Skip to content

feat: validate T1546.003 WMI event subscriptions - #22

Open
egrexsec wants to merge 1 commit into
mainfrom
feat/pt-2026-013-wmi-event-subscription
Open

egrexsec wants to merge 1 commit into
mainfrom
feat/pt-2026-013-wmi-event-subscription

Conversation

@egrexsec

@egrexsec egrexsec commented Aug 3, 2026

Copy link
Copy Markdown
Owner

Summary

  • live-validates Atomic Red Team T1546.003 test UUID 3c64f177-28e2-49eb-a799-d767b24dd1e0 on the approved Windows victim
  • adds a behavioral Sysmon WMI subscription Sigma rule for Event IDs 19–21, generated Splunk/Elastic queries, two positive fixtures, and three negative fixtures
  • records the exact Atomic positive, modified non-triggering variant, three negative controls, cleanup, hunt, DFIR workflow, and sanitized evidence
  • updates campaign metrics to 13 validated techniques and 69 fixtures

Validation

  • exact Atomic and modified variant both detected in live Splunk telemetry
  • exact-positive latency: 4.486 seconds
  • modified-positive latency: 0.994 seconds
  • all three controls remained quiet
  • 16/16 unit tests passed
  • 69/69 Sigma fixtures passed
  • schema, Sigma lint/conversion, prior validation records, lifecycle manifest, metrics, Markdown links, and diff checks passed

Safety and cleanup

  • victim-local execution only; exact Atomic UUID pinned to prevent sibling-test execution
  • rollback capability verified, with the private snapshot identifier omitted from public artifacts
  • victim uptime exceeded the Atomic payload trigger interval, and a bounded Sysmon Event ID 1 search found zero notepad.exe matches during the exact-positive window
  • modified variant used a non-triggering condition
  • bindings removed and rechecked through association-aware REFERENCES OF queries before consumers and filters
  • final and idempotence cleanup checks returned zero WMI objects or completion artifacts with Clean=true
  • victim sensors, secure channel, SIEM ingestion, and domain-controller health remained operational

Review

  • final staged tree independently approved before commit
  • exact commit verification completed before push

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1edb002cfd

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +36 to +37
if (Get-WmiObject -Namespace $namespace -Class __EventFilter -Filter "Name = '$name'" -ErrorAction SilentlyContinue) { "filter:$name" }
if (Get-WmiObject -Namespace $namespace -Class CommandLineEventConsumer -Filter "Name = '$name'" -ErrorAction SilentlyContinue) { "consumer:$name" }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Fail cleanup when WMI verification queries error

If a final WMI query fails because the provider is unavailable, permissions changed, or the namespace cannot be queried, -ErrorAction SilentlyContinue converts that failure into an empty result, so $remaining stays empty and the script reports Clean=true even though the preceding removals may also have failed. For this persistence scenario, make the verification queries terminating or explicitly check their success before certifying cleanup.

Useful? React with 👍 / 👎.

@@ -0,0 +1 @@
search index=main source="WinEventLog:Microsoft-Windows-Sysmon/Operational" (_raw="*<EventID>19</EventID>*" OR _raw="*<EventID>20</EventID>*" OR _raw="*<EventID>21</EventID>*") (_raw="*<Data Name='Operation'>*Created*") AND ((_raw="*<Data Name='EventType'>*WmiFilterEvent*" OR _raw="*<Data Name='EventType'>*WmiConsumerEvent*" OR _raw="*<Data Name='EventType'>*WmiBindingEvent*"))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Bound Operation matching to its XML element

In the generated Mayuri live query, _raw="*<Data Name='Operation'>*Created*" does not require Created to be the value of Operation; it can occur in any later XML field. For example, a Sysmon Event 19 deletion whose filter name or WQL text contains Created will satisfy this clause and be reported as a creation, contrary to the Sigma rule and the negative deletion contract. Match Created before the corresponding </Data> boundary for exact-value fields.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant