Skip to content
WMI-Activity

WMI Event ID 5861: Permanent event consumer

Permanent WMI event consumer registeredWMI-Activity event 5861 logs a permanent WMI event subscription (filter-to-consumer binding), the classic fileless persistence technique.
5861
Event ID
5861
Channel
Microsoft-Windows-WMI-Activity/Operational
Provider
Microsoft-Windows-WMI-Activity
Log file
Microsoft-Windows-WMI-Activity%4Operational.evtx
Category
WMI
Default logging
Logged by default

What event 5861 means

Event 5861 is written by the WMI service when a permanent event subscription becomes active: an __EventFilter (a WQL event query) bound to an event consumer through __FilterToConsumerBinding. Permanent subscriptions live in the WMI repository and survive reboots, which is why attackers use them for persistence: the consumer runs code whenever the filter fires, for example a few minutes after startup or when a user logs on.

The record gives the Namespace (usually root\subscription), the filter in ESS and the consumer in CONSUMER. The PossibleCause field holds the details of the binding, including the consumer's properties — for a CommandLineEventConsumer the command line, for an ActiveScriptEventConsumer the script — so 5861 often shows the payload directly.

New permanent subscriptions are rare on most endpoints, which makes this a high-signal event. Windows ships a default one (SCM Event Log Consumer), and some management and OEM software add their own; baseline those and review everything else.

When it is logged

Audit policy / configuration

None — the Microsoft-Windows-WMI-Activity/Operational channel is enabled by default.

Event 5861 is defined from Windows 10 1607 / Windows Server 2016 onward; earlier releases do not have it. Sysmon events 19, 20 and 21 cover the same activity (filter, consumer, binding) when Sysmon is deployed with WMI monitoring in its configuration.

Key fields

FieldWhat it tells you
NamespaceWMI namespace holding the subscription, typically root\subscription.
ESSThe event filter (name and WQL query) that triggers the consumer.
CONSUMERThe consumer bound to the filter, e.g. CommandLineEventConsumer="Updater" or ActiveScriptEventConsumer="...". Command line and script consumers are the dangerous types.
PossibleCauseDetails of the binding, including the consumer's properties (such as CommandLineTemplate, ExecutablePath or ScriptText). Read this field first.

Common benign sources

  • The built-in SCM Event Log Consumer subscription present on Windows installs.
  • Management, monitoring and OEM software (for example configuration management or hardware vendor agents) registering their own subscriptions.

What attackers do that produces it

  • Fileless persistence: a CommandLineEventConsumer or ActiveScriptEventConsumer that runs PowerShell, cmd.exe or a script shortly after boot or on a timer.
  • Remote persistence installed over WMI or WinRM from another host with admin credentials.
  • Offensive frameworks and malware families that ship WMI persistence modules.

Investigation tips

  • Review every 5861 whose CONSUMER is a command line or active script consumer; read PossibleCause for the payload.
  • Enumerate the live subscriptions (__EventFilter, __EventConsumer, __FilterToConsumerBinding in root\subscription) or parse OBJECTS.DATA from the WMI repository offline.
  • Look for child processes of WmiPrvSE.exe or scrcons.exe (active script consumers) in Security 4688 or Sysmon 1.
  • Check Sysmon 19, 20 and 21 for the same subscription and for who created it.

MITRE ATT&CK techniques

TechniqueTactics
T1546.003 Event Triggered Execution: Windows Management Instrumentation Event SubscriptionPrivilege Escalation, Persistence
T1047 Windows Management InstrumentationExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 1
  • MediumWMI PersistenceRule by Florian Roth (Nextron Systems), Gleb Sukhodolskiy, Timur Zinniatullin oscd.community, SigmaHQ, DRL 1.1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideEvent ID 5861: WMI persistence in the WMI-Activity log

Sources and further reading