Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0086 — Detect WMI Event Subscription for Persistence via WmiPrvSE Process and MOF Compilation
DET0086

Detect WMI Event Subscription for Persistence via WmiPrvSE Process and MOF Compilation

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0236 Analytic 0236
Windows

Monitor for creation of WMI EventFilter, EventConsumer, and FilterToConsumerBinding objects through WMI or MOF file execution. Detect command-line execution of `mofcomp.exe`, usage of `Register-WmiEvent` via PowerShell, and anomalous child processes of `WmiPrvSE.exe` that indicate triggered execution. Look for lateral anomalies in process lineage and WMI logging channels.

WinEventLog:WMI EventCode=5857, 5858, 5860, 5861 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=7
[TimeWindow] Defines temporal correlation range between WMI creation and child process execution
[UserContext] Tune for specific accounts (e.g., SYSTEM or attacker-controlled users)
[ProcessNameAllowlist] Used to exclude known benign consumers triggered via WMI (e.g., backup tools)
[ParentProcessAnomalyThreshold] Defines what constitutes anomalous spawning from WmiPrvSE.exe

Detected Techniques

1

Details

MITRE ID
DET0086
STIX ID
x-mitre-detection-strategy--99e60eb7-f2fa-4423-8c51-29832cd6e7ef
Analytics
1
Techniques Detected
1
By Tactic
Privilege Escalation
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.