Skip to content
Threat Feed

Tag

Winrm

5 briefs RSS
high threat

Toy Ghouls Deploying Custom HiveMQ and Matrix-Based Backdoors

The threat actor Toy Ghouls is using WinRM to deploy custom 'Bird' backdoors that utilize HiveMQ MQTT brokers and the Matrix protocol for C2, featuring machine-bound encrypted configurations.

Toy Ghouls backdoors persistence winrm c2 mqtt
1r 3t 1i
medium advisory

Detection of Remote PowerShell Invoke-Command Execution

Adversaries leverage the PowerShell Invoke-Command cmdlet to perform lateral movement and execute arbitrary code on remote Windows hosts via WinRM.

lateral-movement powershell winrm
1r 1t
medium advisory

Detection of WinRM Remote Management Enablement

Adversaries may enable Windows Remote Management (WinRM) to facilitate lateral movement and remote code execution on compromised systems.

lateral-movement powershell winrm
1t
medium advisory

Suspicious WSMAN Provider Image Loads

A detection engineering rule targets suspicious loading of Windows Management (WSMAN) provider DLLs by unusual processes, indicating potential local or remote execution and lateral movement through Windows Remote Management (WinRM) by threat actors.

lateral-movement remote-execution windows-management winrm
1r 2t
medium advisory

Incoming Execution via WinRM Remote Shell

This rule detects incoming execution via Windows Remote Management (WinRM) remote shell on a target host, which could be an indication of lateral movement by monitoring network traffic on ports 5985 or 5986 and processes initiated by WinRM.

Elastic Defend +1 lateral-movement windows winrm remote-execution
2r 1t