Glossary
CommandLineEventConsumer
The standard WMI consumer that starts a process: CommandLineTemplate, ExecutablePath and WorkingDirectory, launched as SYSTEM when its filter fires.
CommandLineEventConsumer starts a process when its filter fires. The important properties are CommandLineTemplate, ExecutablePath and WorkingDirectory; others control the window, priority and a KillTimeout. The process is started by the WMI provider host (WmiPrvSE.exe) and runs as SYSTEM.
It is the most common consumer in WMI persistence: an encoded PowerShell command or a binary in a user-writable folder are typical findings. Windows' own BVTConsumer is one — see SCM Event Log Consumer and BVTConsumer.