Log source category
wmi_event log source Sigma rules
3 Sigma detection rules in the library use the wmi_event log source, mostly on windows. The wmi_event category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
3 rules
Suspicious Encoded Scripts in a WMI Consumer
highDetects suspicious encoded payloads in WMI Event Consumers
windows
Suspicious Scripting in a WMI Consumer
highDetects suspicious commands that are related to scripting/powershell in WMI Event Consumers
windows
WMI Event Subscription
mediumDetects creation of WMI event subscription persistence method
windows