Skip to content

Series

WMI repository fundamentals

3 posts in this series. Read them in order or jump to any one.

  1. WMI Event Subscription Persistence Explained

    How WMI event subscription persistence works: __EventFilter, event consumers and __FilterToConsumerBinding, where they are stored and how to find them.

  2. Inside OBJECTS.DATA: WMI Repository Forensics

    How the WMI CIM repository stores objects: OBJECTS.DATA pages, INDEX.BTR keys, the three MAPPING files, class definitions, instances and name hashes.

  3. How to Collect the WMI Repository for Forensics

    Where the WMI repository lives and how to copy OBJECTS.DATA, INDEX.BTR and the MAPPING files safely: shadow copy, KAPE WBEM target, Velociraptor or an image.

All posts in this series

How WMI event subscription persistence works: __EventFilter, event consumers and __FilterToConsumerBinding, where they are stored and how to find them.
How the WMI CIM repository stores objects: OBJECTS.DATA pages, INDEX.BTR keys, the three MAPPING files, class definitions, instances and name hashes.
Where the WMI repository lives and how to copy OBJECTS.DATA, INDEX.BTR and the MAPPING files safely: shadow copy, KAPE WBEM target, Velociraptor or an image.