Windows WMI Persistence via Event Filter and Event Consumer (Event IDs 5861 and 5859)
Flags likely WMI-based persistence by spotting event filter/consumer bindings and WMI filter registrations tied to script/command-line consumers.
FreeUnreviewedSigmamediumv1
windows-wmi-persistence-via-event-filter-and-event-consumer-event-ids-5861-and-5-0b7889b4
title: Windows WMI Persistence via Event Filter and Event Consumer (Event IDs 5861 and 5859)
id: d0128ba4-9b04-49d1-9afa-5feaeb8f57db
status: test
description: This rule identifies suspicious Windows Management Instrumentation (WMI) persistence by correlating WMI event filter–to–consumer bindings with specific script-based or command-line consumers. Attackers use these WMI components to execute attacker-controlled logic at scheduled or system-triggered times while blending into legitimate infrastructure. The detection relies on Windows WMI-related logging and Security/Auditing events, matching Event ID 5861 bindings with consumer keyword patterns and Event ID 5859 for WMI filter registrations.
references:
- https://twitter.com/mattifestation/status/899646620148539397
- https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/wmi/win_wmi_persistence.yml
author: Florian Roth (Nextron Systems), Gleb Sukhodolskiy, Timur Zinniatullin oscd.community, Huntrule Team
date: 2017-08-22
modified: 2022-02-10
tags:
- attack.persistence
- attack.privilege-escalation
- attack.t1546.003
logsource:
product: windows
service: wmi
definition: WMI Namespaces Auditing and SACL should be configured, EventID 5861 and 5859 detection requires Windows 10, 2012 and higher
detection:
wmi_filter_to_consumer_binding:
EventID: 5861
consumer_keywords:
- ActiveScriptEventConsumer
- CommandLineEventConsumer
- CommandLineTemplate
wmi_filter_registration:
EventID: 5859
filter_scmevent:
Provider: SCM Event Provider
Query: select * from MSFT_SCMEventLogEvent
User: S-1-5-32-544
PossibleCause: Permanent
condition: ( (wmi_filter_to_consumer_binding and consumer_keywords) or (wmi_filter_registration) ) and not filter_scmevent
falsepositives:
- Unknown (data set is too small; further testing needed)
level: medium
license: DRL-1.1
related:
- id: 0b7889b4-5577-4521-a60a-3376ee7f9f7b
type: derived
What it detects
This rule identifies suspicious Windows Management Instrumentation (WMI) persistence by correlating WMI event filter–to–consumer bindings with specific script-based or command-line consumers. Attackers use these WMI components to execute attacker-controlled logic at scheduled or system-triggered times while blending into legitimate infrastructure. The detection relies on Windows WMI-related logging and Security/Auditing events, matching Event ID 5861 bindings with consumer keyword patterns and Event ID 5859 for WMI filter registrations.
Known false positives
- Unknown (data set is too small; further testing needed)
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.