Query Details
Tags: Query: DeviceEvents | where ActionType == 'WmiBindEventFilterToConsumer' | where AdditionalFields !contains "SCM Event Log Filter" and AdditionalFields !contains "CCM_PolicyReplicationConsumer" | extend parsed = parse_json(AdditionalFields) | where parsed.Namespace == @"//./root/subscription" and parsed.PossibleCause !contains @"Win32_Processor" and parsed.Ess != @"DellCommandPowerManagerAlertEventFilter" and parsed.Ess != @"DellCommandPowerManagerPolicyChangeEventFilter" References:
This query is looking at device events to identify specific Windows Management Instrumentation (WMI) activities. Here's a simplified breakdown:
In essence, this query is narrowing down to specific WMI events while excluding certain known benign events.

Ali Hussein
Released: October 11, 2023
Tables
Keywords
Operators