WMI Event ID 5860: Temporary event consumer
- Event ID
- 5860
- Channel
- Microsoft-Windows-WMI-Activity/Operational
- Provider
- Microsoft-Windows-WMI-Activity
- Log file
- Microsoft-Windows-WMI-Activity%4Operational.evtx
- Category
- WMI
- Default logging
- Logged by default
What event 5860 means
Event 5860 is written when a client registers a temporary event subscription — a WQL notification query that WMI answers for as long as the client process is running (for example Register-WmiEvent, Register-CimIndicationEvent or ExecNotificationQuery from a script or program). Unlike a permanent subscription (5861), nothing is stored in the WMI repository and the subscription disappears when the client exits.
The record holds the namespace (NamespaceName), the notification query (Query), the user (User), the client process ID (processid) and the client machine (MachineName). The query shows what the client is watching: process starts, logons, USB insertion, service changes and so on.
Many legitimate programs register temporary subscriptions, so the event is noisy; its value is in the query text and in the client process behind it.
When it is logged
None — the Microsoft-Windows-WMI-Activity/Operational channel is enabled by default.
Event 5860 is defined from Windows 10 1511 onward. Temporary subscriptions are not covered by Sysmon's WMI events (19–21), which only track permanent ones.
Key fields
| Field | What it tells you |
|---|---|
| NamespaceName | WMI namespace the query was registered in, usually root\cimv2. |
| Query | The WQL notification query, e.g. SELECT * FROM __InstanceCreationEvent WITHIN 5 WHERE TargetInstance ISA 'Win32_Process'. |
| User | Account of the client that registered the subscription. |
| processid | Process ID of the client that registered the subscription. Map it to a process with 4688 / Sysmon 1. |
| MachineName | Client machine name; a remote name means the subscription was registered over the network. |
| PossibleCause | Additional context supplied by WMI about the registration. |
Common benign sources
- Endpoint agents, monitoring tools and hardware utilities watching for process, device or power events.
- Administrative PowerShell scripts using
Register-WmiEventorRegister-CimIndicationEvent.
What attackers do that produces it
- In-memory implants that wait for a trigger (process start, user logon) without writing a permanent subscription.
- Malware monitoring for analysis tools or security products starting, to react or exit.
Investigation tips
- Resolve processid to an image with Security 4688 or Sysmon 1 and check whether it is a known agent.
- Read the Query for what is being watched; process creation and logon queries from unknown processes are worth a look.
- Check whether MachineName is remote and correlate with network logons (Security 4624) on the host.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1047 Windows Management Instrumentation | Execution |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.