Sysmon Event ID 19: WMI event filter registered
- Event ID
- 19
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- WMI
- Default logging
- Needs configuration
What event 19 means
Sysmon event 19 records the creation (or deletion) of a WMI __EventFilter: the query that defines when a permanent WMI subscription fires. It logs the namespace, the filter name and the WQL Query.
WMI event subscription is a fileless persistence method: a filter (event 19) defines the trigger, a consumer (event 20) defines the action, and a binding (event 21) links the two. Attackers often use triggers such as system uptime reaching a few minutes, a user logon, or a timer.
Legitimate permanent subscriptions are rare on most endpoints, so every event 19 is worth a look.
When it is logged
Sysmon installed; filter with <WmiEvent> rules in the configuration.
Key fields
| Field | What it tells you |
|---|---|
| EventType | WmiFilterEvent for this event. |
| Operation | Created for a new filter; removal is also recorded. |
| User | Account that registered the filter. |
| EventNamespace | WMI namespace the filter watches, commonly root\cimv2. |
| Name | Name of the filter. Random or product-imitating names are common in attacks. |
| Query | WQL query that triggers the subscription, e.g. a __InstanceModificationEvent on Win32_PerfFormattedData_PerfOS_System for uptime. |
Common benign sources
- Built-in or legacy filters such as
SCM Event Log FilterandBVTFilteron older systems. - Management agents (SCCM, hardware vendor tools) registering their own subscriptions.
What attackers do that produces it
- A new filter created by PowerShell or
wmicright before events 20 and 21 — WMI persistence being installed. - Filters triggering on uptime or logon to relaunch a backdoor after every reboot.
Investigation tips
- Collect events 19, 20 and 21 around the same time to rebuild the full subscription.
- Compare the filter Name against a fleet baseline; new names on single hosts stand out.
- Check WMI-Activity 5861 for the same subscription and query the
root\subscriptionnamespace on the host.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1546.003 Event Triggered Execution: Windows Management Instrumentation Event Subscription | Privilege Escalation, Persistence |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
3 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 2
- Medium · 1
- HighSuspicious Encoded Scripts in a WMI ConsumerRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighSuspicious Scripting in a WMI ConsumerRule by Florian Roth (Nextron Systems), Jonhnathan Ribeiro, SigmaHQ, DRL 1.1
- MediumWMI Event SubscriptionRule by Tom Ueltschi (@c_APT_ure), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.