WMI Event ID 5858: Operation error
- Event ID
- 5858
- Channel
- Microsoft-Windows-WMI-Activity/Operational
- Provider
- Microsoft-Windows-WMI-Activity
- Log file
- Microsoft-Windows-WMI-Activity%4Operational.evtx
- Category
- WMI
- Default logging
- Logged by default
What event 5858 means
Event 5858 is written when a WMI operation returns an error. Unlike most WMI activity, which leaves no trace in the Operational log when it succeeds, failures are recorded with the client machine (ClientMachine), the user (User), the client process ID (ClientProcessId), the operation text (Operation, which includes the namespace and the WQL query or method) and the error (ResultCode).
That makes 5858 a partial window into WMI usage: reconnaissance queries against classes that do not exist on the host, access-denied errors from low-privileged accounts, and remote clients probing namespaces all show up here. The Operation text is the main thing to read.
Expect a lot of volume. Management agents and monitoring tools generate repeated 5858 errors, most commonly "not found" results for classes or instances that are simply absent on that machine.
When it is logged
None — the Microsoft-Windows-WMI-Activity/Operational channel is enabled by default.
Only failed operations are logged; successful queries do not produce 5858. Full tracing of WMI calls requires the analytic Trace channel, which is off by default and very verbose.
Key fields
| Field | What it tells you | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Id | Identifier of the operation. | ||||||||||||
| ClientMachine | Name of the machine the request came from; a name other than the local host means remote WMI. | ||||||||||||
| User | Account that made the request. | ||||||||||||
| ClientProcessId | Process ID of the client that issued the request. | ||||||||||||
| Component | WMI component that reported the error. | ||||||||||||
| Operation | The failing operation, e.g. Start IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM .... Read this for the namespace, class and query. | ||||||||||||
| ResultCode | WMI (WBEM) error code returned by the operation.
| ||||||||||||
| PossibleCause | Hint from WMI about the likely cause, when available. |
Common benign sources
- Management, inventory and monitoring agents querying classes that are missing on some hardware or OS versions.
- Security and backup software polling WMI and hitting not-found or access-denied errors.
What attackers do that produces it
- Reconnaissance scripts and offensive tools enumerating WMI classes (antivirus products, processes, shares) and failing on some of them.
- Remote WMI attempts from another host with insufficient rights, visible through ClientMachine and access-denied codes.
Investigation tips
- Group by Operation and ClientMachine; filter the recurring agent noise, then review the rest.
- Resolve ClientProcessId to a process (4688 / Sysmon 1) when the client is local.
- For remote ClientMachine values, correlate with network logons (Security 4624 type 3) at the same time.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1047 Windows Management Instrumentation | Execution |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Medium · 1
- MediumFailed Event Log Clear Via WMI NTEventLogFile ClearEventLogRule by Swachchhanda Shrawan Poudel (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.