Failed WMI NTEventLogFile ClearEventLog attempts (Windows WMI Event 5858)

Alerts on WMI errors (Event 5858) tied to attempted NTEventLogFile ClearEventLog calls on Windows.

FreeReviewedSigma · Medium · v2
Product
windows
Service
wmi
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-07-01
Updated
2026-07-31

ATT&CK techniques

  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule flags failed attempts to clear Windows event logs using the WMI NTEventLogFile ClearEventLog method. It matches error event 5858 in the WMI-Activity operational log where the operation contains the Win32_NTEventlogFile class and the cleareventlog action. Attackers may attempt event-log tampering, and failures often indicate attempts blocked by insufficient privileges or other WMI provider issues. The rule relies on WMI-Activity event telemetry and the presence of the specified class/action strings in the event fields.

Related detections9 linkedT1685.005 — drag to rearrange
Malicious Security Event Log Disabled via wevtutil
Suspicious Event Log Clearing via Wevtutil (via process_creation)
Suspicious Mass Windows Event Log Clearing via PowerShell (via ps_script)
Malicious Event Log Clear Attempt - Wmi (via process_creation)
Malicious Event Log Clear Attempt - Command (via process_creation)
Malicious Event Log Cleared Using Diagnostics - Via PowerShell (via powershell)
Malicious Clearing of Windows Event Logs (via process_creation)
Suspicious Event Log Clearing via wevtutil During Ransomware Activity
Suspicious Event Log Clearing via Get-WinEvent ClearLog (Qilin)
Failed WMI NTEventLogFile ClearEventLog attempts (Windows WMI Event 5858)
Pivot detection · T1685.005 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.