Sysmon Event ID 20: WMI event consumer registered
- Event ID
- 20
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- WMI
- Default logging
- Needs configuration
What event 20 means
Sysmon event 20 records a permanent WMI event consumer: the action that runs when a filter fires. Type says what kind of consumer it is and Destination holds what it executes — a command line or script text.
Command-line and script consumers are the ones attackers use for persistence, launching PowerShell, mshta.exe or a dropped binary as SYSTEM whenever the trigger occurs. Read Destination in full; it is often an encoded PowerShell command.
When it is logged
Sysmon installed; filter with <WmiEvent> rules in the configuration.
Key fields
| Field | What it tells you |
|---|---|
| EventType | WmiConsumerEvent for this event. |
| Operation | Created for a new consumer; removal is also recorded. |
| User | Account that registered the consumer. |
| Name | Name of the consumer. |
| Type | Consumer type, e.g. Command Line (CommandLineEventConsumer) or Script (ActiveScriptEventConsumer). |
| Destination | Command line or script the consumer executes. The key field to review. |
Common benign sources
- Legacy
BVTConsumerorSCM Event Log Consumeron older Windows versions. - Management and monitoring agents registering consumers during installation.
What attackers do that produces it
- A
Command Lineconsumer launchingpowershell.exe -enc ...or a binary inProgramData. - A
Scriptconsumer running VBScript or JScript stored directly in WMI.
Investigation tips
- Decode and read Destination; note any file paths and URLs it references.
- Find the matching filter (event 19) and binding (event 21) to learn the trigger.
- Look for processes spawned by
WmiPrvSE.exeorscrcons.exe(event 1) when the trigger fires.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1546.003 Event Triggered Execution: Windows Management Instrumentation Event Subscription | Privilege Escalation, Persistence |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
3 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 2
- Medium · 1
- HighSuspicious Encoded Scripts in a WMI ConsumerRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighSuspicious Scripting in a WMI ConsumerRule by Florian Roth (Nextron Systems), Jonhnathan Ribeiro, SigmaHQ, DRL 1.1
- MediumWMI Event SubscriptionRule by Tom Ueltschi (@c_APT_ure), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.