<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>WMI Parser — Blog</title>
    <link>https://www.wmiparser.com/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Tue, 29 Sep 2026 12:45:29 GMT</lastBuildDate>
    <atom:link href="https://www.wmiparser.com/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>SCCM RecentlyUsedApps: evidence of execution in WMI</title>
      <link>https://www.wmiparser.com/en/blog/sccm-recentlyusedapps-evidence-of-execution</link>
      <guid isPermaLink="true">https://www.wmiparser.com/en/blog/sccm-recentlyusedapps-evidence-of-execution</guid>
      <description>Read CCM_RecentlyUsedApps from the WMI repository: which programs each user ran, when last and how often, including older copies carved from OBJECTS.DATA.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 29 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>WMI Persistence Investigation Checklist</title>
      <link>https://www.wmiparser.com/en/blog/wmi-persistence-investigation-checklist</link>
      <guid isPermaLink="true">https://www.wmiparser.com/en/blog/wmi-persistence-investigation-checklist</guid>
      <description>Step-by-step checklist for WMI persistence: live queries, the repository, event IDs 5860 and 5861, Sysmon 19-21, execution evidence and a safe clean-up.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SCM Event Log Consumer and BVTConsumer: Benign or Not?</title>
      <link>https://www.wmiparser.com/en/blog/scm-event-log-consumer-bvtconsumer</link>
      <guid isPermaLink="true">https://www.wmiparser.com/en/blog/scm-event-log-consumer-bvtconsumer</guid>
      <description>The two WMI subscriptions Windows ships — SCM Event Log and BVTFilter/BVTConsumer — what they contain, why they are harmless, and how attackers can abuse the names.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Recovering Deleted WMI Persistence From OBJECTS.DATA</title>
      <link>https://www.wmiparser.com/en/blog/recover-deleted-wmi-persistence</link>
      <guid isPermaLink="true">https://www.wmiparser.com/en/blog/recover-deleted-wmi-persistence</guid>
      <description>Why deleted WMI filters, consumers and bindings survive in OBJECTS.DATA, how index walking and carving differ, and how python-cim and PyWMIPersistenceFinder compare.</description>
      <author>Florian Amette</author>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to Collect the WMI Repository for Forensics</title>
      <link>https://www.wmiparser.com/en/blog/collect-wmi-repository</link>
      <guid isPermaLink="true">https://www.wmiparser.com/en/blog/collect-wmi-repository</guid>
      <description>Where the WMI repository lives and how to copy OBJECTS.DATA, INDEX.BTR and the MAPPING files safely: shadow copy, KAPE WBEM target, Velociraptor or an image.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Inside OBJECTS.DATA: WMI Repository Forensics</title>
      <link>https://www.wmiparser.com/en/blog/wmi-repository-objects-data-forensics</link>
      <guid isPermaLink="true">https://www.wmiparser.com/en/blog/wmi-repository-objects-data-forensics</guid>
      <description>How the WMI CIM repository stores objects: OBJECTS.DATA pages, INDEX.BTR keys, the three MAPPING files, class definitions, instances and name hashes.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 23 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>WMI Event Subscription Persistence Explained</title>
      <link>https://www.wmiparser.com/en/blog/wmi-event-subscription-persistence</link>
      <guid isPermaLink="true">https://www.wmiparser.com/en/blog/wmi-event-subscription-persistence</guid>
      <description>How WMI event subscription persistence works: __EventFilter, event consumers and __FilterToConsumerBinding, where they are stored and how to find them.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 22 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>