Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0008 ✕ technique: T1021 ✕
Download CSV Show ATT&CK heatmapRare WinRM Session Informational 1 variation
Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote system. WinRM sessions can be established using WinRM/WinRS commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Lateral Movement (TA0008)ATT&CK techniques: Remote Services: Windows Remote Management (T1021.006)Required data: XDR AgentAttacker's goals: Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote endpoint. WinRM sessions can be established using winrm/winrs commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network.Investigative actions: Investigate the endpoints participating in the session.Variations
Rare WinRM Session by an RMM actor
Low overridden
Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote system. WinRM sessions can be established using WinRM/WinRS commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network. The session was initiated by a Remote Monitoring & Management tool. overridden