For the complete documentation index, see llms.txt. This page is also available as Markdown.

Rare WinRM Session

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services: Windows Remote Management (T1021.006)

Severity

Informational

Description

Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote system. WinRM sessions can be established using WinRM/WinRS commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network.

Attacker's Goals

Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote endpoint. WinRM sessions can be established using winrm/winrs commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network.

Investigative actions

Investigate the endpoints participating in the session.

Variations

Rare WinRM Session by an RMM actor

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services: Windows Remote Management (T1021.006)

Severity

Low

Description

Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote system. WinRM sessions can be established using WinRM/WinRS commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network. The session was initiated by a Remote Monitoring & Management tool.

Attacker's Goals

Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote endpoint. WinRM sessions can be established using winrm/winrs commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network.

Investigative actions

Investigate the endpoints participating in the session.

Was this helpful?