Rare Windows Remote Management (WinRM) HTTP Activity
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Palo Alto Networks Firewall EAL Logs OR XDR Agent
Detector Tags
NDR Lateral Movement Analytics
ATT&CK Tactic
Lateral Movement (TA0008)
ATT&CK Technique
Remote Services (T1021)
Severity
Low
Description
The endpoint performed unfamiliar WinRM HTTP activity to a remote host.
Attacker's Goals
Attackers may use WinRM to execute code on remote hosts, in an attempt to gain persistence or move laterally in the network.
Investigative actions
Correlate the WinRM HTTP request from the source host and understand which software initiated it.
Verify that this isn't IT activity.
PreviousRare Unsigned Process Spawned by Office Process Under Suspicious Directory
NextRare WinRM Session
Was this helpful?
