Analytics BIOC Informational

Rare WinRM Session

Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote system. WinRM sessions can be established using WinRM/WinRS commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Remote Services: Windows Remote Management (T1021.006)
Attacker's goals:

Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote endpoint. WinRM sessions can be established using winrm/winrs commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network.

Investigative actions:

Investigate the endpoints participating in the session.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Rare WinRM Session by an RMM actor Low (parent: Informational)