Sub-technique of T1021 Remote Services.View on attack.mitre.org
Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.
WinRM is the name of both a Windows service and a protocol that allows a user to interact with a remote system (e.g., run an executable, modify the Registry, modify services). It may be called with the `winrm` command or by any number of programs such as PowerShell. WinRM can be used as a method of remotely interacting with Windows Management Instrumentation.
Rules on DetectionCode tagged with T1021.006.
| Rule | Level | Log source |
|---|---|---|
| OMIGOD HTTP No Authentication RCE | high | zeek / NULL |
| Potential Remote PowerShell Session Initiated | high | windows / network_connection |
| Remote LSASS Process Access Through Windows Remote Management | high | windows / process_access |
| Remote PowerShell Session (PS Module) | high | windows / ps_module |
| Winrs Local Command Execution | high | windows / process_creation |
| Enable Windows Remote Management | medium | windows / ps_script |
| Execute Invoke-command on Remote Host | medium | windows / ps_script |
| HackTool - WinRM Access Via Evil-WinRM | medium | windows / process_creation |
| Potential Lateral Movement via Windows Remote Shell | medium | windows / process_creation |
| Remote PowerShell Session Host Process (WinRM) | medium | windows / process_creation |
| Remote PowerShell Session (PS Classic) | low | windows / ps_classic_start |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Interactive Session on Remote Endpoint with PowerShell | TTP | NULL | Powershell Script Block Logging 4104 |
| Possible Lateral Movement PowerShell Spawn | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Powershell Remote Services Add TrustedHost | TTP | NULL | Powershell Script Block Logging 4104 |
| Remote Process Instantiation via WinRM and PowerShell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Remote Process Instantiation via WinRM and PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 |
| Remote Process Instantiation via WinRM and Winrs | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Remote Host Computer Management Access | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688 |
| Windows Remote Management Execute Shell | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688 |
| Wsmprovhost LOLBAS Execution Process Spawn | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupChimera | Chimera has used WinRM for lateral movement. |
| GroupFIN13 | FIN13 has leveraged `WMI` to move laterally within a compromised network via application servers and SQL servers. |
| GroupStorm-0501 | Storm-0501 has utilized the post-exploitation tool known as Evil-WinRM that uses PowerShell over Windows Remote Management (WinRM) for remote code execution. |
| GroupThreat Group-3390 | Threat Group-3390 has used WinRM to enable remote execution. |
| GroupWizard Spider | Wizard Spider has used Window Remote Management to move laterally through a victim network. |
| Used by | Procedure example |
|---|---|
| ToolBrute Ratel C4 | Brute Ratel C4 can use WinRM for pivoting. |
| MalwareCobalt Strike | Cobalt Strike can use |
| ToolSILENTTRINITY | SILENTTRINITY tracks `TrustedHosts` and can move laterally to these targets via WinRM. |
| Used by | Procedure example |
|---|---|
| CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used WinRM to move laterally in targeted networks. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used WinRM via PowerShell to execute commands and payloads on remote hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.