Skip to content
Sysmon

Sysmon Event ID 19: WMI event filter registered

WmiEvent (WmiEventFilter activity detected)Sysmon event 19 logs a WMI event filter being registered, with namespace, name and WQL query. The first of three events behind WMI subscription persistence.
19
Event ID
19
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
WMI
Default logging
Needs configuration

What event 19 means

Sysmon event 19 records the creation (or deletion) of a WMI __EventFilter: the query that defines when a permanent WMI subscription fires. It logs the namespace, the filter name and the WQL Query.

WMI event subscription is a fileless persistence method: a filter (event 19) defines the trigger, a consumer (event 20) defines the action, and a binding (event 21) links the two. Attackers often use triggers such as system uptime reaching a few minutes, a user logon, or a timer.

Legitimate permanent subscriptions are rare on most endpoints, so every event 19 is worth a look.

When it is logged

Audit policy / configuration

Sysmon installed; filter with <WmiEvent> rules in the configuration.

Key fields

FieldWhat it tells you
EventTypeWmiFilterEvent for this event.
OperationCreated for a new filter; removal is also recorded.
UserAccount that registered the filter.
EventNamespaceWMI namespace the filter watches, commonly root\cimv2.
NameName of the filter. Random or product-imitating names are common in attacks.
QueryWQL query that triggers the subscription, e.g. a __InstanceModificationEvent on Win32_PerfFormattedData_PerfOS_System for uptime.

Common benign sources

  • Built-in or legacy filters such as SCM Event Log Filter and BVTFilter on older systems.
  • Management agents (SCCM, hardware vendor tools) registering their own subscriptions.

What attackers do that produces it

  • A new filter created by PowerShell or wmic right before events 20 and 21 — WMI persistence being installed.
  • Filters triggering on uptime or logon to relaunch a backdoor after every reboot.

Investigation tips

  • Collect events 19, 20 and 21 around the same time to rebuild the full subscription.
  • Compare the filter Name against a fleet baseline; new names on single hosts stand out.
  • Check WMI-Activity 5861 for the same subscription and query the root\subscription namespace on the host.

MITRE ATT&CK techniques

TechniqueTactics
T1546.003 Event Triggered Execution: Windows Management Instrumentation Event SubscriptionPrivilege Escalation, Persistence

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

3 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 2
  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading