Windows WMI Event Consumer with Encoded Payload Containing Suspicious Strings
Detects WMI event consumer encoded payloads containing suspicious execution-related strings on Windows.
- Product
- windows
- Category
- wmi_event
- Author
- Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2021-09-01
- Updated
- 2026-07-30
ATT&CK techniques
Execution → Priv EscRecon
Resource Dev
Initial Access
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows WMI Event Consumer activity where an encoded value includes specific strings associated with suspicious memory/process execution behaviors. Such payloads can be used to hide commands or stage follow-on actions through WMI-driven execution. The detection relies on telemetry from WMI event data, specifically the presence of these substrings within the encoded field.
Reporting behind it
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows WMI Event Consumer with Encoded Payload Containing Suspicious Strings
id: 48313ca5-fa7a-4047-bcf5-4fccc7deb4b4
status: test
description: This rule flags Windows WMI Event Consumer activity where an encoded value includes specific strings associated with suspicious memory/process execution behaviors. Such payloads can be used to hide commands or stage follow-on actions through WMI-driven execution. The detection relies on telemetry from WMI event data, specifically the presence of these substrings within the encoded field.
references:
- https://github.com/RiccardoAncarani/LiquidSnake
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/wmi_event/sysmon_wmi_susp_encoded_scripts.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2021-09-01
modified: 2022-10-09
tags:
- attack.privilege-escalation
- attack.execution
- attack.t1047
- attack.persistence
- attack.t1546.003
logsource:
product: windows
category: wmi_event
detection:
selection_destination:
Destination|base64offset|contains:
- WriteProcessMemory
- This program cannot be run in DOS mode
- This program must be run under Win32
condition: selection_destination
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 83844185-1c5b-45bc-bcf3-b5bf3084ca5b
type: derived