WMI Event Subscription Persistence via wmic, PowerShell, or mofcomp
Detects the creation or manipulation of WMI event subscriptions using wmic.exe, powershell.exe, or mofcomp.exe. These tools are commonly abused by adversaries to establish persistence by triggering malicious code execution via WMI event filters, consumers, and bindings.
SentinelOne

