Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0477 — Behavioral Detection of WinRM-Based Remote Access
DET0477

Behavioral Detection of WinRM-Based Remote Access

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1313 Analytic 1313
Windows

Adversaries using WinRM to remotely execute commands, launch child processes, or access WMI. The detection chain includes service use, network activity, remote session logon, and process creation within a short temporal window.

WinEventLog:Security EventCode=4624, 4648 WinEventLog:Sysmon EventCode=1 WinEventLog:WinRM EventCode=6 NSM:Connections Inbound on ports 5985/5986
[TimeWindow] Defines max time between remote shell creation and child process execution (e.g., 60 seconds)
[UserContext] Scope to unexpected remote user logons (non-admins, service accounts)
[CommandLineAnomalyScore] Score for suspicious command usage via WinRM (e.g., encoded PowerShell)
[KnownAdminHosts] List of trusted systems allowed to use WinRM legitimately

Detected Techniques

1

Details

MITRE ID
DET0477
STIX ID
x-mitre-detection-strategy--7ff1f384-2373-4ea9-9311-1587b520a5c4
Analytics
1
Techniques Detected
1
By Tactic
Lateral Movement
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.