PowerShell Remoting Lateral Movement via WinRM (T1021.006)

Detects potential lateral movement activity where PowerShell or the Windows Remote Management (WinRM) host process (wsmprovhost.exe) initiates network connections to multiple distinct destination IP addresses over the WinRM default ports (5985/5986). This behavior is characteristic of an adversary using legitimate remote administration tools to pivot or spread across a network.