Skip to content
Sysmon

Sysmon Event ID 21: WMI consumer bound to filter

WmiEvent (WmiEventConsumerToFilter activity detected)Sysmon event 21 logs a WMI consumer being bound to a filter, the step that activates a permanent WMI subscription. Completes the WMI persistence trio.
21
Event ID
21
Channel
Microsoft-Windows-Sysmon/Operational
Provider
Microsoft-Windows-Sysmon
Log file
Microsoft-Windows-Sysmon%4Operational.evtx
Category
WMI
Default logging
Needs configuration

What event 21 means

Sysmon event 21 records a __FilterToConsumerBinding: the link that makes a filter (event 19) trigger a consumer (event 20). Once this binding exists, the subscription is live and survives reboots.

The event carries the WMI paths of both the consumer and the filter, which lets you tie the three events together even when they were created at different times.

When it is logged

Audit policy / configuration

Sysmon installed; filter with <WmiEvent> rules in the configuration.

Key fields

FieldWhat it tells you
EventTypeWmiBindingEvent for this event.
OperationCreated for a new binding; removal is also recorded.
UserAccount that created the binding.
ConsumerWMI path of the bound consumer, including its class and name.
FilterWMI path of the bound filter.

Common benign sources

  • Bindings created by legitimate management software, matching known filters and consumers.

What attackers do that produces it

  • Binding created seconds after a new filter and a command-line consumer — WMI persistence being completed.

Investigation tips

  • Resolve Consumer and Filter to the matching events 20 and 19 and review the command and trigger.
  • Remove the three objects from root\subscription during remediation, then confirm with a new event 21 deletion.

MITRE ATT&CK techniques

TechniqueTactics
T1546.003 Event Triggered Execution: Windows Management Instrumentation Event SubscriptionPrivilege Escalation, Persistence

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

3 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 2
  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading