Skip to content
Sysmon

Sysmon Event ID 20: WMI event consumer registered

WmiEvent (WmiEventConsumer activity detected)Sysmon event 20 logs a WMI event consumer being registered, including the command or script it runs. The action half of WMI subscription persistence.
20
Event ID
20
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
WMI
Default logging
Needs configuration

What event 20 means

Sysmon event 20 records a permanent WMI event consumer: the action that runs when a filter fires. Type says what kind of consumer it is and Destination holds what it executes — a command line or script text.

Command-line and script consumers are the ones attackers use for persistence, launching PowerShell, mshta.exe or a dropped binary as SYSTEM whenever the trigger occurs. Read Destination in full; it is often an encoded PowerShell command.

When it is logged

Audit policy / configuration

Sysmon installed; filter with <WmiEvent> rules in the configuration.

Key fields

FieldWhat it tells you
EventTypeWmiConsumerEvent for this event.
OperationCreated for a new consumer; removal is also recorded.
UserAccount that registered the consumer.
NameName of the consumer.
TypeConsumer type, e.g. Command Line (CommandLineEventConsumer) or Script (ActiveScriptEventConsumer).
DestinationCommand line or script the consumer executes. The key field to review.

Common benign sources

  • Legacy BVTConsumer or SCM Event Log Consumer on older Windows versions.
  • Management and monitoring agents registering consumers during installation.

What attackers do that produces it

  • A Command Line consumer launching powershell.exe -enc ... or a binary in ProgramData.
  • A Script consumer running VBScript or JScript stored directly in WMI.

Investigation tips

  • Decode and read Destination; note any file paths and URLs it references.
  • Find the matching filter (event 19) and binding (event 21) to learn the trigger.
  • Look for processes spawned by WmiPrvSE.exe or scrcons.exe (event 1) when the trigger fires.

MITRE ATT&CK techniques

TechniqueTactics
T1546.003 Event Triggered Execution: Windows Management Instrumentation Event SubscriptionPrivilege Escalation, Persistence

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

3 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 2
  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading