Windows process creation: child process spawned by winrshost.exe

Flags Windows process children of winrshost.exe that may indicate WinRS-driven remote command execution.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Liran Ravich (SigmaHQ), DRL 1.1
Published
2025-10-22
Updated
2026-07-30

ATT&CK techniques

Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies when a process is created as a child of winrshost.exe on Windows, indicating remote command execution via Windows Remote Shell (WinRS). Such activity can be used to run commands on additional hosts and may support lateral movement. It relies on Windows process creation telemetry, matching the parent executable name and excluding cases involving conhost.exe as the spawned image.

Related detections9 linkedT1021.006 — drag to rearrange
Suspicious WinRM Compatibility HTTPS Listener Enabled via winrm.vbs
Malicious Invoke-WMIExec Lateral Movement Download and Execute (via ps_script)
Windows Winrs.exe Local Command Execution via localhost/loopback
Windows PowerShell: Invoke-Command targeting -ComputerName via script block
Windows PowerShell script enabling WinRM via Enable-PSRemoting
Windows HackTool Activity: Evil-WinRM Ruby Process with -i, -u, -p Arguments
Zeek HTTP POST to /wsman without Authorization — Possible OMIGOD unauthenticated RCE (CVE-2021-38647)
Windows remote PowerShell session activity via wsmprovhost.exe process relationships
Windows Remote PowerShell via PS Classic (wsmprovhost.exe, HostName=ServerRemoteHost)
Windows process creation: child process spawned by winrshost.exe
Pivot detection · T1021.006 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.