Sysmon Event ID 21: WMI consumer bound to filter
- Event ID
- 21
- Channel
- Microsoft-Windows-Sysmon/Operational
- Provider
- Microsoft-Windows-Sysmon
- Log file
- Microsoft-Windows-Sysmon%4Operational.evtx
- Category
- WMI
- Default logging
- Needs configuration
What event 21 means
Sysmon event 21 records a __FilterToConsumerBinding: the link that makes a filter (event 19) trigger a consumer (event 20). Once this binding exists, the subscription is live and survives reboots.
The event carries the WMI paths of both the consumer and the filter, which lets you tie the three events together even when they were created at different times.
When it is logged
Sysmon installed; filter with <WmiEvent> rules in the configuration.
Key fields
| Field | What it tells you |
|---|---|
| EventType | WmiBindingEvent for this event. |
| Operation | Created for a new binding; removal is also recorded. |
| User | Account that created the binding. |
| Consumer | WMI path of the bound consumer, including its class and name. |
| Filter | WMI path of the bound filter. |
Common benign sources
- Bindings created by legitimate management software, matching known filters and consumers.
What attackers do that produces it
- Binding created seconds after a new filter and a command-line consumer — WMI persistence being completed.
Investigation tips
- Resolve Consumer and Filter to the matching events 20 and 19 and review the command and trigger.
- Remove the three objects from
root\subscriptionduring remediation, then confirm with a new event 21 deletion.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1546.003 Event Triggered Execution: Windows Management Instrumentation Event Subscription | Privilege Escalation, Persistence |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
3 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 2
- Medium · 1
- HighSuspicious Encoded Scripts in a WMI ConsumerRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
- HighSuspicious Scripting in a WMI ConsumerRule by Florian Roth (Nextron Systems), Jonhnathan Ribeiro, SigmaHQ, DRL 1.1
- MediumWMI Event SubscriptionRule by Tom Ueltschi (@c_APT_ure), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.