AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl (via process_creation)
This rule detects execution of attacker-controlled WsmPty.xsl or WsmTxt.xsl via winrm.vbs and copied cscript.exe (can be renamed)
SigmamediumWindowsv1
sigma
awl-bypass-with-winrm-vbs-and-malicious-wsmpty-xsl-wsmtxt-xsl-via-process-creation
title: AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl (via process_creation)
id: 60bff1f4-e87c-5cf3-a0d7-e53b1d6ea316
status: stable
description: This rule detects execution of attacker-controlled WsmPty.xsl or WsmTxt.xsl via winrm.vbs and copied cscript.exe (can be renamed)
references:
- https://attack.mitre.org/techniques/T1216/
- https://posts.specterops.io/application-whitelisting-bypass-and-arbitrary-unsigned-code-execution-technique-in-winrm-vbs-c8c24fb40404
author: Huntrule Team
date: 2026-05-12
tags:
- attack.stealth
- attack.t1216
logsource:
category: process_creation
product: windows
detection:
contains_format_pretty_arg:
CommandLine|contains:
- 'format:pretty'
- 'format:"pretty"'
- 'format:"text"'
- 'format:text'
image_from_system_folder:
Image|startswith:
- 'C:\Windows\System32\'
- 'C:\Windows\SysWOW64\'
contains_winrm:
CommandLine|contains: 'winrm'
condition: contains_winrm and (contains_format_pretty_arg and not image_from_system_folder)
falsepositives:
- Unknown
level: medium
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.