Persistent Asynchronous and Fileless Backdoor
us-15-Graeber-Abusing-Windows-Management-Instrumentation-WMI-To-Build-A-Persistent Asynchronous-And-Fileless-Backdoor
us-15-Graeber-Abusing-Windows-Management-Instrumentation-WMI-To-Build-A-Persistent Asynchronous-And-Fileless-Backdoor
- No tags were found...
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
WMI Event Type - Intrinsic• Intrinsic events are system classes included in everynamespace• Attacker/defender can make a creative use of these• Must be captured at a polling interval. Use carefully.• Possible to miss event firings.__NamespaceOperationEvent__NamespaceModificationEvent__NamespaceDeletionEvent__NamespaceCreationEvent__ClassOperationEvent__ClassDeletionEvent__ClassModificationEvent__ClassCreationEvent__InstanceOperationEvent__InstanceCreationEvent__MethodInvocationEvent__InstanceModificationEvent__InstanceDeletionEvent__TimerEvent