Windows Remote Management

T1021.006

Sub-technique of T1021 Remote Services.View on attack.mitre.org

About this technique

Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.

WinRM is the name of both a Windows service and a protocol that allows a user to interact with a remote system (e.g., run an executable, modify the Registry, modify services). It may be called with the `winrm` command or by any number of programs such as PowerShell. WinRM can be used as a method of remotely interacting with Windows Management Instrumentation.

Detection rules20

Rules on DetectionCode tagged with T1021.006.

Sigma11

RuleLevelLog source
OMIGOD HTTP No Authentication RCEhighzeek / NULL
Potential Remote PowerShell Session Initiatedhighwindows / network_connection
Remote LSASS Process Access Through Windows Remote Managementhighwindows / process_access
Remote PowerShell Session (PS Module)highwindows / ps_module
Winrs Local Command Executionhighwindows / process_creation
Enable Windows Remote Managementmediumwindows / ps_script
Execute Invoke-command on Remote Hostmediumwindows / ps_script
HackTool - WinRM Access Via Evil-WinRMmediumwindows / process_creation
Potential Lateral Movement via Windows Remote Shellmediumwindows / process_creation
Remote PowerShell Session Host Process (WinRM)mediumwindows / process_creation
Remote PowerShell Session (PS Classic)lowwindows / ps_classic_start

Splunk9

RuleTypeRiskData source
Interactive Session on Remote Endpoint with PowerShellTTPNULLPowershell Script Block Logging 4104
Possible Lateral Movement PowerShell SpawnAnomalyNULLSysmon EventID 1, CrowdStrike ProcessRollup2
Powershell Remote Services Add TrustedHostTTPNULLPowershell Script Block Logging 4104
Remote Process Instantiation via WinRM and PowerShellTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Remote Process Instantiation via WinRM and PowerShell Script BlockTTPNULLPowershell Script Block Logging 4104
Remote Process Instantiation via WinRM and WinrsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Remote Host Computer Management AccessAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688
Windows Remote Management Execute ShellAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688
Wsmprovhost LOLBAS Execution Process SpawnTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups5

Software3

Campaigns2

Procedure examples10

Groups5

Used byProcedure example
GroupChimera

Chimera has used WinRM for lateral movement.

GroupFIN13

FIN13 has leveraged `WMI` to move laterally within a compromised network via application servers and SQL servers.

GroupStorm-0501

Storm-0501 has utilized the post-exploitation tool known as Evil-WinRM that uses PowerShell over Windows Remote Management (WinRM) for remote code execution.

GroupThreat Group-3390

Threat Group-3390 has used WinRM to enable remote execution.

GroupWizard Spider

Wizard Spider has used Window Remote Management to move laterally through a victim network.

Software3

Used byProcedure example
ToolBrute Ratel C4

Brute Ratel C4 can use WinRM for pivoting.

MalwareCobalt Strike

Cobalt Strike can use WinRM to execute a payload on a remote host.

ToolSILENTTRINITY

SILENTTRINITY tracks `TrustedHosts` and can move laterally to these targets via WinRM.

Campaigns2

Used byProcedure example
CampaignOperation MidnightEclipse

During Operation MidnightEclipse, threat actors used WinRM to move laterally in targeted networks.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used WinRM via PowerShell to execute commands and payloads on remote hosts.

References3

  1. Jacobsen 2014 Open source
    Jacobsen, K. (2014, May 16). Lateral Movement with PowerShell[slides]. Retrieved November 12, 2014.
  2. MSDN WMI Open source
    Microsoft. (n.d.). Windows Management Instrumentation. Retrieved April 27, 2016.
  3. Microsoft WinRM Open source
    Microsoft. (n.d.). Windows Remote Management. Retrieved September 12, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.