Adversary tradecraft 101: Hunting for persistence using Elastic Security (Part 1)
ID: 5162a737-2fed-582e-adc0-a3e3b2ca46a3
STIX ID: report--5162a737-2fed-582e-adc0-a3e3b2ca46a3
Feed Name: Elastic Security Labs
This blog post outlines how attackers maintain persistence and demonstrates hunting and detection for WMI Event Subscriptions (MITRE ATT&CK T1084) using Elastic Security and EQL, including example EQL queries that correlate EventFilter, EventConsumer, and FilterToConsumerBinding creations, guidance on alerting (e.g., Windows Event ID 5861), and integrated Elastic Endpoint/SIEM workflows; it also previews a follow-up covering BITS Jobs (T1197) and Scheduled Tasks (T1053).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
