WMI Creation (05645013-2fed-4066-8bdc-626b2e201dd4)
Initial construction of a WMI object, such as a filter, consumer, subscription, binding, or providers.
Data Collection Measures:
- Windows Security Event Logs:
- Event ID 5861 (WMI Permanent Event Subscription)
 - Event ID 5860 (WMI Event Filter Activity)
 - Event ID 5857 (WMI Event Consumer Activity)
 
 - Sysmon Logs:
- Sysmon Event ID 19 – WMI Event Filter Created
 - Sysmon Event ID 20 – WMI Event Consumer Created
 - Sysmon Event ID 21 – WMI Event Binding Created
 
 - Endpoint Detection & Response (EDR)
- Detects WMI-based persistence techniques.