WMI Event Subscription Persistence via Sysmon EventCode 19/20/21
Detects the creation or modification of Windows Management Instrumentation (WMI) event subscriptions (filters, consumers, and bindings) that target potentially malicious destinations like cmd.exe, PowerShell, or files located in common user-writable directories like Temp or AppData, or multiple concurrent WMI subscription activities which may indicate persistence mechanisms.
Splunk (SPL)

