Remote Services: Windows Remote Management T1021.006
Tactic: Lateral Movement
Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.
Events covered
23 catalog events are tagged with this technique by at least one rule.
Authoring guide
Patterns shared across the 37 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (42 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (543 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (46 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 14 rules
- Enable Windows Remote Management
- Execute Invoke-command on Remote Host
- HackTool - WinRM Access Via Evil-WinRM
- OMIGOD HTTP No Authentication RCE - CVE-2021-38647
- Potential Lateral Movement via Windows Remote Shell
- Potential Remote PowerShell Session Initiated
- Remote LSASS Process Access Through Windows Remote Management
- Remote PowerShell Session (PS Classic)
- Remote PowerShell Session (PS Module)
- Remote PowerShell Session Host Process (WinRM)
- WinRM listening service reconnaissance (process)
- WinRM listening service reconnaissance (WS-Management)
- Winrs Local Command Execution
- WinRS usage for remote execution
Elastic 5 rules
- Deprecated - PowerShell Script with Remote Execution Capabilities via WinRM
- Incoming Execution via PowerShell Remoting
- Incoming Execution via WinRM Remote Shell
- Potential PowerShell HackTool Script by Function Names
- WMIC Remote Command
Splunk 13 rules
- Impacket SMBexec (Windows Event Log)
- Interactive Session on Remote Endpoint with PowerShell
- Possible Lateral Movement PowerShell Spawn
- Powershell Remote Services Add TrustedHost
- Remote Process Instantiation via WinRM and PowerShell
- Remote Process Instantiation via WinRM and PowerShell Script Block
- Remote Process Instantiation via WinRM and Winrs
- Windows Remote Host Computer Management Access
- Windows Remote Management Execute Shell
- WinRM Tools (PowerShell)
- WinRM Tools (Sysmon)
- WinRM Tools (Windows Event Log)
- Wsmprovhost LOLBAS Execution Process Spawn
Kusto 4 rules
- Detect service account login on new device
- Detect Unknown process launched via WinRM
- Detect Unknown process using SMB or WinRM
- WinRM Plugin Lateral Movement