Windows Winrs.exe Local Command Execution via localhost/loopback

Alerts on Winrs.exe processes running locally by targeting localhost/loopback in /r or /remote.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Liran Ravich, Nasreddine Bencherchali (SigmaHQ), DRL 1.1
Published
2025-10-22
Updated
2026-07-30

ATT&CK techniques

Defense Evasion → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags process creations of Winrs.exe when its command line targets localhost or loopback addresses (including 127.0.0.1 and ::1). Winrs is commonly used for remote management, so local execution with these parameters can indicate proxy execution behavior for stealth or movement. The detection relies on Windows process creation telemetry, specifically matching Winrs image and command-line arguments for /r or /remote values.

Related detections9 linkedT1218 — drag to rearrange
Suspicious Cabinet Extraction of Masqueraded vstm Archive via extrac32
Malicious Invoke-WMIExec Lateral Movement Download and Execute (via ps_script)
Malicious DLL Execution via Wuauclt Update Handler (via process_creation)
Malicious aspnet_compiler.exe Injection Host Spawned by PowerShell via process_creation
Malicious regsvcs LOLBin Loading Ransomware DLL from UNC Path
Suspicious RegAsm or RegSvcs Spawned by Script Host (via process_creation)
Suspicious Extexport DLL Side-Loading Execution
Malicious ClickFix Execution Chain Spawning MSHTA via Pcalua on EtherRAT Infection
Suspicious TALONITE Certutil LOLBIN Decode and Download Abuse (via process_creation)
Windows Winrs.exe Local Command Execution via localhost/loopback
Pivot detection · T1218 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.