Techniques
Sample rules
WMI Event Subscription
- source: sigma
- technicques:
- t1546
- t1546.003
Description
Detects creation of WMI event subscription persistence method
Detection logic
condition: selection
selection:
EventID:
- 19
- 20
- 21
LoFP
/
exclude legitimate (vetted) use of wmi event subscription in your network