Techniques
Sample rules
New ActiveScriptEventConsumer Created Via Wmic.EXE
- source: sigma
- technicques:
- t1546
- t1546.003
Description
Detects WMIC executions in which an event consumer gets created. This could be used to establish persistence
Detection logic
condition: selection
selection:
CommandLine|contains|all:
- ActiveScriptEventConsumer
- ' CREATE '