Data Source: Windows Event Log WMI Activity 5861

Description

Logs the creation of a permanent WMI event subscription when an event filter is bound to an event consumer, including consumer and filter details.

Details

Property Value
Source XmlWinEventLog:Microsoft-Windows-WMI-Activity/Operational
Sourcetype XmlWinEventLog
Separator EventID
Name ▲▼ Technique ▲▼ Type ▲▼
WMI Permanent Event Subscription Windows Management Instrumentation Event Subscription Anomaly

Event Fields

+ Fields
  <span class="pill kill-chain">_time</span>
  
  <span class="pill kill-chain">Channel</span>
  
  <span class="pill kill-chain">Computer</span>
  
  <span class="pill kill-chain">EventCode</span>
  
  <span class="pill kill-chain">System_Props_Xml</span>
  
  <span class="pill kill-chain">UserData_Xml</span>
  
  <span class="pill kill-chain">EventID</span>
  
  <span class="pill kill-chain">EventRecordID</span>
  
  <span class="pill kill-chain">Guid</span>
  
  <span class="pill kill-chain">Keywords</span>
  
  <span class="pill kill-chain">Level</span>
  
  <span class="pill kill-chain">Opcode</span>
  
  <span class="pill kill-chain">ProcessID</span>
  
  <span class="pill kill-chain">SystemTime</span>
  
  <span class="pill kill-chain">Task</span>
  
  <span class="pill kill-chain">TaskCategory</span>
  
  <span class="pill kill-chain">ThreadID</span>
  
  <span class="pill kill-chain">UserID</span>
  
  <span class="pill kill-chain">Version</span>
  
  <span class="pill kill-chain">source</span>
  
  <span class="pill kill-chain">sourcetype</span>
  
  <span class="pill kill-chain">user_id</span>
  
  <span class="pill kill-chain">vendor_product</span>
  
</div>

Example Log

 1<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='Microsoft-Windows-WMI-Activity' Guid='{1418ef04-b0b4-4623-bf7e-d74ab47bbdaa}'/><EventID>5861</EventID><Version>0</Version><Level>0</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x4000000000000000</Keywords><TimeCreated SystemTime='2026-10-05T09:37:13.4994636Z'/><EventRecordID>24669</EventRecordID><Correlation ActivityID='{3d558c65-3010-0000-25c1-7b3d1030dd01}'/><Execution ProcessID='2448' ThreadID='7872'/><Channel>Microsoft-Windows-WMI-Activity/Operational</Channel><Computer>EC2AMAZ-1QDNI6F</Computer><Security UserID='S-1-5-18'/></System><UserData><Operation_ESStoConsumerBinding xmlns='http://manifests.microsoft.com/win/2006/windows/WMI'><Namespace>//./root/subscription</Namespace><ESS>AtomicRedTeam_filter</ESS><CONSUMER>CommandLineEventConsumer="AtomicRedTeam_consumer"</CONSUMER><PossibleCause>Binding EventFilter: 
 2instance of __EventFilter
 3{
 4	CreatorSID = {1, 5, 0, 0, 0, 0, 0, 5, 21, 0, 0, 0, 95, 211, 181, 28, 123, 4, 131, 205, 168, 40, 205, 106, 244, 1, 0, 0};
 5	EventNamespace = "root\\subscription";
 6	Name = "AtomicRedTeam_filter";
 7	Query = "SELECT * FROM __InstanceCreationEvent Within 3 Where TargetInstance Isa \"Win32_Process\" And Targetinstance.Name = \"notepad.exe\" ";
 8	QueryLanguage = "WQL";
 9};
10Perm. Consumer: 
11instance of CommandLineEventConsumer
12{
13	CommandLineTemplate = "cmd.exe";
14	CreatorSID = {1, 5, 0, 0, 0, 0, 0, 5, 21, 0, 0, 0, 95, 211, 181, 28, 123, 4, 131, 205, 168, 40, 205, 106, 244, 1, 0, 0};
15	Name = "AtomicRedTeam_consumer";
16	RunInteractively = FALSE;
17};
18</PossibleCause></Operation_ESStoConsumerBinding></UserData></Event>

Required Output Fields

  • dest

Source: GitHub | Version: 1