Analytics BIOC Low

Wsmprovhost.exe Rare Child Process

The PowerShell host wsmprovhost.exe is a proxy process executed remotely through PowerShell when using Windows Remote Management (WinRM). It has executed a rare child process, which may indicate remote code execution abuse by an attacker.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)
ATT&CK techniques: Remote Services: Windows Remote Management (T1021.006) Command and Scripting Interpreter: PowerShell (T1059.001)
Attacker's goals:

Gain code execution on a remote host.

Investigative actions:

Investigate the processes being spawned from Wsmprovhost.exe on the host for malicious indicators. Correlate the initiator process (most likely PowerShell) to the source host and investigate it.

Test period:
N/A (single event)
Deduplication:
1 Day