Guided lab: the persistence that leaves almost no log
WMI event subscriptions run code on a condition you choose, survive reboots, live nowhere in the filesystem, and log nothing by default. The last of the persistence series, and the one that changes how you think about the other three.
Last in the persistence series, after Run keys,
scheduled tasks and
services. Save it for last on purpose: it only
makes sense once you have seen how visible the other three are.
A WMI event subscription is three objects that together mean when this happens,
run that. It survives reboots. It has no file on disk. And on a default Windows
install it produces no log entry at all when created.
That last property is why this technique matters out of proportion to how often
you meet it.
The three objects
Set up
Sysmon with WMI logging enabled, which the SwiftOnSecurity config includes, and
Atomic Red Team. Read the tests for T1546.003 and run one that creates all
three objects.
What is in this lab
Questions
5
Artifacts
2
Staged hints
8
Sections
The three objects
Set up
The investigation
What the whole series adds up to
The first question, as it appears
Find the subscription in the Sysmon log. Which events fired, and how many?
Its hints are staged from a nudge, to the method, to the answer. Members see all three.
[!] members only
The rest of this teardown — the full timeline, the complete IOC list and the detection rule with its tuning notes — is for members. Sign in if you have an account, or start a 7-day trial. No card is charged and none is collected up front.