WMI Event Subscription Persistence via wmic or PowerShell (T1546.003)
Detects the use of administrative tools like wmic.exe, powershell.exe, or pwsh.exe to invoke WMI event subscription components such as ActiveScriptEventConsumer, CommandLineEventConsumer, or FilterToConsumerBinding. This behavior is a common technique for establishing persistence or elevating privileges by executing malicious code when specific system events occur.
SentinelOne

