Suspicious Process Execution via WinRM
Detects instances where common administrative tools (such as PowerShell, cmd, or network utilities) are launched as child processes of the WinRM service process (wsmprovhost.exe) shortly after an inbound WinRM network connection is established on port 5985 or 5986.
Microsoft Sentinel (KQL)

