Analytics BIOC
Informational
✕
Rare WinRM Session
Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote system. WinRM sessions can be established using WinRM/WinRS commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Remote Services: Windows Remote Management (T1021.006)
Attacker's goals:
Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote endpoint. WinRM sessions can be established using winrm/winrs commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network.
Investigative actions:
Investigate the endpoints participating in the session.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Rare WinRM Session by an RMM actor Low (parent: Informational)