Remote PowerShell Sessions Network Connections (WinRM)

 Original Source: [Sigma source]
Title: Remote PowerShell Sessions Network Connections (WinRM)
Status: test
Description:Detects basic PowerShell Remoting (WinRM) by monitoring for network inbound connections to ports 5985 OR 5986
References:
  -https://threathunterplaybook.com/hunts/windows/190511-RemotePwshExecution/notebook.html
Author: Roberto Rodriguez @Cyb3rWard0g
Date: 2019-09-12
modified:2022-10-09
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
Logsource:
  • product: windows
  • service: security
Detection:
  selection:
    EventID: '5156'
    DestPort:
      -'5985'
      -'5986'

    LayerRTID: '44'
  condition:selection
Falsepositives:
  -Legitimate use of remote PowerShell execution
Level: high