Windows WMI Persistence via Event Filter and Event Consumer (Event IDs 5861 and 5859)

Flags likely WMI-based persistence by spotting event filter/consumer bindings and WMI filter registrations tied to script/command-line consumers.

FreeUnreviewedSigmamediumv1
title: Windows WMI Persistence via Event Filter and Event Consumer (Event IDs 5861 and 5859)
id: d0128ba4-9b04-49d1-9afa-5feaeb8f57db
status: test
description: This rule identifies suspicious Windows Management Instrumentation (WMI) persistence by correlating WMI event filter–to–consumer bindings with specific script-based or command-line consumers. Attackers use these WMI components to execute attacker-controlled logic at scheduled or system-triggered times while blending into legitimate infrastructure. The detection relies on Windows WMI-related logging and Security/Auditing events, matching Event ID 5861 bindings with consumer keyword patterns and Event ID 5859 for WMI filter registrations.
references:
  - https://twitter.com/mattifestation/status/899646620148539397
  - https://www.eideon.com/2018-03-02-THL03-WMIBackdoors/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/wmi/win_wmi_persistence.yml
author: Florian Roth (Nextron Systems), Gleb Sukhodolskiy, Timur Zinniatullin oscd.community, Huntrule Team
date: 2017-08-22
modified: 2022-02-10
tags:
  - attack.persistence
  - attack.privilege-escalation
  - attack.t1546.003
logsource:
  product: windows
  service: wmi
  definition: WMI Namespaces Auditing and SACL should be configured, EventID 5861 and 5859 detection requires Windows 10, 2012 and higher
detection:
  wmi_filter_to_consumer_binding:
    EventID: 5861
  consumer_keywords:
    - ActiveScriptEventConsumer
    - CommandLineEventConsumer
    - CommandLineTemplate
  wmi_filter_registration:
    EventID: 5859
  filter_scmevent:
    Provider: SCM Event Provider
    Query: select * from MSFT_SCMEventLogEvent
    User: S-1-5-32-544
    PossibleCause: Permanent
  condition: ( (wmi_filter_to_consumer_binding and consumer_keywords) or (wmi_filter_registration) ) and not filter_scmevent
falsepositives:
  - Unknown (data set is too small; further testing needed)
level: medium
license: DRL-1.1
related:
  - id: 0b7889b4-5577-4521-a60a-3376ee7f9f7b
    type: derived

What it detects

This rule identifies suspicious Windows Management Instrumentation (WMI) persistence by correlating WMI event filter–to–consumer bindings with specific script-based or command-line consumers. Attackers use these WMI components to execute attacker-controlled logic at scheduled or system-triggered times while blending into legitimate infrastructure. The detection relies on Windows WMI-related logging and Security/Auditing events, matching Event ID 5861 bindings with consumer keyword patterns and Event ID 5859 for WMI filter registrations.

Known false positives

  • Unknown (data set is too small; further testing needed)

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.