Cross-source coverage

T1028 / ATT&CK

Windows Remote Management

ATT&CK has retired this technique. Rules still tag it; the current id is T1021.006 Remote Services: Windows Remote Management.

6 rules across 2 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Windows Remote Management (WinRM) is the name of both a Windows service and a protocol that allows a user to interact with a remote system (e.g., run an executable, modify the Registry, modify services). It may be called with the winrm command or by any number of programs such as PowerShell.

Platforms
Windows
Telemetry

chronicle/detection-rules

4 rules
Detection Severity Format
detection_of_winrs_usage Undefined YARA-L
mimikatz_through_windows_remote_management Undefined YARA-L
winrm_configuration_detector Undefined YARA-L
winrm_session_created_sysmon_behavior Undefined YARA-L

Emerging Threats Open

2 rules
Detection Severity Format
ET POLICY WinRM wsman Access - Possible Lateral Movement High Suricata
ET USER_AGENTS WinRM User Agent Detected - Possible Lateral Movement Medium Suricata

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.