Skip to content

DS0005 WMI

The infrastructure for management data and operations that enables local and remote management of Windows personal computers and servers12

Item Value
ID DS0005
Platforms Windows
Collection Layers Host
Version 1.0
Created 20 October 2021
Last Modified 10 November 2021

Data Components

WMI Creation

Initial construction of a WMI object, such as a filter, consumer, subscription, binding, or provider (ex: Sysmon EIDs 19-21)

Domain ID Name
enterprise T1546 Event Triggered Execution
enterprise T1546.003 Windows Management Instrumentation Event Subscription
enterprise T1027 Obfuscated Files or Information
enterprise T1027.011 Fileless Storage

References