Suspicious Non PowerShell WSMAN COM Provider

 Original Source: [Sigma source]
Title: Suspicious Non PowerShell WSMAN COM Provider
Status: test
Description:Detects suspicious use of the WSMAN provider without PowerShell.exe as the host application.
References:
  -https://twitter.com/chadtilbury/status/1275851297770610688
  -https://bohops.com/2020/05/12/ws-management-com-another-approach-for-winrm-lateral-movement/
  -https://github.com/bohops/WSMan-WinRM
Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research)
Date: 2020-06-24
modified:2025-10-22
Tags:
  • -'attack.execution'
  • -'attack.t1059.001'
  • -'attack.lateral-movement'
  • -'attack.t1021.003'
Logsource:
  • product: windows
  • service: powershell-classic
Detection:
  selection:
    Data|contains: 'ProviderName=WSMan'
  filter_main_ps:
    Data|contains:
      -'HostApplication=powershell'
      -'HostApplication=C:\Windows\System32\WindowsPowerShell\v1.0\powershell'
      -'HostApplication=C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell'
      -'HostApplication=C:/Windows/System32/WindowsPowerShell/v1.0/powershell'
      -'HostApplication=C:/Windows/SysWOW64/WindowsPowerShell/v1.0/powershell'

  filter_main_host_application_null:
    Data|re: 'HostId=[a-zA-Z0-9-]{36}\s+EngineVersion='
  filter_optional_hexnode:
    Data|contains: 'HostApplication=C:\Hexnode\Hexnode Agent\Current\HexnodeAgent.exe'
  condition:selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: medium