Suspicious Processes Spawned by WinRM
Description
Detects suspicious processes including shells spawnd from WinRM host process
Query · sigma
selection: ParentImage|endswith: \wsmprovhost.exe Image|endswith: - \cmd.exe - \sh.exe - \bash.exe - \powershell.exe - \pwsh.exe - \wsl.exe - \schtasks.exe - \certutil.exe - \whoami.exe - \bitsadmin.exe condition: selection
Known false positives
- Legitimate WinRM usage