Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Rare WinRM Session Informational 1 variation

    Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote system. WinRM sessions can be established using WinRM/WinRS commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Lateral Movement (TA0008)
    ATT&CK techniques: Remote Services: Windows Remote Management (T1021.006)
    Required data: XDR Agent
    Attacker's goals: Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote endpoint. WinRM sessions can be established using winrm/winrs commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network.
    Investigative actions: Investigate the endpoints participating in the session.

    Variations

    Rare WinRM Session by an RMM actor

    Low overridden

    Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote system. WinRM sessions can be established using WinRM/WinRS commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network. The session was initiated by a Remote Monitoring & Management tool. overridden