Glossary
__EventFilter
The WMI class that describes the trigger of an event subscription: a named WQL query, its language and the namespace it watches.
An __EventFilter instance is the when of a WMI subscription. Its properties are Name, Query (a WQL event query), QueryLanguage (WQL), EventNamespace (usually root\cimv2), EventAccess and CreatorSID.
Filters used for persistence often watch system uptime (Win32_PerfFormattedData_PerfOS_System.SystemUpTime), logons, process starts or timers. A filter does nothing until a binding links it to an event consumer.