Skip to content
WMI-Activity

WMI Event ID 5860: Temporary event consumer

Temporary WMI event consumer registeredWMI-Activity event 5860 logs a temporary WMI event subscription: the namespace, the WQL notification query and the client process that registered it.
5860
Event ID
5860
Channel
Microsoft-Windows-WMI-Activity/Operational
Provider
Microsoft-Windows-WMI-Activity
Log file
Microsoft-Windows-WMI-Activity%4Operational.evtx
Category
WMI
Default logging
Logged by default

What event 5860 means

Event 5860 is written when a client registers a temporary event subscription — a WQL notification query that WMI answers for as long as the client process is running (for example Register-WmiEvent, Register-CimIndicationEvent or ExecNotificationQuery from a script or program). Unlike a permanent subscription (5861), nothing is stored in the WMI repository and the subscription disappears when the client exits.

The record holds the namespace (NamespaceName), the notification query (Query), the user (User), the client process ID (processid) and the client machine (MachineName). The query shows what the client is watching: process starts, logons, USB insertion, service changes and so on.

Many legitimate programs register temporary subscriptions, so the event is noisy; its value is in the query text and in the client process behind it.

When it is logged

Audit policy / configuration

None — the Microsoft-Windows-WMI-Activity/Operational channel is enabled by default.

Event 5860 is defined from Windows 10 1511 onward. Temporary subscriptions are not covered by Sysmon's WMI events (19–21), which only track permanent ones.

Key fields

FieldWhat it tells you
NamespaceNameWMI namespace the query was registered in, usually root\cimv2.
QueryThe WQL notification query, e.g. SELECT * FROM __InstanceCreationEvent WITHIN 5 WHERE TargetInstance ISA 'Win32_Process'.
UserAccount of the client that registered the subscription.
processidProcess ID of the client that registered the subscription. Map it to a process with 4688 / Sysmon 1.
MachineNameClient machine name; a remote name means the subscription was registered over the network.
PossibleCauseAdditional context supplied by WMI about the registration.

Common benign sources

  • Endpoint agents, monitoring tools and hardware utilities watching for process, device or power events.
  • Administrative PowerShell scripts using Register-WmiEvent or Register-CimIndicationEvent.

What attackers do that produces it

  • In-memory implants that wait for a trigger (process start, user logon) without writing a permanent subscription.
  • Malware monitoring for analysis tools or security products starting, to react or exit.

Investigation tips

  • Resolve processid to an image with Security 4688 or Sysmon 1 and check whether it is a known agent.
  • Read the Query for what is being watched; process creation and logon queries from unknown processes are worth a look.
  • Check whether MachineName is remote and correlate with network logons (Security 4624) on the host.

MITRE ATT&CK techniques

TechniqueTactics
T1047 Windows Management InstrumentationExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading