WMI Event ID 5857: Provider started
- Event ID
- 5857
- Channel
- Microsoft-Windows-WMI-Activity/Operational
- Provider
- Microsoft-Windows-WMI-Activity
- Log file
- Microsoft-Windows-WMI-Activity%4Operational.evtx
- Category
- WMI
- Default logging
- Logged by default
What event 5857 means
Event 5857 is written when WMI loads a provider to serve a request. It names the provider (ProviderName), the DLL that implements it (ProviderPath), the process hosting it (HostProcess, usually WmiPrvSE.exe), that process's ID (ProcessID) and the load result (Code, 0x0 on success).
On a normal system the list of providers and DLL paths is short and stable — mostly files under %SystemRoot%\System32\wbem\ and a handful of vendor components. A provider DLL loading from an unusual location, or a provider name you have never seen, can reveal a malicious WMI provider installed for persistence or execution.
The event also works as indirect evidence of WMI use: a provider such as the Win32 process provider loading at the time of suspected remote execution helps confirm that WMI was involved, even though 5857 does not identify the client or the query.
When it is logged
None — the Microsoft-Windows-WMI-Activity/Operational channel is enabled by default.
The event records provider loads, not individual WMI calls. It does not show the client, user or query; see 5858, 5860 and 5861 for those.
Key fields
| Field | What it tells you |
|---|---|
| ProviderName | Name of the WMI provider that was loaded, e.g. CIMWin32, WMIProv, MSI_PROV. |
| Code | Result code of the provider load; 0x0 means it started successfully. |
| HostProcess | Process hosting the provider, normally WmiPrvSE.exe. |
| ProcessID | Process ID of the host process. Correlate with 4688 / Sysmon 1 and with child processes it spawns. |
| ProviderPath | Path of the provider DLL, e.g. %systemroot%\system32\wbem\cimwin32.dll. Paths outside System32\wbem or Program Files deserve a look. |
Common benign sources
- Built-in providers loading on demand for monitoring, inventory and management tools.
- Vendor providers (storage, hardware, backup, security agents) registered by their installers.
What attackers do that produces it
- A malicious WMI provider DLL registered for persistence or code execution inside
WmiPrvSE.exe. - Remote WMI execution (for example
Win32_ProcessCreate) causing the process provider to load at the time of the attack.
Investigation tips
- Stack ProviderName and ProviderPath across hosts; rare combinations and non-standard paths stand out.
- Check the signature and creation time of unusual provider DLLs.
- For suspected remote WMI execution, correlate with child processes of
WmiPrvSE.exe(Security 4688, Sysmon 1) and network logons (4624 type 3).
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1047 Windows Management Instrumentation | Execution |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.