kevmap

Log sources › WinEventLog:WMI

WinEventLog:WMI

Inverted view: what can be detected if this is the log you have. Windows

2
channels
6
analytics
6
techniques
2
KEV CVEs reachable

"Reachable" means: a KEV CVE has a public mapping to a technique, and MITRE's analytic for that technique names this log source. It is a statement about published knowledge, not about whether any particular rule fires.

Channels

ChannelData componentsAnalyticsTechniques
Creation or modification of __EventFilter, __FilterToConsumerBinding, or CommandLineEventConsumer DC0008 WMI Creation AN0024 1
EventCode=5857, 5858, 5860, 5861 DC0008 WMI Creation AN0236 AN1031 AN1177 AN1305 AN1551 5

Techniques detectable from this source

TechniqueTacticsSigma rulesKEV CVEs
T1047 Windows Management Instrumentationexecution522
T1222.001 Windows Permissionsdefense impairment50
T1480 Execution Guardrailsstealth00
T1480.001 Environmental Keyingstealth00
T1546 Event Triggered Executionprivilege escalation, persistence100
T1546.003 Windows Management Instrumentation Event Subscriptionprivilege escalation, persistence120

KEV CVEs reachable from this source

CVEVendor / productVia techniqueState
CVE-2021-40539Zoho ManageEngine T1047 Mapped
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus T1047 Mapped