Install agent persistence via WMI event subscription

/static/assets/windows-logo.svg
Use a powershell to install a WMI event subscription persistence mechanism. This technique requires setting the #{staging_dir} fact to specify the path the Pneuma agent.
locked
View Command

To view this TTPs command, you must be logged in with a professional or enterprise license.

Login

Test this TTP

Download Operator (1.7.1)
Test this TTP using one of our Operator chains
APT40 maritime industry

2022-04-19

/static/assets/windows-logo.svg
Emulating APT40's malware persistence techniques.