Microsoft-Windows-WMI-Activity

EventTitleChannelSampleRule
1GroupOperationId = GroupOperationId; OperationId = OperationId; Operation = …TraceNN
2ProviderInfo for GroupOperationId = GroupOperationId; Operation = Operation; …TraceNN
3Stop OperationId = OperationId.TraceNN
11CorrelationId = CorrelationId; GroupOperationId = GroupOperationId; OperationId …TraceYN
12ProviderInfo for GroupOperationId = GroupOperationId; Operation = Operation; …TraceYN
13Stop OperationId = OperationId; ResultCode = ResultCode.TraceYN
14OperationId = OperationId; Operation = Operation; Channel = Channel; Message = …TraceNN
15OperationId = OperationId; Operation = Operation; ErrorID = ErrorId; …TraceNN
16OperationId = OperationId; Operation = Operation; ErrorID = ErrorId; Message = …TraceYN
17CorrelationId = CorrelationId; ProcessId = ProcessId; Protocol = Protocol; …TraceYN
18WMI Events were dropped.TraceNN
19Performing delete operation on the WMI repository.TraceYN
20Performing Update operation on the WMI repository.TraceYN
21WMI Events were bound.TraceNN
22CorrelationId = CorrelationId; GroupOperationId = GroupOperationId; OperationId …TraceYN
23CorrelationId = CorrelationId; GroupOperationId = GroupOperationId; OperationId …TraceYN
24GroupOperationId = GroupOperationId; Executing polling query Query in namespace …TraceNN
50Activity TransferTraceYN
100ComponentName = ComponentName; MessageDetail = MessageDetail; FileName = …DebugYN
101ComponentName = ComponentName; ErrorId = ErrorId; ErrorDetail = ErrorDetail; …DebugYN
5857Operation_StartedOperational.ProviderName provider started with result code …OperationalYN
5858Id = Operation_ClientFailure.Id; ClientMachine = …OperationalYY
5859Namespace = Operation_EssStarted.NamespaceName; NotificationQuery = …OperationalYY
5860Namespace = Operation_TemporaryEssStarted.NamespaceName; NotificationQuery = …OperationalYY
5861Namespace = Operation_ESStoConsumerBinding.Namespace; Eventfilter = …OperationalYY

Event ID 1: GroupOperationId = GroupOperationId; OperationId = OperationId; Operation = Operation; ClientMachine = ClientMachine; User = User; ClientProcessId = ClientProcessId; NamespaceName = NamespaceName.

#
Channel
Trace

Message #

GroupOperationId = %1; OperationId = %2; Operation = %3; ClientMachine = %4; User = %5; ClientProcessId = %6; NamespaceName = %7

Fields #

NameDescription
GroupOperationId UInt32
OperationId UInt32
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ClientMachine UnicodeString
User UnicodeString
ClientProcessId UInt32
NamespaceName UnicodeString

Event ID 2: ProviderInfo for GroupOperationId = GroupOperationId; Operation = Operation; ProviderName = ProviderName; ProviderGuid = ProviderGuid; Path = Path.

#
Channel
Trace

Message #

ProviderInfo for GroupOperationId = %1; Operation = %2; ProviderName = %3; ProviderGuid = %4; Path = %5

Fields #

NameDescription
GroupOperationId UInt32
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ProviderName UnicodeString
ProviderGuid UnicodeString
Path UnicodeString

Event ID 3: Stop OperationId = OperationId.

#
Channel
Trace

Message #

Stop OperationId = %1

Fields #

NameDescription
OperationId UInt32

Event ID 11: CorrelationId = CorrelationId; GroupOperationId = GroupOperationId; OperationId = OperationId; Operation = Operation; ClientMachine = ClientMachine; User = User; ClientProcessId = ClientProcessId; ...

#
Channel
Trace
Also via
realtime ETW trace
Level
Informational

Description

CorrelationId = CorrelationId; GroupOperationId = GroupOperationId; OperationId = OperationId; Operation = Operation; ClientMachine = ClientMachine; User = User; ClientProcessId = ClientProcessId; NamespaceName = ClientProcessCreationTime.

Message #

CorrelationId = %1; GroupOperationId = %2; OperationId = %3; Operation = %4; ClientMachine = %5; User = %7; ClientProcessId = %8; NamespaceName = %9

Fields #

NameDescription
CorrelationId UnicodeString
GroupOperationId UInt32
OperationId UInt32
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ClientMachine UnicodeString
ClientMachineFQDN UnicodeString
User UnicodeString
ClientProcessId UInt32
ClientProcessCreationTime UInt64
NamespaceName UnicodeString
IsLocal Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WMI-Activity",
    "guid": "1418ef04-b0b4-4623-bf7e-d74ab47bbdaa",
    "event_source_name": "",
    "event_id": 11,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-05-03T21:02:22.5390626+00:00",
    "event_record_id": 3702,
    "correlation": {
      "ActivityID": "a5a72efc-0725-4af3-8928-2c7be294af3b",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 3776,
      "thread_id": 14888
    },
    "channel": "Microsoft-Windows-WMI-Activity/Trace",
    "computer": "DESKTOP-K7Q9MS2",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "Operation_New": {
      "CorrelationId": "{EB2F7CD8-77D6-447B-8B41-85BBC0F0CD29}",
      "GroupOperationId": "33824",
      "OperationId": "33915",
      "Operation": "Start IWbemServices::DeleteInstance - Root\\Rsop\\Computer : RSOP_ExtensionStatus.extensionGuid=\"{FB2CA36D-0B40-4307-821B-A13B252DE56C}\"",
      "ClientMachine": "DESKTOP-K7Q9MS2",
      "ClientMachineFQDN": "DESKTOP-K7Q9MS2",
      "User": "NT AUTHORITY\\SYSTEM",
      "ClientProcessId": "5592",
      "ClientProcessCreationTime": "134223150821160298",
      "NamespaceName": "\\\\.\\Root\\Rsop\\Computer",
      "IsLocal": "true"
    }
  },
  "message": "CorrelationId = {EB2F7CD8-77D6-447B-8B41-85BBC0F0CD29}; GroupOperationId = 33824; OperationId = 33915; Operation = Start IWbemServices::DeleteInstance - Root\\Rsop\\Computer : RSOP_ExtensionStatus.extensionGuid=\"{FB2CA36D-0B40-4307-821B-A13B252DE56C}\"; ClientMachine = DESKTOP-K7Q9MS2; User = NT AUTHORITY\\SYSTEM; ClientProcessId = 5592; NamespaceName = 134223150821160298"
}

Event ID 12: ProviderInfo for GroupOperationId = GroupOperationId; Operation = Operation; HostID = HostId; ProviderName = ProviderName; ProviderGuid = ProviderGuid; Path = Path.

#
Channel
Trace
Also via
realtime ETW trace
Level
Informational

Message #

ProviderInfo for GroupOperationId = %1; Operation = %2; HostID = %3; ProviderName = %4; ProviderGuid = %5; Path = %6

Fields #

NameDescription
GroupOperationId UInt32
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
HostId UInt32
ProviderName UnicodeString
ProviderGuid UnicodeString
Path UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WMI-Activity",
    "guid": "1418ef04-b0b4-4623-bf7e-d74ab47bbdaa",
    "event_source_name": "",
    "event_id": 12,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-05-03T21:02:08.7213624+00:00",
    "event_record_id": 2932,
    "correlation": {
      "ActivityID": "c4d83776-df9b-4f73-8eb3-abf6fdb18958",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 3776,
      "thread_id": 15356
    },
    "channel": "Microsoft-Windows-WMI-Activity/Trace",
    "computer": "DESKTOP-K7Q9MS2",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "Operation_Provider_Info_New": {
      "GroupOperationId": "33752",
      "Operation": "Provider::ExecQuery - CIMWin32 : select __RELPATH, __RELPATH from Win32_Process",
      "HostId": "14556",
      "ProviderName": "CIMWin32",
      "ProviderGuid": "{d63a5850-8f16-11cf-9f47-00aa00bf345c}",
      "Path": "%systemroot%\\system32\\wbem\\cimwin32.dll"
    }
  },
  "message": "ProviderInfo for GroupOperationId = 33752; Operation = Provider::ExecQuery - CIMWin32 : select __RELPATH, __RELPATH from Win32_Process; HostID = 14556; ProviderName = CIMWin32; ProviderGuid = {d63a5850-8f16-11cf-9f47-00aa00bf345c}; Path = %systemroot%\\system32\\wbem\\cimwin32.dll"
}

Event ID 13: Stop OperationId = OperationId; ResultCode = ResultCode.

#
Channel
Trace
Also via
realtime ETW trace
Level
Informational

Message #

Stop OperationId = %1; ResultCode = %2

Fields #

NameDescription
OperationId UInt32
ResultCode HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WMI-Activity",
    "guid": "1418ef04-b0b4-4623-bf7e-d74ab47bbdaa",
    "event_source_name": "",
    "event_id": 13,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-05-03T21:02:22.5397755+00:00",
    "event_record_id": 3704,
    "correlation": {
      "ActivityID": "eda08d7d-6e98-43be-adba-1f74e64b4281",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 3776,
      "thread_id": 14888
    },
    "channel": "Microsoft-Windows-WMI-Activity/Trace",
    "computer": "DESKTOP-K7Q9MS2",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "Operation_Stop_New": {
      "OperationId": "33915",
      "ResultCode": "0x80041002"
    }
  },
  "message": "Stop OperationId = 33915; ResultCode = 0x80041002"
}

Event ID 14: OperationId = OperationId; Operation = Operation; Channel = Channel; Message = Message.

#
Channel
Trace

Message #

OperationId = %1; Operation = %2; Channel = %3; Message = %4

Fields #

NameDescription
OperationId UInt32
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
Channel UInt32
Message UnicodeString

Event ID 15: OperationId = OperationId; Operation = Operation; ErrorID = ErrorId; ErrorCategory = ErrorCategory; Message = Message; TargetName = TargetName.

#
Channel
Trace

Message #

OperationId = %1; Operation = %2; ErrorID = %3; ErrorCategory = %4; Message = %5; TargetName = %6

Fields #

NameDescription
OperationId UInt32
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ErrorId UnicodeString
ErrorCategory UInt32
Message UnicodeString
TargetName UnicodeString

Event ID 16: OperationId = OperationId; Operation = Operation; ErrorID = ErrorId; Message = Message.

#
Channel
Trace
Also via
realtime ETW trace
Level
Informational

Message #

OperationId = %1; Operation = %2; ErrorID = %3; Message = %4

Fields #

NameDescription
OperationId UInt32
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ErrorId HexInt32
Message UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WMI-Activity",
    "guid": "1418ef04-b0b4-4623-bf7e-d74ab47bbdaa",
    "event_source_name": "",
    "event_id": 16,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-05-03T20:59:47.4850086+00:00",
    "event_record_id": 1271,
    "correlation": {
      "ActivityID": "64478093-d4f9-0001-b4d0-5164f9d4dc01",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 3536,
      "thread_id": 11712
    },
    "channel": "Microsoft-Windows-WMI-Activity/Trace",
    "computer": "DESKTOP-K7Q9MS2",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "Operation_Provider_Result": {
      "OperationId": "32845",
      "Operation": "Method Execution",
      "ErrorId": "0x0",
      "Message": ""
    }
  },
  "message": "OperationId = 32845; Operation = Method Execution; ErrorID = 0x0; Message = "
}

Event ID 17: CorrelationId = CorrelationId; ProcessId = ProcessId; Protocol = Protocol; Operation = Operation; User = User; Namespace = Namespace.

#
Channel
Trace
Level
Informational

Message #

CorrelationId = %1; ProcessId = %2; Protocol = %3; Operation = %4; User = %5; Namespace = %6

Fields #

NameDescription
CorrelationId UnicodeString
ProcessId UInt32
Protocol UnicodeString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
User UnicodeString
Namespace UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WMI-Activity",
    "guid": "1418ef04-b0b4-4623-bf7e-d74ab47bbdaa",
    "event_source_name": "",
    "event_id": 17,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-05-03T21:02:08.7157677+00:00",
    "event_record_id": 2926,
    "correlation": {
      "ActivityID": "64478093-d4f9-0007-03d4-5464f9d4dc01",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 12952,
      "thread_id": 11016
    },
    "channel": "Microsoft-Windows-WMI-Activity/Trace",
    "computer": "DESKTOP-K7Q9MS2",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "Operation_Client": {
      "CorrelationId": "{64478093-D4F9-0007-03D4-5464F9D4DC01}",
      "ProcessId": "12952",
      "Protocol": "DCOM",
      "Operation": "MI_Session::EnumerateInstance",
      "User": "NULL",
      "Namespace": "root\\cimv2"
    }
  },
  "message": "CorrelationId = {64478093-D4F9-0007-03D4-5464F9D4DC01}; ProcessId = 12952; Protocol = DCOM; Operation = MI_Session::EnumerateInstance; User = NULL; Namespace = root\\cimv2"
}

Event ID 18: WMI Events were dropped.

#
Channel
Trace

Description

WMI Events were dropped. ConsumerType = ConsumerType; Possiblecause = PossibleCause.

Message #

WMI Events were dropped. ConsumerType = %1; Possiblecause = %2

Fields #

NameDescription
ConsumerType UnicodeString
PossibleCause UnicodeString

Event ID 19: Performing delete operation on the WMI repository.

#
Channel
Trace
Also via
realtime ETW trace
Level
Informational

Description

Performing delete operation on the WMI repository. OperationID = OperationID; Operation = Operation.

Message #

Performing delete operation on the WMI repository. OperationID = %1; Operation = %2

Fields #

NameDescription
OperationID UInt32
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ClientProcessId UInt32
ClientMachineFQDN UnicodeString
ClientProcessCreationTime UInt64
IsLocal Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WMI-Activity",
    "guid": "1418ef04-b0b4-4623-bf7e-d74ab47bbdaa",
    "event_source_name": "",
    "event_id": 19,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-05-03T21:02:22.4784408+00:00",
    "event_record_id": 3467,
    "correlation": {
      "ActivityID": "b1d8c3f2-a930-480b-bcb8-cb95471878d4",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 3776,
      "thread_id": 12224
    },
    "channel": "Microsoft-Windows-WMI-Activity/Trace",
    "computer": "DESKTOP-K7Q9MS2",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "Operation_RepDelete": {
      "OperationID": "33824",
      "Operation": "\\\\DESKTOP-K7Q9MS2\\ROOT\\Rsop\\Computer:RSOP_RegistryPolicySetting.id=\"{852A0000-5369-4B5D-A940-3515E805B186}\",precedence=1"
    }
  },
  "message": "Performing delete operation on the WMI repository. OperationID = 33824; Operation = \\\\DESKTOP-K7Q9MS2\\ROOT\\Rsop\\Computer:RSOP_RegistryPolicySetting.id=\"{852A0000-5369-4B5D-A940-3515E805B186}\",precedence=1"
}

Event ID 20: Performing Update operation on the WMI repository.

#
Channel
Trace
Also via
realtime ETW trace
Level
Informational

Description

Performing Update operation on the WMI repository. OperationID = OperationID; Operation = Operation; Flags = Flags.

Message #

Performing Update operation on the WMI repository. OperationID = %1; Operation = %2; Flags = %3

Fields #

NameDescription
OperationID UInt32
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
Flags UInt32
ClientProcessId UInt32
ClientMachineFQDN UnicodeString
ClientProcessCreationTime UInt64
IsLocal Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WMI-Activity",
    "guid": "1418ef04-b0b4-4623-bf7e-d74ab47bbdaa",
    "event_source_name": "",
    "event_id": 20,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-05-03T21:02:22.4902463+00:00",
    "event_record_id": 3508,
    "correlation": {
      "ActivityID": "258aa0ca-4464-4d48-85ef-f9a43cd8ccbf",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 3776,
      "thread_id": 14888
    },
    "channel": "Microsoft-Windows-WMI-Activity/Trace",
    "computer": "DESKTOP-K7Q9MS2",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "Operation_RepUpdate": {
      "OperationID": "33824",
      "Operation": "RSOP_ExtensionStatus.extensionGuid=\"{35378EAC-683F-11D2-A89A-00C04FBBCFA2}\"",
      "Flags": "1"
    }
  },
  "message": "Performing Update operation on the WMI repository. OperationID = 33824; Operation = RSOP_ExtensionStatus.extensionGuid=\"{35378EAC-683F-11D2-A89A-00C04FBBCFA2}\"; Flags = 1"
}

Event ID 21: WMI Events were bound.

#
Channel
Trace

Description

WMI Events were bound. ConsumerType = ConsumerType; Possiblecause = PossibleCause.

Message #

WMI Events were bound. ConsumerType = %1; Possiblecause = %2

Fields #

NameDescription
ConsumerType UnicodeString
PossibleCause UnicodeString

Event ID 22: CorrelationId = CorrelationId; GroupOperationId = GroupOperationId; OperationId = OperationId; ClassName= ClassName; MethodName = MethodName; ImplementationClass = ImplementationClass; ClientMachin...

#
Channel
Trace
Level
Informational

Description

CorrelationId = CorrelationId; GroupOperationId = GroupOperationId; OperationId = OperationId; ClassName= ClassName; MethodName = MethodName; ImplementationClass = ImplementationClass; ClientMachine = ClientMachine; User = User; ClientProcessId = ClientProcessId; NamespaceName = NamespaceName.

Message #

CorrelationId = %1; GroupOperationId = %2; OperationId = %3; ClassName= %4; MethodName = %5; ImplementationClass = %6; ClientMachine = %7; User = %9; ClientProcessId = %10; NamespaceName = %12

Fields #

NameDescription
CorrelationId UnicodeString
GroupOperationId UInt32
OperationId UInt32
ClassName UnicodeString
MethodName UnicodeString
ImplementationClass UnicodeString
ClientMachine UnicodeString
ClientMachineFQDN UnicodeString
User UnicodeString
ClientProcessId UInt32
ClientProcessCreationTime UInt64
NamespaceName UnicodeString
IsLocal Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WMI-Activity",
    "guid": "1418ef04-b0b4-4623-bf7e-d74ab47bbdaa",
    "event_source_name": "",
    "event_id": 22,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-05-03T20:57:44.1010074+00:00",
    "event_record_id": 227,
    "correlation": {
      "ActivityID": "09b2d503-9f8b-44d1-b13f-a24eb51f7612",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 3776,
      "thread_id": 15116
    },
    "channel": "Microsoft-Windows-WMI-Activity/Trace",
    "computer": "DESKTOP-K7Q9MS2",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "MethodExec": {
      "CorrelationId": "{8D9DCB76-6D12-4141-8AD2-CAE6C7B89797}",
      "GroupOperationId": "32845",
      "OperationId": "32842",
      "ClassName": "MSFT_MpScan",
      "MethodName": "Start",
      "ImplementationClass": "MSFT_MpScan",
      "ClientMachine": "DESKTOP-K7Q9MS2",
      "ClientMachineFQDN": "DESKTOP-K7Q9MS2",
      "User": "DESKTOP-K7Q9MS2\\localuser",
      "ClientProcessId": "14256",
      "ClientProcessCreationTime": "134223154630497608",
      "NamespaceName": "\\\\.\\ROOT\\Microsoft\\Windows\\Defender",
      "IsLocal": "true"
    }
  },
  "message": "CorrelationId = {8D9DCB76-6D12-4141-8AD2-CAE6C7B89797}; GroupOperationId = 32845; OperationId = 32842; ClassName= MSFT_MpScan; MethodName = Start; ImplementationClass = MSFT_MpScan; ClientMachine = DESKTOP-K7Q9MS2; User = DESKTOP-K7Q9MS2\\localuser; ClientProcessId = 14256; NamespaceName = \\\\.\\ROOT\\Microsoft\\Windows\\Defender"
}

Event ID 23: CorrelationId = CorrelationId; GroupOperationId = GroupOperationId; OperationId = OperationId; Commandline= Commandline; CreatedProcessId = CreatedProcessId; ClientMachine = CreatedProcessCreationT...

#
Channel
Trace

Description

CorrelationId = CorrelationId; GroupOperationId = GroupOperationId; OperationId = OperationId; Commandline= Commandline; CreatedProcessId = CreatedProcessId; ClientMachine = CreatedProcessCreationTime; User = ClientMachineFQDN; ClientProcessId = User.

Message #

CorrelationId = %1; GroupOperationId = %2; OperationId = %3; Commandline= %4; CreatedProcessId = %5; ClientMachine = %6; User = %8; ClientProcessId = %9

Fields #

NameDescription
CorrelationId UnicodeString
GroupOperationId UInt32
OperationId UInt32
Commandline UnicodeString
CreatedProcessId UInt32
CreatedProcessCreationTime UInt64
ClientMachine UnicodeString
ClientMachineFQDN UnicodeString
User UnicodeString
ClientProcessId UInt32
ClientProcessCreationTime UInt64
IsLocal Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WMI-Activity",
    "guid": "",
    "event_source_name": "",
    "event_id": 23,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": 0,
    "time_created": "2026-07-19T02:32:42.959+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "28A454EC-2AB0-4BE4-88F3-267B7D6D0A25"
    },
    "execution": {
      "process_id": 1276,
      "thread_id": 3420
    },
    "channel": "Microsoft-Windows-WMI-Activity/Trace",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ClientMachine": "JD-WIN11-22H2-1",
    "ClientMachineFQDN": "JD-WIN11-22H2-1.ludus.domain",
    "ClientProcessCreationTime": 134289019581799216,
    "ClientProcessId": 3180,
    "Commandline": "cmd.exe /c exit",
    "CorrelationId": "{E1C851E7-5B5E-455F-842B-0BA429248953}",
    "CreatedProcessCreationTime": 134289019629493095,
    "CreatedProcessId": 12944,
    "GroupOperationId": 89414,
    "IsLocal": true,
    "OperationId": 89413,
    "User": "ludus\\domainadmin"
  },
  "message": ""
}

Event ID 24: GroupOperationId = GroupOperationId; Executing polling query Query in namespace NamespaceName.

#
Channel
Trace

Message #

GroupOperationId = %1; Executing polling query %2 in namespace %3

Fields #

NameDescription
GroupOperationId UInt32
Query UnicodeString
NamespaceName UnicodeString

Event ID 50: Activity Transfer

#
Channel
Trace
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WMI-Activity",
    "guid": "1418ef04-b0b4-4623-bf7e-d74ab47bbdaa",
    "event_source_name": "",
    "event_id": 50,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-05-03T21:02:22.5402448+00:00",
    "event_record_id": 3705,
    "correlation": {
      "ActivityID": "bf89d6b0-0749-4787-9648-37993808a186",
      "RelatedActivityID": "eb2f7cd8-77d6-447b-8b41-85bbc0f0cd29"
    },
    "execution": {
      "process_id": 3776,
      "thread_id": 14888
    },
    "channel": "Microsoft-Windows-WMI-Activity/Trace",
    "computer": "DESKTOP-K7Q9MS2",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "Activity Transfer"
}

Event ID 100: ComponentName = ComponentName; MessageDetail = MessageDetail; FileName = FileName.

#
Channel
Debug
Also via
realtime ETW trace

Message #

ComponentName = %1; MessageDetail = %2; FileName = %3

Fields #

NameDescription
ComponentName UnicodeString
MessageDetail UnicodeString
FileName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WMI-Activity",
    "guid": "{1418EF04-B0B4-4623-BF7E-D74AB47BBDAA}",
    "event_source_name": "",
    "event_id": 100,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": "0x2000000000000000",
    "time_created": "2026-06-02T04:29:47.965+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{41135196-7D61-49AA-B971-A65A11898EBC}"
    },
    "execution": {
      "process_id": 11952,
      "thread_id": 15276
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ComponentName": "MI_Client",
    "FileName": "onecore\\admin\\wmi\\wmiv2\\client\\api\\operation.c:940",
    "MessageDetail": "Operation Instance Result (async): session=00000260EE5D9EE0, operation=00000260ED62C9A0, internal-operation=00000260EE4B8C20, resultCode=0, moreResults=TRUE"
  },
  "message": ""
}

Event ID 101: ComponentName = ComponentName; ErrorId = ErrorId; ErrorDetail = ErrorDetail; FileName = FileName.

#
Channel
Debug
Level
Error

Message #

ComponentName = %1; ErrorId = %2; ErrorDetail = %3; FileName = %4

Fields #

NameDescription
ComponentName UnicodeString
ErrorId HexInt32
ErrorDetail UnicodeString
FileName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-WMI-Activity/Debug",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 101,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 3336,
      "thread_id": 9564
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-WMI-Activity",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 00:51:44.016Z",
    "version": 0
  },
  "event_data": {
    "ComponentName": "WMI_ADAPTER",
    "ErrorDetail": "WMIContext::PostResultToServer, provider completed the operation with context (000002883B9714B0). Failed with MIRESULT (16).",
    "ErrorId": "10000000",
    "FileName": "onecore\\admin\\wmi\\wmiv2\\tools\\adapter\\wmicontext.cpp:945"
  },
  "message": ""
}

Event ID 5857: Operation_StartedOperational.ProviderName provider started with result code Operation_StartedOperational.Code.

#
Channel
Operational
Collection Priority
Recommended (Palantir, others)

Description

Operation_StartedOperational.ProviderName provider started with result code Operation_StartedOperational.Code. HostProcess = Operation_StartedOperational.HostProcess; ProcessID = Operation_StartedOperational.ProcessID; ProviderPath = Operation_StartedOperational.ProviderPath.

Message #

%1 provider started with result code %2. HostProcess = %3; ProcessID = %4; ProviderPath = %5

Fields #

NameDescription
Operation_StartedOperational.ProviderNameName of the WMI provider that started.
Operation_StartedOperational.CodeResult code of the provider start operation.
Operation_StartedOperational.HostProcessWMI provider process name.
Operation_StartedOperational.ProcessIDWMI provider process ID.
Operation_StartedOperational.ProviderPathPath of the WMI provider module being loaded.
ProviderNameName of the WMI provider that started.
CodeResult code of the provider start operation.
HostProcessWMI provider process name.
ProcessIDWMI provider process ID.
ProviderPathPath of the WMI provider module being loaded.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WMI-Activity",
    "guid": "{1418EF04-B0B4-4623-BF7E-D74AB47BBDAA}",
    "event_source_name": "",
    "event_id": 5857,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-06-13T10:41:36.8111708+00:00",
    "event_record_id": 1482,
    "correlation": {},
    "execution": {
      "process_id": 5884,
      "thread_id": 7412
    },
    "channel": "Microsoft-Windows-WMI-Activity/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "Operation_StartedOperational": {
      "ProviderName": "Win32_TpmProvider",
      "Code": "0x0",
      "HostProcess": "wmiprvse.exe",
      "ProcessID": "5884",
      "ProviderPath": "C:\\Windows\\System32\\wbem\\Win32_TPM.dll"
    }
  },
  "message": "Win32_TpmProvider provider started with result code 0x0. HostProcess = wmiprvse.exe; ProcessID = 5884; ProviderPath = C:\\Windows\\System32\\wbem\\Win32_TPM.dll"
}

References #

Event ID 5858: Id = Operation_ClientFailure.Id; ClientMachine = Operation_ClientFailure.ClientMachine; User = Operation_ClientFailure.User; ClientProcessId = Operation_ClientFailure.ClientProcessId; Component = O...

#
Channel
Operational
Level
Error
Collection Priority
Recommended (Palantir, others)

Description

Id = ; ClientMachine = ; User = ; ClientProcessId = ; Component = ; Operation = ; ResultCode = ; PossibleCause =.

Message #

Id = %1; ClientMachine = %2; User = %3; ClientProcessId = %4; Component = %5; Operation = %6; ResultCode = %7; PossibleCause = %8

Fields #

NameDescriptionRules
Operation_ClientFailure.IdCorrelation identifier for the operation.
Operation_ClientFailure.ClientMachineName of the machine that issued the WMI request.
Operation_ClientFailure.UserAccount that issued the WMI request.
Operation_ClientFailure.ClientProcessIdProcess ID of the WMI client.
Operation_ClientFailure.ComponentWMI subsystem component that failed.
Operation_ClientFailure.OperationWMI operation that failed.
Operation_ClientFailure.ResultCodeHexadecimal result code from the failed operation.
Operation_ClientFailure.PossibleCausePossible reason for the failure as reported by WMI.
IdCorrelation identifier for the operation.
ClientMachineName of the machine that issued the WMI request.
UserAccount that issued the WMI request.
ClientProcessIdProcess ID of the WMI client.
ComponentWMI subsystem component that failed.
OperationWMI operation that failed.2 detection rules
ResultCodeHexadecimal result code from the failed operation.
PossibleCausePossible reason for the failure as reported by WMI.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WMI-Activity",
    "guid": "{1418EF04-B0B4-4623-BF7E-D74AB47BBDAA}",
    "event_source_name": "",
    "event_id": 5858,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-06-13T14:12:35.2925993+00:00",
    "event_record_id": 1549,
    "correlation": {},
    "execution": {
      "process_id": 3616,
      "thread_id": 7696
    },
    "channel": "Microsoft-Windows-WMI-Activity/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "Operation_ClientFailure": {
      "Id": "{C6821FB2-EF88-0001-F50B-83C688EFDC01}",
      "ClientMachine": "TELEMETRY-DC-A",
      "User": "cell-a\\domainadmin",
      "ClientProcessId": "3256",
      "Component": "Unknown",
      "Operation": "Start IWbemServices::ExecQuery - root\\cimv2 : Select * from Win32_PingStatus where ((Address='8.8.8.8') And TimeToLive=80 And BufferSize=32)",
      "ResultCode": "0x80041032",
      "PossibleCause": "Throttling Idle Tasks, refer to CIMOM regkey: ArbTaskMaxIdle"
    }
  },
  "message": "Id = {C6821FB2-EF88-0001-F50B-83C688EFDC01}; ClientMachine = TELEMETRY-DC-A; User = cell-a\\domainadmin; ClientProcessId = 3256; Component = Unknown; Operation = Start IWbemServices::ExecQuery - root\\cimv2 : Select * from Win32_PingStatus where ((Address='8.8.8.8') And TimeToLive=80 And BufferSize=32); ResultCode = 0x80041032; PossibleCause = Throttling Idle Tasks, refer to CIMOM regkey: ArbTaskMaxIdle"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

  • Failed Event Log Clear Via WMI NTEventLogFile ClearEventLog source medium: Detects failed attempts to clear Windows event logs via the WMI NTEventLogFile ClearEventLog method. Event 5858 in the WMI-Activity operational log is an error event, meaning it is only generated when the WMI operation encounters an error (e.g. access denied, provider failure). It could be an indication of an attacker attempting to clear event logs via WMI, but failing due to insufficient privileges or other issues. Successful clearing operations will NOT produce this event; for those, correlate with Security event 1102 or System event 104.T1685, T1685.005

References #

Event ID 5859: Namespace = Operation_EssStarted.NamespaceName; NotificationQuery = Operation_EssStarted.Query; OwnerName = Operation_EssStarted.User; HostProcessID = Operation_EssStarted.Processid; Provider= Oper...

#
Channel
Operational
Collection Priority
Recommended (Palantir, others)

Description

Namespace = ; NotificationQuery = ; OwnerName = ; HostProcessID = ; Provider= , queryID = ; PossibleCause =.

Message #

Namespace = %1; NotificationQuery = %2; OwnerName = %3; HostProcessID = %4;  Provider= %5, queryID = %6; PossibleCause = %7

Fields #

NameDescriptionRules
Operation_EssStarted.NamespaceName
Operation_EssStarted.Query
Operation_EssStarted.User
Operation_EssStarted.Processid
Operation_EssStarted.Provider
Operation_EssStarted.queryid
Operation_EssStarted.PossibleCause
NamespaceName
Query1 detection rule
User1 detection rule
processid
providerName
queryid
PossibleCause1 detection rule

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WMI-Activity",
    "guid": "{1418EF04-B0B4-4623-BF7E-D74AB47BBDAA}",
    "event_source_name": "",
    "event_id": 5859,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-29T16:33:27.8339007+00:00",
    "event_record_id": 1302,
    "correlation": {
      "ActivityID": "{C6821FB2-EF88-0002-7522-82C688EFDC01}"
    },
    "execution": {
      "process_id": 3616,
      "thread_id": 5728
    },
    "channel": "Microsoft-Windows-WMI-Activity/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "Operation_EssStarted": {
      "NamespaceName": "//./root/CIMV2",
      "Query": "select * from MSFT_SCMEventLogEvent",
      "User": "S-1-5-32-544",
      "Processid": "3616",
      "Provider": "SCM Event Provider",
      "queryid": "0",
      "PossibleCause": "Permanent"
    }
  },
  "message": "Namespace = //./root/CIMV2; NotificationQuery = select * from MSFT_SCMEventLogEvent; OwnerName = S-1-5-32-544; HostProcessID = 3616;  Provider= SCM Event Provider, queryID = 0; PossibleCause = Permanent"
}

Detection Patterns #

Community Notes #

Can be used for remote execution.

References #

Event ID 5860: Namespace = Operation_TemporaryEssStarted.NamespaceName; NotificationQuery = Operation_TemporaryEssStarted.Query; UserName = Operation_TemporaryEssStarted.User; ClientProcessID = Operation_Temporar...

#
Channel
Operational
Collection Priority
Recommended (Palantir, others)

Description

Namespace = ; NotificationQuery = ; UserName = ; ClientProcessID = , ClientMachine = ; PossibleCause =.

Message #

Namespace = %1; NotificationQuery = %2; UserName = %3; ClientProcessID = %4, ClientMachine = %5; PossibleCause = %6

Fields #

NameDescription
Operation_TemporaryEssStarted.NamespaceNameWMI namespace for the event subscription.
Operation_TemporaryEssStarted.QueryWQL query for the temporary event subscription.
Operation_TemporaryEssStarted.UserAccount that registered the subscription.
Operation_TemporaryEssStarted.Processid
Operation_TemporaryEssStarted.ClientMachine
Operation_TemporaryEssStarted.PossibleCauseSubscription type indicator.
NamespaceNameWMI namespace for the event subscription.
QueryWQL query for the temporary event subscription.
UserAccount that registered the subscription.
processidProcess ID of the registering client.
MachineNameName of the client machine.
PossibleCauseSubscription type indicator.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WMI-Activity",
    "guid": "{1418EF04-B0B4-4623-BF7E-D74AB47BBDAA}",
    "event_source_name": "",
    "event_id": 5860,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-29T16:33:27.9912212+00:00",
    "event_record_id": 1305,
    "correlation": {},
    "execution": {
      "process_id": 3616,
      "thread_id": 5648
    },
    "channel": "Microsoft-Windows-WMI-Activity/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "Operation_TemporaryEssStarted": {
      "NamespaceName": "ROOT\\CIMV2",
      "Query": "SELECT * FROM __InstanceCreationEvent WITHIN 2 WHERE TargetInstance ISA 'Win32_Process'",
      "User": "NT AUTHORITY\\SYSTEM",
      "Processid": "3688",
      "ClientMachine": "TELEMETRY-DC-A",
      "PossibleCause": "Temporary"
    }
  },
  "message": "Namespace = ROOT\\CIMV2; NotificationQuery = SELECT * FROM __InstanceCreationEvent WITHIN 2 WHERE TargetInstance ISA 'Win32_Process'; UserName = NT AUTHORITY\\SYSTEM; ClientProcessID = 3688, ClientMachine = TELEMETRY-DC-A; PossibleCause = Temporary"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk # view in coverage

  • WMI Temporary Event Subscription source: The following analytic detects the creation of WMI temporary event subscriptions. It leverages Windows Event Logs, specifically EventCode 5860, to identify these activities. This detection is significant because attackers often use WMI to…T1047

References #

Event ID 5861: Namespace = Operation_ESStoConsumerBinding.Namespace; Eventfilter = Operation_ESStoConsumerBinding.ESS (refer to its activate eventid:5859); Consumer = Operation_ESStoConsumerBinding.CONSUMER; Poss...

#
Channel
Operational
Collection Priority
Recommended (Palantir, others)

Description

Namespace = Operation_ESStoConsumerBinding.Namespace; Eventfilter = Operation_ESStoConsumerBinding.ESS (refer to its activate eventid:5859); Consumer = Operation_ESStoConsumerBinding.CONSUMER; PossibleCause = Operation_ESStoConsumerBinding.PossibleCause.

Message #

Namespace = %1; Eventfilter = %2 (refer to its activate eventid:5859); Consumer = %3; PossibleCause = %4

Fields #

NameDescription
Operation_ESStoConsumerBinding.NamespaceWMI namespace containing the filter and consumer.
Operation_ESStoConsumerBinding.ESSName of the event filter bound to the consumer.
Operation_ESStoConsumerBinding.CONSUMERName and type of the event consumer bound to the filter.
Operation_ESStoConsumerBinding.PossibleCauseFull text of the event filter and consumer binding, including the WQL query and consumer configuration.
NamespaceWMI namespace containing the filter and consumer.
ESSName of the event filter bound to the consumer.
CONSUMERName and type of the event consumer bound to the filter.
PossibleCauseFull text of the event filter and consumer binding, including the WQL query and consumer configuration.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WMI-Activity",
    "guid": "{1418EF04-B0B4-4623-BF7E-D74AB47BBDAA}",
    "event_source_name": "",
    "event_id": 5861,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-29T16:33:27.7987060+00:00",
    "event_record_id": 1300,
    "correlation": {},
    "execution": {
      "process_id": 3616,
      "thread_id": 5728
    },
    "channel": "Microsoft-Windows-WMI-Activity/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "Operation_ESStoConsumerBinding": {
      "Namespace": "//./root/subscription",
      "ESS": "SCM Event Log Filter",
      "CONSUMER": "NTEventLogEventConsumer=\"SCM Event Log Consumer\"",
      "PossibleCause": "Binding EventFilter: \ninstance of __EventFilter\n{\n\tCreatorSID = {1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 32, 2, 0, 0};\n\tEventNamespace = \"root\\\\cimv2\";\n\tName = \"SCM Event Log Filter\";\n\tQuery = \"select * from MSFT_SCMEventLogEvent\";\n\tQueryLanguage = \"WQL\";\n};\nPerm. Consumer: \ninstance of NTEventLogEventConsumer\n{\n\tCategory = 0;\n\tCreatorSID = {1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 32, 2, 0, 0};\n\tEventType = 1;\n\tName = \"SCM Event Log Consumer\";\n\tNameOfUserSIDProperty = \"sid\";\n\tSourceName = \"Service Control Manager\";\n};\n"
    }
  },
  "message": "Namespace = //./root/subscription; Eventfilter = SCM Event Log Filter (refer to its activate eventid:5859); Consumer = NTEventLogEventConsumer=\"SCM Event Log Consumer\"; PossibleCause = Binding EventFilter: \ninstance of __EventFilter\n{\n\tCreatorSID = {1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 32, 2, 0, 0};\n\tEventNamespace = \"root\\\\cimv2\";\n\tName = \"SCM Event Log Filter\";\n\tQuery = \"select * from MSFT_SCMEventLogEvent\";\n\tQueryLanguage = \"WQL\";\n};\nPerm. Consumer: \ninstance of NTEventLogEventConsumer\n{\n\tCategory = 0;\n\tCreatorSID = {1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 32, 2, 0, 0};\n\tEventType = 1;\n\tName = \"SCM Event Log Consumer\";\n\tNameOfUserSIDProperty = \"sid\";\n\tSourceName = \"Service Control Manager\";\n};\n"
}

Detection Patterns #

Community Notes #

These consumers survive reboots. WMI abuse is a classic technique for file-less persistence.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk # view in coverage

  • WMI Permanent Event Subscription source: The following analytic detects the creation of permanent event subscriptions using Windows Management Instrumentation (WMI). It leverages Sysmon EventID 5 data to identify instances where the event consumers are not the expected…T1047

References #

Provenance

ETW provider GUID {1418EF04-B0B4-4623-BF7E-D74AB47BBDAA}

Defined in WinMgmtR.dll, which carries the event manifest.

  • WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.2849, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB
  • JD-WIN11-22H2-1, sample captured from a live trace, captured 2026-07-19

    Sealighter user-mode ETW capture of a local WMI-created process.