Windows Remote PowerShell Session via PS Module ContextInfo and wsmprovhost.exe

Flags Windows PowerShell remote session module context involving wsmprovhost.exe while filtering out archive module references.

FreeReviewedSigma · High · v2
Product
windows
Category
ps_module
Author
Roberto Rodriguez @Cyb3rWard0g, Tim Shelton (SigmaHQ), DRL 1.1
Published
2019-08-10
Updated
2026-07-31

ATT&CK techniques

Execution → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies remote PowerShell session activity by matching PowerShell module context details that include the ServerRemoteHost marker and the wsmprovhost.exe host application. It helps detect attacker-driven remote PowerShell usage for execution and lateral movement. The detection relies on Windows PowerShell module telemetry that contains ContextInfo strings, plus the presence of Microsoft.PowerShell.Archive module paths that are excluded by the filter.

Related detections9 linkedT1059.001 — drag to rearrange
Windows remote PowerShell session activity via wsmprovhost.exe process relationships
Windows Remote PowerShell via PS Classic (wsmprovhost.exe, HostName=ServerRemoteHost)
WinRM Remote Access to LSASS via wsmprovhost.exe (Windows Process Access)
Suspicious Script Interpreter Spawned by Explorer via ClickFix Run Dialog (via process_creation)
Suspicious PowerShell Download Cradle via ClickFix Fake CAPTCHA (via process_creation)
Suspicious PowerShell EncodedCommand Spawned From Command Shell via Process Creation
Suspicious Script Download via Curl and PowerShell by Dohdoor
Malicious Mass Hyper-V Virtual Machine Shutdown via PowerShell by Kraken Ransomware
Suspicious PowerShell WebClient DownloadFile of Archive Payload (UAT-7237)
Windows Remote PowerShell Session via PS Module ContextInfo and wsmprovhost.exe
Pivot detection · T1059.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.