Skip to content
WMI-Activity

WMI Event ID 5857: Provider started

WMI provider startedWMI-Activity event 5857 logs a WMI provider being loaded: provider name, DLL path and host process. Useful to spot rogue providers and WMI usage.
5857
Event ID
5857
Channel
Microsoft-Windows-WMI-Activity/Operational
Provider
Microsoft-Windows-WMI-Activity
Log file
Microsoft-Windows-WMI-Activity%4Operational.evtx
Category
WMI
Default logging
Logged by default

What event 5857 means

Event 5857 is written when WMI loads a provider to serve a request. It names the provider (ProviderName), the DLL that implements it (ProviderPath), the process hosting it (HostProcess, usually WmiPrvSE.exe), that process's ID (ProcessID) and the load result (Code, 0x0 on success).

On a normal system the list of providers and DLL paths is short and stable — mostly files under %SystemRoot%\System32\wbem\ and a handful of vendor components. A provider DLL loading from an unusual location, or a provider name you have never seen, can reveal a malicious WMI provider installed for persistence or execution.

The event also works as indirect evidence of WMI use: a provider such as the Win32 process provider loading at the time of suspected remote execution helps confirm that WMI was involved, even though 5857 does not identify the client or the query.

When it is logged

Audit policy / configuration

None — the Microsoft-Windows-WMI-Activity/Operational channel is enabled by default.

The event records provider loads, not individual WMI calls. It does not show the client, user or query; see 5858, 5860 and 5861 for those.

Key fields

FieldWhat it tells you
ProviderNameName of the WMI provider that was loaded, e.g. CIMWin32, WMIProv, MSI_PROV.
CodeResult code of the provider load; 0x0 means it started successfully.
HostProcessProcess hosting the provider, normally WmiPrvSE.exe.
ProcessIDProcess ID of the host process. Correlate with 4688 / Sysmon 1 and with child processes it spawns.
ProviderPathPath of the provider DLL, e.g. %systemroot%\system32\wbem\cimwin32.dll. Paths outside System32\wbem or Program Files deserve a look.

Common benign sources

  • Built-in providers loading on demand for monitoring, inventory and management tools.
  • Vendor providers (storage, hardware, backup, security agents) registered by their installers.

What attackers do that produces it

  • A malicious WMI provider DLL registered for persistence or code execution inside WmiPrvSE.exe.
  • Remote WMI execution (for example Win32_Process Create) causing the process provider to load at the time of the attack.

Investigation tips

  • Stack ProviderName and ProviderPath across hosts; rare combinations and non-standard paths stand out.
  • Check the signature and creation time of unusual provider DLLs.
  • For suspected remote WMI execution, correlate with child processes of WmiPrvSE.exe (Security 4688, Sysmon 1) and network logons (4624 type 3).

MITRE ATT&CK techniques

TechniqueTactics
T1047 Windows Management InstrumentationExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading