Guided lab: the persistence that leaves almost no log

WMI event subscriptions run code on a condition you choose, survive reboots, live nowhere in the filesystem, and log nothing by default. The last of the persistence series, and the one that changes how you think about the other three.

ATT&CK
T1546.003

Last in the persistence series, after Run keys, scheduled tasks and services. Save it for last on purpose: it only makes sense once you have seen how visible the other three are.

A WMI event subscription is three objects that together mean when this happens, run that. It survives reboots. It has no file on disk. And on a default Windows install it produces no log entry at all when created.

That last property is why this technique matters out of proportion to how often you meet it.

The three objects

Set up

Sysmon with WMI logging enabled, which the SwiftOnSecurity config includes, and Atomic Red Team. Read the tests for T1546.003 and run one that creates all three objects.

What is in this lab

Questions
5
Artifacts
2
Staged hints
8

Sections

  1. The three objects
  2. Set up
  3. The investigation
  4. What the whole series adds up to

The first question, as it appears

Find the subscription in the Sysmon log. Which events fired, and how many?

Its hints are staged from a nudge, to the method, to the answer. Members see all three.

[!] members only

The rest of this teardown — the full timeline, the complete IOC list and the detection rule with its tuning notes — is for members. Sign in if you have an account, or start a 7-day trial. No card is charged and none is collected up front.

sign insee what is included