Persistence via WMI Permanent Event Subscription
Detects the creation of permanent WMI event subscriptions which can be used by adversaries to establish persistence by triggering malicious code execution upon specific system events. The rule monitors Sysmon events 19, 20, and 21 as well as Microsoft-Windows-WMI-Activity logs for modifications involving Event Filters, Consumers, and Bindings, specifically looking for CommandLineEventConsumer or ActiveScriptEventConsumer.
Sigma

