Suspicious Processes Spawned by WinRM
Detects suspicious processes including shells spawnd from WinRM host process
Detection logic
selection
ParentImage|endswith: \wsmprovhost.exe
Image|endswith:
- \cmd.exe
- \sh.exe
- \bash.exe
- \powershell.exe
- \pwsh.exe
- \wsl.exe
- \schtasks.exe
- \certutil.exe
- \whoami.exe
- \bitsadmin.exeCondition
selectionRaw YAML
title: Suspicious Processes Spawned by WinRM
id: 5cc2cda8-f261-4d88-a2de-e9e193c86716
status: test
description: Detects suspicious processes including shells spawnd from WinRM host process
author: Andreas Hunkeler (@Karneades), Markus Neis
references:
- Internal Research
date: 2021-05-20
modified: 2022-07-14
tags:
- attack.t1190
- attack.initial-access
- attack.persistence
- attack.privilege-escalation
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: '\wsmprovhost.exe'
Image|endswith:
- '\cmd.exe'
- '\sh.exe'
- '\bash.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\wsl.exe'
- '\schtasks.exe'
- '\certutil.exe'
- '\whoami.exe'
- '\bitsadmin.exe'
condition: selection
falsepositives:
- Legitimate WinRM usage
level: highFalse positives
- Legitimate WinRM usage
References
Internal Research
Similar rules
Suspicious Child Process Of SQL Server
highwindows · Shares T1190
Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309)
highwindows · Shares T1190
Potential Exploitation of GoAnywhere MFT Vulnerability
highwindows · Shares T1190
Suspicious Child Process of SAP NetWeaver
mediumwindows · Shares T1190