Observed arrival · 2026-09-30
WMI Parser: looking for persistence in Windows repositories
A free, browser-based DFIR tool that parses WMI repository files to show event filters, consumers, bindings, and carved deleted objects.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- DFIR analysts investigating Windows WMI persistence
- Worth noticing
- OBJECTS.DATA alone can be used to carve filters, consumers, and bindings; INDEX.BTR and MAPPING files add the structured view.
Field notes
The acquisition guide recommends collecting the Repository folder from a single shadow-copy snapshot because the files are locked while the WMI service is running. A separate PowerShell example queries live bindings directly, with an explicit warning that this method does not show deleted objects and may miss results if WMI is tampered with. The included sample is labeled synthetic, with no real data or working payloads.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
⊠LoginAccess appeared gated
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central
One card from the complete issue