Title:Remote PowerShell Session Host Process (WinRM) Status:test Description:Detects remote PowerShell sections by monitoring for wsmprovhost (WinRM host process) as a parent or child process (sign of an active PowerShell remote session). References: -https://threathunterplaybook.com/hunts/windows/190511-RemotePwshExecution/notebook.html Author: Roberto Rodriguez @Cyb3rWard0g Date: 2019-09-12 modified:2022-10-09 Tags:
-'attack.execution'
-'attack.lateral-movement'
-'attack.t1059.001'
-'attack.t1021.006'
Logsource:
category: process_creation
product: windows
Detection: selection: Image|endswith:'\wsmprovhost.exe'ParentImage|endswith:'\wsmprovhost.exe'condition:selection Falsepositives:
-Legitimate usage of remote Powershell, e.g. for monitoring purposes. Level:medium