⌕
Showing 5 of 5 events
Reference for native WMI (Windows Management Instrumentation) forensic analysis via the Microsoft-Windows-WMI-Activity/Operational log — available on every Windows host by default, independent of Sysmon. Focused on WMI-based fileless persistence (permanent event consumers), remote execution, and reconnaissance.
Curated highest-signal Sigma-style detection rules for WMI-Activity Event Reference activity, based on patterns from SigmaHQ/sigma. Click any Event ID chip to jump to that event in the reference tab.
Convert to your SIEM: sigconverter.io