For the complete documentation index, see llms.txt. This page is also available as Markdown.

Wsmprovhost.exe Rare Child Process

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Lateral Movement (TA0008), Execution (TA0002)

ATT&CK Technique

Remote Services: Windows Remote Management (T1021.006), Command and Scripting Interpreter: PowerShell (T1059.001)

Severity

Low

Description

The PowerShell host wsmprovhost.exe is a proxy process executed remotely through PowerShell when using Windows Remote Management (WinRM). It has executed a rare child process, which may indicate remote code execution abuse by an attacker.

Attacker's Goals

Gain code execution on a remote host.

Investigative actions

  • Investigate the processes being spawned from Wsmprovhost.exe on the host for malicious indicators.

  • Correlate the initiator process (most likely PowerShell) to the source host and investigate it.

Was this helpful?