LoFP LoFP / legitimate event consumers

Techniques

Sample rules

WMI ActiveScriptEventConsumers Activity Via Scrcons.EXE DLL Load

Description

Detects signs of the WMI script host process “scrcons.exe” loading scripting DLLs which could indicates WMI ActiveScriptEventConsumers EventConsumers activity.

Detection logic

condition: selection
selection:
  ImageLoaded|endswith:
  - \vbscript.dll
  - \wbemdisp.dll
  - \wshom.ocx
  - \scrrun.dll
  Image|endswith: \scrcons.exe

WMI Persistence - Script Event Consumer

Description

Detects WMI script event consumers

Detection logic

condition: selection
selection:
  Image: C:\WINDOWS\system32\wbem\scrcons.exe
  ParentImage: C:\Windows\System32\svchost.exe