For the complete documentation index, see llms.txt. This page is also available as Markdown.

Rare Windows Remote Management (WinRM) HTTP Activity

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Palo Alto Networks Firewall EAL Logs OR XDR Agent

Detector Tags

NDR Lateral Movement Analytics

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services (T1021)

Severity

Low

Description

The endpoint performed unfamiliar WinRM HTTP activity to a remote host.

Attacker's Goals

  • Attackers may use WinRM to execute code on remote hosts, in an attempt to gain persistence or move laterally in the network.

Investigative actions

  • Correlate the WinRM HTTP request from the source host and understand which software initiated it.

  • Verify that this isn't IT activity.

Was this helpful?