1200KM / detection
T1021.006 Windows Remote Management — Detection Rules
Detection workspace for T1021.006 Windows Remote Management: 10 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Potential Remote PowerShell Session Initiated · test · high · {"category":"network_connection","product":"windows"}
- Remote PowerShell Session (PS Classic) · test · low · {"product":"windows","category":"ps_classic_start"}
- Remote PowerShell Session (PS Module) · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Enable Windows Remote Management · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Execute Invoke-command on Remote Host · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Remote LSASS Process Access Through Windows Remote Management · stable · high · {"category":"process_access","product":"windows"}
- HackTool - WinRM Access Via Evil-WinRM · test · medium · {"category":"process_creation","product":"windows"}
- Remote PowerShell Session Host Process (WinRM) · test · medium · {"category":"process_creation","product":"windows"}
- Winrs Local Command Execution · experimental · high · {"category":"process_creation","product":"windows"}
- Potential Lateral Movement via Windows Remote Shell · experimental · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1021.006 Windows Remote Management
MATCH(remote_management_session_or_command) AND source_host NOT_IN approved_management_hosts -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0477 Behavioral Detection of WinRM-Based Remote Access
AN1313 Analytic 1313
Adversaries using WinRM to remotely execute commands, launch child processes, or access WMI. The detection chain includes service use, network activity, remote session logon, and process creation within a short temporal window.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.