
Rule Info
Name
Wsmprovhost Suspicious Image Load
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the potentailly suspicious image loads events by the wsmprovhost.exe process.
This could be an indicator of Windows Remote Management (WinRM) loading a new plugin, that could be potentially malicious.
Date
2025-02-12 00:00:00
Modified
None
Id
27aff1a7-2895-4d07-908d-45c2bfc94cad
Tags
attack.lateral-movement attack.t1021.006
Type
Nextron Sigma feed only (private)