WMI Event ID 5861: Permanent event consumer
- Event ID
- 5861
- Channel
- Microsoft-Windows-WMI-Activity/Operational
- Provider
- Microsoft-Windows-WMI-Activity
- Log file
- Microsoft-Windows-WMI-Activity%4Operational.evtx
- Category
- WMI
- Default logging
- Logged by default
What event 5861 means
Event 5861 is written by the WMI service when a permanent event subscription becomes active: an __EventFilter (a WQL event query) bound to an event consumer through __FilterToConsumerBinding. Permanent subscriptions live in the WMI repository and survive reboots, which is why attackers use them for persistence: the consumer runs code whenever the filter fires, for example a few minutes after startup or when a user logs on.
The record gives the Namespace (usually root\subscription), the filter in ESS and the consumer in CONSUMER. The PossibleCause field holds the details of the binding, including the consumer's properties — for a CommandLineEventConsumer the command line, for an ActiveScriptEventConsumer the script — so 5861 often shows the payload directly.
New permanent subscriptions are rare on most endpoints, which makes this a high-signal event. Windows ships a default one (SCM Event Log Consumer), and some management and OEM software add their own; baseline those and review everything else.
When it is logged
None — the Microsoft-Windows-WMI-Activity/Operational channel is enabled by default.
Event 5861 is defined from Windows 10 1607 / Windows Server 2016 onward; earlier releases do not have it. Sysmon events 19, 20 and 21 cover the same activity (filter, consumer, binding) when Sysmon is deployed with WMI monitoring in its configuration.
Key fields
| Field | What it tells you |
|---|---|
| Namespace | WMI namespace holding the subscription, typically root\subscription. |
| ESS | The event filter (name and WQL query) that triggers the consumer. |
| CONSUMER | The consumer bound to the filter, e.g. CommandLineEventConsumer="Updater" or ActiveScriptEventConsumer="...". Command line and script consumers are the dangerous types. |
| PossibleCause | Details of the binding, including the consumer's properties (such as CommandLineTemplate, ExecutablePath or ScriptText). Read this field first. |
Common benign sources
- The built-in
SCM Event Log Consumersubscription present on Windows installs. - Management, monitoring and OEM software (for example configuration management or hardware vendor agents) registering their own subscriptions.
What attackers do that produces it
- Fileless persistence: a
CommandLineEventConsumerorActiveScriptEventConsumerthat runs PowerShell,cmd.exeor a script shortly after boot or on a timer. - Remote persistence installed over WMI or WinRM from another host with admin credentials.
- Offensive frameworks and malware families that ship WMI persistence modules.
Investigation tips
- Review every 5861 whose CONSUMER is a command line or active script consumer; read PossibleCause for the payload.
- Enumerate the live subscriptions (
__EventFilter,__EventConsumer,__FilterToConsumerBindinginroot\subscription) or parseOBJECTS.DATAfrom the WMI repository offline. - Look for child processes of
WmiPrvSE.exeorscrcons.exe(active script consumers) in Security 4688 or Sysmon 1. - Check Sysmon 19, 20 and 21 for the same subscription and for who created it.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Medium · 1
- MediumWMI PersistenceRule by Florian Roth (Nextron Systems), Gleb Sukhodolskiy, Timur Zinniatullin oscd.community, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.