A hunt enumerated existing WMI subscriptions estate-wide; the promoted rule watches creation events. What coverage was lost?
answer
- the query asked what is, the rule asks what happens next
- the rule would not have caught the hunt's own finding
- reach starts at telemetry-on, per host
- state view and event view each miss what the other sees
- ship a recurring sweep alongside the rule
basics
~20 sEverything already in place. The hunt asked what exists right now; the rule only sees what is created from the moment it goes live, so the entire existing backlog — including anything planted before telemetry reached that host — is invisible to it forever. Promotion has to ship a recurring state sweep alongside the rule.
solid answer
~50 sThe hunt was a **state** question — enumerate the subscriptions present on these hosts today — and the promoted rule is an **event** question: tell me when one is created. Those are different coverages that happen to look alike. The rule's reach begins at deployment, and per host it really begins whenever Sysmon started reporting there, so any subscription planted before that point never generates a creation record and will never fire the rule no matter how long it runs. The finding the hunt made would not have been caught by the rule it produced. So promotion is two artefacts, not one: the event rule for everything from now on, and a recurring state sweep on a stated cadence to cover the backlog and any host whose telemetry lapsed. The event view is not strictly weaker, though — it catches subscriptions created and removed between sweeps, which a state sweep can never see.
go deeper
Understand that a search over what exists right now and a rule that fires when something is created answer different questions. A rule only ever sees what happens after it is switched on.
Be able to explain per-host telemetry start, why a staged agent rollout leaves permanent holes in a creation-event rule, and why deletions being recorded makes the event view useful in its own right.
Demonstrate that you would ship the pair — the event rule plus a stated-cadence state sweep and a one-off retrospective pass — and that you would say out loud which population each one covers.
Own the coverage claim. The risk is not the miss, it is an organisation confidently believing a technique is watched when only future instances are, and you set the standard that a promotion states what it does not cover.
## Two different questions that share a name When a hunter says "I looked for WMI persistence", they may mean either of two things, and the difference decides what a promoted rule actually covers. - A **state sweep** asks: *what subscriptions exist on these hosts right now?* It is answered by querying live hosts or by a fleet query tool that reads the current contents of the `root\subscription` namespace. It sees whatever is there, however old. - An **event rule** asks: *when is a subscription created?* It is answered from telemetry — Sysmon's WMI records — and it sees only changes that happened while telemetry was flowing. Hunts often start as state sweeps because that is the natural way to find something for the first time. Rules are almost always event rules, because that is what a detection platform evaluates. Promotion therefore silently changes the question, and the change is easy to miss precisely because the output looks similar. ## What the event rule cannot see **The existing backlog.** Every subscription already registered when the rule goes live produced its creation record in the past — or produced none at all — so the rule will never fire on it. This includes the very finding that motivated the promotion. If a hunter found a hostile binding by hand on Tuesday and you deploy the rule on Friday, that binding is not covered by your new detection; only the next one is. **Anything planted before telemetry.** The rule's reach per host starts at that host's telemetry start, not at the estate's age. A staged Sysmon rollout, hosts rebuilt from an old image, or a machine that spent months out of the collector's reach all carve holes that no amount of runtime closes. **Telemetry gaps.** If an agent stopped reporting for a week and a subscription was created in that week, the event view has nothing. A later state sweep would still find the object sitting there. ## What the state sweep cannot see It is worth being even-handed, because the honest answer is that neither view subsumes the other. **Short-lived subscriptions.** An adversary who registers a subscription, uses it and deletes it leaves nothing for a sweep to find. The event view captures the whole arc, because deletions are recorded too — Sysmon's WMI records carry an `Operation` field with `Created` and `Deleted` values. A create-then-delete pair on the same consumer name within minutes is a stronger signal than most state findings. **Provenance.** A sweep tells you a subscription exists. The event records tell you *when* it appeared and under which account, which is what makes it correlatable with a logon, a deployment window, or a session you already suspect. **Hosts that are down or unreachable at sweep time.** A sweep is a point-in-time census and it misses whatever was asleep. ## What promotion should actually deliver The defensible promotion is a pair: 1. **The event rule**, anchored on the binding record, narrowed to the claim you can defend, with its threshold, owner and triage notes — covering everything from now on. 2. **A recurring state sweep**, on a stated cadence, covering the backlog and any host whose telemetry lapsed. This is not an alert; it is a scheduled review that produces a small list somebody reads. Its cadence is a capacity decision, and monthly or quarterly is far better than never. Plus, at promotion time, a **one-off retrospective pass**: run the state sweep across the estate once, deliberately, so the backlog is dealt with rather than left as a permanent blind spot behind a rule everyone assumes covers it. ## Why this matters more than it sounds The failure is not that a rule misses something — every rule misses something. The failure is a **coverage claim that is wrong in a specific and confident way**. The team believes the technique is now watched. In fact only future instances are watched, the population most likely to matter (anything an adversary already established) is exempt, and nobody will discover this until an incident finds an old subscription the rule never mentioned. The general form of the lesson goes well beyond WMI. Whenever you promote a hunt into a rule, ask which question the hunt answered and which question the rule answers. If the hunt asked *what is* and the rule asks *what happens next*, you have changed the coverage, and the difference is a backlog that needs its own treatment.
- What does the event view catch that a recurring state sweep never will?Subscriptions that are created and deleted between two sweeps. Sysmon's WMI records carry an Operation field with Deleted as well as Created, so a create-then-delete pair on the same consumer name is visible in telemetry and leaves nothing on the host for a census to find. The event view also gives provenance — the account and the timestamp — which a sweep cannot.
- Your Sysmon rollout finished eight months ago. What does that bound?It bounds the creation rule's reach per host to that host's telemetry start, not to the estate's age. Anything registered before a host was onboarded, or during a period when its agent was not reporting, produced no creation record and never will. That is exactly the population a recurring state sweep exists to cover.
- How often should the accompanying state sweep run?It is a capacity decision, not a security absolute. Pick a cadence the team will genuinely execute and write it down — a quarterly sweep that actually happens beats a monthly one that quietly stops. The important part is that the cadence is stated, so the size of the window the sweep leaves open is a known number rather than an assumption.
Swapping a census for a turnstile counter. The turnstile tells you everyone who walked in after you installed it, and nothing at all about who was already inside.
saying these in an interview costs you the question
- Assumes a creation rule covers what already exists
- Cannot say when the rule's coverage per host begins
- Believes a state sweep is strictly better than event telemetry
- Records the technique as covered by the rule alone
- Forgets that deletions are recorded too