WMI log analysis

by Igor Mikhaylov2017-10-19

Carlos Perez previously talked about how Microsoft expanded the WMI log in the latest versions of its client and server operating systems. He decided to describe what kind of new version events were added to special versions of events 6.10 for registering persistent events in this article.


In conclusion, Carlos notes that registering with Sysmon extends what we can already enter into the new versions of Windows, and provides better consistency and understanding of events such as Pervants and their components that are not present in the current Windows session. He advises on the  logging of all events related to persistent WMI events and advises.

Do not filter in the configuration file, because creating them is not usual for the aday-day operation. More information about new events can be found in this article.



