Suspicious Process Execution via WinRM

Detects instances where common administrative tools (such as PowerShell, cmd, or network utilities) are launched as child processes of the WinRM service process (wsmprovhost.exe) shortly after an inbound WinRM network connection is established on port 5985 or 5986.