Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription.

Tactics
TA0003 TA0004

Sub-technique of
T1546


See: MITRE ATT&CK