Suspicious Non PowerShell WSMAN COM Provider (via powershell-classic)
This rule detects anomalous use of the WSMAN provider without PowerShell.exe as the host application.
SigmamediumWindowsv1
sigma
suspicious-non-powershell-wsman-com-provider-via-powershell-classic
title: Suspicious Non PowerShell WSMAN COM Provider (via powershell-classic)
id: cd39bb1e-4f66-5353-863d-1fed715b499a
status: stable
description: This rule detects anomalous use of the WSMAN provider without PowerShell.exe as the host application.
references:
- https://attack.mitre.org/techniques/T1021/003/
- https://attack.mitre.org/techniques/T1059/001/
- https://twitter.com/chadtilbury/status/1275851297770610688
- https://bohops.com/2020/05/12/ws-management-com-another-approach-for-winrm-lateral-movement/
- https://github.com/bohops/WSMan-WinRM
author: Huntrule Team
date: 2026-04-26
tags:
- attack.execution
- attack.t1059.001
- attack.lateral-movement
- attack.t1021.003
logsource:
product: windows
service: powershell-classic
detection:
selection:
Data|contains: 'ProviderName=WSMan'
filter_main_ps:
Data|contains:
- 'HostApplication=powershell'
- 'HostApplication=C:\Windows\System32\WindowsPowerShell\v1.0\powershell'
- 'HostApplication=C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell'
- 'HostApplication=C:/Windows/System32/WindowsPowerShell/v1.0/powershell'
- 'HostApplication=C:/Windows/SysWOW64/WindowsPowerShell/v1.0/powershell'
filter_main_host_application_null:
Data|re: 'HostId=[a-zA-Z0-9-]{36}\s+EngineVersion='
filter_optional_hexnode:
Data|contains: 'HostApplication=C:\Hexnode\Hexnode Agent\Current\HexnodeAgent.exe'
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Unknown
level: medium
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.