Skip to content
WMI-Activity

WMI Event ID 5858: Operation error

WMI operation errorWMI-Activity event 5858 logs a failed WMI operation with the client machine, user, process ID and the query or method that failed. Noisy but revealing.
5858
Event ID
5858
Channel
Microsoft-Windows-WMI-Activity/Operational
Provider
Microsoft-Windows-WMI-Activity
Log file
Microsoft-Windows-WMI-Activity%4Operational.evtx
Category
WMI
Default logging
Logged by default

What event 5858 means

Event 5858 is written when a WMI operation returns an error. Unlike most WMI activity, which leaves no trace in the Operational log when it succeeds, failures are recorded with the client machine (ClientMachine), the user (User), the client process ID (ClientProcessId), the operation text (Operation, which includes the namespace and the WQL query or method) and the error (ResultCode).

That makes 5858 a partial window into WMI usage: reconnaissance queries against classes that do not exist on the host, access-denied errors from low-privileged accounts, and remote clients probing namespaces all show up here. The Operation text is the main thing to read.

Expect a lot of volume. Management agents and monitoring tools generate repeated 5858 errors, most commonly "not found" results for classes or instances that are simply absent on that machine.

When it is logged

Audit policy / configuration

None — the Microsoft-Windows-WMI-Activity/Operational channel is enabled by default.

Only failed operations are logged; successful queries do not produce 5858. Full tracing of WMI calls requires the analytic Trace channel, which is off by default and very verbose.

Key fields

FieldWhat it tells you
IdIdentifier of the operation.
ClientMachineName of the machine the request came from; a name other than the local host means remote WMI.
UserAccount that made the request.
ClientProcessIdProcess ID of the client that issued the request.
ComponentWMI component that reported the error.
OperationThe failing operation, e.g. Start IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM .... Read this for the namespace, class and query.
ResultCodeWMI (WBEM) error code returned by the operation.
ValueMeaning
0x80041002WBEM_E_NOT_FOUND — the object or instance was not found. The most common, usually benign.
0x80041003WBEM_E_ACCESS_DENIED — the caller lacks permission; watch for this from unexpected accounts.
0x80041010WBEM_E_INVALID_CLASS — the class does not exist in the namespace.
0x80041017WBEM_E_INVALID_QUERY — the query is syntactically invalid.
0x80041032WBEM_E_CALL_CANCELLED — the call was cancelled.
PossibleCauseHint from WMI about the likely cause, when available.

Common benign sources

  • Management, inventory and monitoring agents querying classes that are missing on some hardware or OS versions.
  • Security and backup software polling WMI and hitting not-found or access-denied errors.

What attackers do that produces it

  • Reconnaissance scripts and offensive tools enumerating WMI classes (antivirus products, processes, shares) and failing on some of them.
  • Remote WMI attempts from another host with insufficient rights, visible through ClientMachine and access-denied codes.

Investigation tips

  • Group by Operation and ClientMachine; filter the recurring agent noise, then review the rest.
  • Resolve ClientProcessId to a process (4688 / Sysmon 1) when the client is local.
  • For remote ClientMachine values, correlate with network logons (Security 4624 type 3) at the same time.

MITRE ATT&CK techniques

TechniqueTactics
T1047 Windows Management InstrumentationExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading