Please enable JavaScript.
Coggle requires JavaScript to display documents.
WMI Attacks - Coggle Diagram
WMI Attacks
Event Consumer Backdoors
Event Consumer
script or executable to run
run as SYSTEM
Binding
tie Filter + Consumer
Event Filter
Conditions
Types
SMTPEventConsumer
NTEventLogEventConsumer
LogFileEventConsumer
CommandLineEventConsumer
ActiveScriptEventConsumer
Custom
Detection
Database
OBJECTS.DATA
INDEX.BTR
PyWMIPersistenceFinder.py
MAPPING[1-3].MAP
Event Consumer
ActiveScriptEventConsumer
wmiprvse.exe
CommandLineEventConsumer
scrcons.exe
Event Log
Powershell
Persistence
CommandLine & ActiveScript
Lateral Movement
process call create
File System
MOF Files
New class definitions & instances
MOF Compiler (mofcomp.exe)
WBEM AutoRecover Folder
PRAGMA AUTORECOVER
AutoRecover Key
Reconnaissance
Privilege Escalation