<span class="pill kill-chain">_time</span>
<span class="pill kill-chain">Channel</span>
<span class="pill kill-chain">Computer</span>
<span class="pill kill-chain">EventCode</span>
<span class="pill kill-chain">System_Props_Xml</span>
<span class="pill kill-chain">UserData_Xml</span>
<span class="pill kill-chain">EventID</span>
<span class="pill kill-chain">EventRecordID</span>
<span class="pill kill-chain">Guid</span>
<span class="pill kill-chain">Keywords</span>
<span class="pill kill-chain">Level</span>
<span class="pill kill-chain">Opcode</span>
<span class="pill kill-chain">ProcessID</span>
<span class="pill kill-chain">SystemTime</span>
<span class="pill kill-chain">Task</span>
<span class="pill kill-chain">TaskCategory</span>
<span class="pill kill-chain">ThreadID</span>
<span class="pill kill-chain">UserID</span>
<span class="pill kill-chain">Version</span>
<span class="pill kill-chain">source</span>
<span class="pill kill-chain">sourcetype</span>
<span class="pill kill-chain">user_id</span>
<span class="pill kill-chain">vendor_product</span>
</div>
Data Source: Windows Event Log WMI Activity 5861
Description
Logs the creation of a permanent WMI event subscription when an event filter is bound to an event consumer, including consumer and filter details.
Details
| Property | Value |
|---|---|
| Source | XmlWinEventLog:Microsoft-Windows-WMI-Activity/Operational |
| Sourcetype | XmlWinEventLog |
| Separator | EventID |
Related Detections
| Name | Technique | Type |
|---|---|---|
| WMI Permanent Event Subscription | Windows Management Instrumentation Event Subscription | Anomaly |
Event Fields
Fields
Example Log
1<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='Microsoft-Windows-WMI-Activity' Guid='{1418ef04-b0b4-4623-bf7e-d74ab47bbdaa}'/><EventID>5861</EventID><Version>0</Version><Level>0</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x4000000000000000</Keywords><TimeCreated SystemTime='2026-10-05T09:37:13.4994636Z'/><EventRecordID>24669</EventRecordID><Correlation ActivityID='{3d558c65-3010-0000-25c1-7b3d1030dd01}'/><Execution ProcessID='2448' ThreadID='7872'/><Channel>Microsoft-Windows-WMI-Activity/Operational</Channel><Computer>EC2AMAZ-1QDNI6F</Computer><Security UserID='S-1-5-18'/></System><UserData><Operation_ESStoConsumerBinding xmlns='http://manifests.microsoft.com/win/2006/windows/WMI'><Namespace>//./root/subscription</Namespace><ESS>AtomicRedTeam_filter</ESS><CONSUMER>CommandLineEventConsumer="AtomicRedTeam_consumer"</CONSUMER><PossibleCause>Binding EventFilter:
2instance of __EventFilter
3{
4 CreatorSID = {1, 5, 0, 0, 0, 0, 0, 5, 21, 0, 0, 0, 95, 211, 181, 28, 123, 4, 131, 205, 168, 40, 205, 106, 244, 1, 0, 0};
5 EventNamespace = "root\\subscription";
6 Name = "AtomicRedTeam_filter";
7 Query = "SELECT * FROM __InstanceCreationEvent Within 3 Where TargetInstance Isa \"Win32_Process\" And Targetinstance.Name = \"notepad.exe\" ";
8 QueryLanguage = "WQL";
9};
10Perm. Consumer:
11instance of CommandLineEventConsumer
12{
13 CommandLineTemplate = "cmd.exe";
14 CreatorSID = {1, 5, 0, 0, 0, 0, 0, 5, 21, 0, 0, 0, 95, 211, 181, 28, 123, 4, 131, 205, 168, 40, 205, 106, 244, 1, 0, 0};
15 Name = "AtomicRedTeam_consumer";
16 RunInteractively = FALSE;
17};
18</PossibleCause></Operation_ESStoConsumerBinding></UserData></Event>
Required Output Fields
- dest
Source: GitHub | Version: 1