WMI: PowerShell Analysis
Prerequisites
Step 1: Access the WMI Namespace
# Open PowerShell with administrative privileges
# Navigate to the root\subscription namespace
Get-WmiObject -Namespace "root\subscription" -ListStep 2: List WMI Event Consumers
Get-WmiObject -Namespace "root\subscription" -Class __EventConsumerStep 3: Investigate Event Filters
Step 4: Examine Filter to Consumer Bindings
Step 5: Inspect Specific Consumers for Malicious Activity
Step 6: Analyze Scripts and Executables
Step 7: Review the WMI Activity Log
Last updated