WMI Event Subscription Persistence via ActiveScript or CommandLine Consumer
This rule detects the use of 'wmic.exe', 'powershell.exe', or 'pwsh.exe' to interact with WMI event consumers (ActiveScriptEventConsumer or CommandLineEventConsumer) and filter bindings. Adversaries use these WMI components to establish persistence by executing malicious code when specific system events occur, such as a process start or a scheduled time trigger.
SentinelOne

