ATT&CK · T1021.006 · sub-technique
Windows Remote Management
Tactics: lateral-movement
About
Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user. WinRM is the name of both a Windows service and a protocol that allows a user to interact with a remote system (e.g., run an executable, modify the Registry, modify services). It may be called with the `winrm` command or by any number of programs such as PowerShell. WinRM can be used as a method of remotely interacting with Windows Management Instrumentation.
Used by actors
5 known groups
Software
3 malware/tools implement this
Corpus indicators tagged with this technique
66 indicators in the corpus carry T1021.006.
Showing the top 30 by severity of 66.