Skip to content

Instantly share code, notes, and snippets.

Bonjour123

Block or report user

Report or block Bonjour123

Hide content and notifications from this user.

Learn more about blocking users

Contact Support about this user’s behavior.

Learn more about reporting abuse

Report abuse
View GitHub Profile
@Bonjour123
Bonjour123 / getPermanentWMISubscriptionsForAllClasses.ps1
Last active Jun 9, 2019
Getting all permanent WMI subscriptions for all classes
View getPermanentWMISubscriptionsForAllClasses.ps1
##########################Author: Bonjour123#############################
# Althought really convenient, WMI permanent subscriptions can also #
# be used by malwares. They usually are set to get events and trigger #
# some actions (like downloading some scripts), thus allowing some #
# persistance mechanisms. #
# This script returns a list of all the permanent WMI subscriptions for #
# all the different classes, allowing an overall view. #
# More info: https://www.fireeye.com/blog/threat-research/2016/08/wmi_vs_wmi_monitor.html
#########################################################################
$classes = get-wmiobject -namespace root\Subscription -list|select Name|Foreach-object {$_ -split "`r`n"}
You can’t perform that action at this time.