Windows Remote PowerShell via PS Classic (wsmprovhost.exe, HostName=ServerRemoteHost)

Flags Windows telemetry indicating a remote PowerShell session startup using wsmprovhost.exe with a specified host parameter.

FreeReviewedSigma · Low · v2
Product
windows
Category
ps_classic_start
Author
Roberto Rodriguez @Cyb3rWard0g (SigmaHQ), DRL 1.1
Published
2019-08-10
Updated
2026-07-31

ATT&CK techniques

Execution → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies start events for a remote PowerShell session in PS Classic by matching process activity where the command data contains HostName=ServerRemoteHost and the executable wsmprovhost.exe. Attackers may use PowerShell remoting to execute commands on remote hosts while blending with legitimate administrative tooling. The detection relies on Windows PS Classic start telemetry that includes the referenced HostName field and the wsmprovhost.exe process indicator.

Related detections9 linkedT1059.001 — drag to rearrange
Windows remote PowerShell session activity via wsmprovhost.exe process relationships
Windows Remote PowerShell Session via PS Module ContextInfo and wsmprovhost.exe
WinRM Remote Access to LSASS via wsmprovhost.exe (Windows Process Access)
Suspicious Script Interpreter Spawned by Explorer via ClickFix Run Dialog (via process_creation)
Suspicious PowerShell Download Cradle via ClickFix Fake CAPTCHA (via process_creation)
Suspicious PowerShell EncodedCommand Spawned From Command Shell via Process Creation
Suspicious Script Download via Curl and PowerShell by Dohdoor
Malicious Mass Hyper-V Virtual Machine Shutdown via PowerShell by Kraken Ransomware
Suspicious PowerShell WebClient DownloadFile of Archive Payload (UAT-7237)
Windows Remote PowerShell via PS Classic (wsmprovhost.exe, HostName=ServerRemoteHost)
Pivot detection · T1059.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.