FORENSIA

ATT&CK · T1021.006 · sub-technique

Windows Remote Management

Tactics: lateral-movement

About

Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user. WinRM is the name of both a Windows service and a protocol that allows a user to interact with a remote system (e.g., run an executable, modify the Registry, modify services). It may be called with the `winrm` command or by any number of programs such as PowerShell. WinRM can be used as a method of remotely interacting with Windows Management Instrumentation.

Platforms: WindowsParent: T1021 Remote ServicesMITRE ATT&CK ↗

Used by actors

5 known groups

Software

3 malware/tools implement this

Cobalt StrikeSILENTTRINITYBrute Ratel C4

Corpus indicators tagged with this technique

66 indicators in the corpus carry T1021.006.

IndicatorTypeFamilySevSrc
cve-2016-15047cve854
cve-2025-34054cve854
cve-2021-27137cve858
f3570bb6e0f9c695d48f89f043380b43831dd0f6fe79b16eda2a3ffd9fd7ad16sha256801
39bd9c888d3e8110c127ba60cc727d2538bf7da2hashransomware801
35e0b22139fb27d2c9721aedf5770d893423bf029e1f56be92485ff8fce210f3sha256801
4537b37b65e9dc35640d750f3fa7f4944534f6b1hash803
eead44c0af7ddb12cece1a6125cf213bab3c22511cd59aff9d63dcfddb7d4386hash804
41e8e327abbf2ba721be677ad8a416a7295708257b39688a0af03275fb199cechash804
7413cbb6eab4d6b10346f71be5dd76d7cf2f4817f7776367b162f83755aefa1fhash804
450ea44da0c9d96a2e8f4d6bad34f1c35cd35743295b8cd2defa9f7a9884685dhash804
8fc2d35b66c692d37a85ae9d30dc5c7f06f0b3eaf01112a5a6398a1a0feb3aeehash804
1cd9eccc8e73d60164390beddf4cdc48hash804
4200b46a93c6ab059e2b34ce200c4a5bhashransomware802
ca9d7aaff7c636120149168e2bbb509c10544993hash804
28f871af1833935beba160b51e4a732c43a5dde5hash804
20042f1efb59c99e3addf822a3e9e5a496f0b701362df038a50a32a9f504a136hash804
3ddb67ab079509dd1e7ac77fc4cfed25a271526668c68f8a2221e96a4cc21812hash804
42bcc743c71a9ea083c1c750a398110582796762hashransomware802
444a9d34a9f59dc7975dfabefb47d789813a4497bbac9127c4806dd816e85211hash804
7b2599ed54b72daec0acfd32744c7a9a77b19e6cf4e1651837175e4606dbc958sha256801
9394666007fac4014a4641fdae150c1b969ed2bc4299876318a336fd386abf59hash804
b61a5508847a2167b737d31193dc393e92c5be2aa5141bbe4b7ea6f440fd4799hash804
b6f835ced11059d341222eba11fff3a4672f4de47a3a4d791fad86059a2b06d4hash804
d452f22dacab9785539484245c13e9cce58df23fc82eeef205684fcd196da20bhash804
dff0edae6e8854ddd3e617054ee0bd74c696c91411f704dff60aabaec839bec9hash804
ea44138b9701fce1b2fe13de8f9e00681c007c9adc625edc9f507f177704c2e8hash804
f02b1d8010dac35b007796def0cbd5d0c9414df790e2b55b105c95df2f2ffa91hash804
703a8383a3df68abce59b02fcd0b5678hash804
9f33095a24471bed55ce11803e4ebbed5118bfb5d3861baf1c8214efcd9e7de6sha256801

Showing the top 30 by severity of 66.