Analytics BIOC
Low
✕
Wsmprovhost.exe Rare Child Process
The PowerShell host wsmprovhost.exe is a proxy process executed remotely through PowerShell when using Windows Remote Management (WinRM). It has executed a rare child process, which may indicate remote code execution abuse by an attacker.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)
ATT&CK techniques: Remote Services: Windows Remote Management (T1021.006) Command and Scripting Interpreter: PowerShell (T1059.001)
Attacker's goals:
Gain code execution on a remote host.
Investigative actions:
Investigate the processes being spawned from Wsmprovhost.exe on the host for malicious indicators. Correlate the initiator process (most likely PowerShell) to the source host and investigate it.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day