Winrs Local Command Execution

 Original Source: [Sigma source]
Title: Winrs Local Command Execution
Status: experimental
Description:Detects the execution of Winrs.exe where it is used to execute commands locally. Commands executed this way are launched under Winrshost.exe and can represent proxy execution used for defense evasion or lateral movement.
References:
  -https://cardinalops.com/blog/living-off-winrm-abusing-complexity-in-remote-management/
  -https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/winrs
Author: Liran Ravich, Nasreddine Bencherchali
Date: 2025-10-22
modified:None
Tags:
  • -'attack.lateral-movement'
  • -'attack.stealth'
  • -'attack.t1021.006'
  • -'attack.t1218'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\winrs.exe' OriginalFileName:'winrs.exe'   selection_local_ip:
    CommandLine|contains|windash:
      -'/r:localhost'
      -'/r:127.0.0.1'
      -'/r:[::1]'
      -'/remote:localhost'
      -'/remote:127.0.0.1'
      -'/remote:[::1]'

  filter_main_remote:
    CommandLine|contains|windash:
      -'/r:'
      -'/remote:'

  condition:all of selection_* or (selection_img and not 1 of filter_main_*)
Falsepositives:
  -Unlikely
Level: high