Potential Lateral Movement Via Windows Remote Management (WinRM)

Rule Info

Name
Potential Lateral Movement Via Windows Remote Management (WinRM)
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects child process of "winrshost.exe". This indicate remote execution via Windows Remote Management (WinRM) and could be a sign of potential lateral movement activity.
Date
2024-05-03 00:00:00
Modified
None
Id
1cf783d5-9798-44b8-a87a-ca71f2dd780a
Tags
attack.execution
Type
Nextron Sigma feed only (private)

Rule History