Suspicious Processes Spawned by WinRM

 Original Source: [Sigma source]
Title: Suspicious Processes Spawned by WinRM
Status: test
Description:Detects suspicious processes including shells spawnd from WinRM host process
References:
  -Internal Research
Author: Andreas Hunkeler (@Karneades), Markus Neis
Date: 2021-05-20
modified:2022-07-14
Tags:
  • -'attack.t1190'
  • -'attack.initial-access'
  • -'attack.persistence'
  • -'attack.privilege-escalation'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\wsmprovhost.exe'
    Image|endswith:
      -'\cmd.exe'
      -'\sh.exe'
      -'\bash.exe'
      -'\powershell.exe'
      -'\pwsh.exe'
      -'\wsl.exe'
      -'\schtasks.exe'
      -'\certutil.exe'
      -'\whoami.exe'
      -'\bitsadmin.exe'

  condition:selection
Falsepositives:
  -Legitimate WinRM usage
Level: high