Wsmprovhost.exe Rare Child Process
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Lateral Movement (TA0008), Execution (TA0002)
ATT&CK Technique
Remote Services: Windows Remote Management (T1021.006), Command and Scripting Interpreter: PowerShell (T1059.001)
Severity
Low
Description
The PowerShell host wsmprovhost.exe is a proxy process executed remotely through PowerShell when using Windows Remote Management (WinRM). It has executed a rare child process, which may indicate remote code execution abuse by an attacker.
Attacker's Goals
Gain code execution on a remote host.
Investigative actions
Investigate the processes being spawned from Wsmprovhost.exe on the host for malicious indicators.
Correlate the initiator process (most likely PowerShell) to the source host and investigate it.
Was this helpful?
