled"
detection:
  selection_ioc:
    - ScriptBlockText|contains|all:
        - "New-CimInstance "
        - "-Namespace root/subscription "
        - "-ClassName __EventFilter "
        - "-Property "
    - ScriptBlockText|contains|all:
        - "New-CimInstance "
        - "-Namespace root/subscription "
        - "-ClassName CommandLineEventConsumer "
        - "-Property "
  condition: selection_ioc
falsepositives:
  - Unknown
level: medium
license: DRL-1.1
related:
  - id: 9e07f6e7-83aa-45c6-998e-0af26efd0a85
    type: derived

What it detects

This rule identifies PowerShell script blocks that create WMI persistence by using New-CimInstance to write to the root\subscription namespace. It specifically looks for creation of an __EventFilter and a CommandLineEventConsumer, which can be used to trigger malicious commands in response to WMI events. The detection relies on Script Block Logging telemetry and matches on ScriptBlockText content strings indicating the WMI classes and parameters used.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.