Compliance Node Overview
MITRE ATT&CK T1546.003 (Windows Management Instrumentation Event Subscription) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription. WMI can be used to install event filters, providers, consumers, and bindings that execute code when a defined event occurs. Examples of events that may be subscribed to are the wall clock time, user login, or the computer's uptime. Affected platforms: Windows. MITRE-documented mitigations include M1018 User Account Management, M1026 Privileged Account Management, M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CA-07, CM-02, CM-03, CM-05.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1546/003/
SHA-256 integrity: 977fbf86f7ed84ccf1ce4543d58171509c7bb08628322c2369e5d23b9f957ead
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1546.003: Windows Management Instrumentation Event Subscription (https://attack.mitre.org/techniques/T1546/003/)
- MITRE ATT&CK Tactic TA0004: Privilege Escalation (https://attack.mitre.org/tactics/TA0004/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access